dsh-web-open-access avatar

dsh-web-open-access

Removes the login token and the local-network access restriction.

PluginSecurityNetworkTerminal / ShellFileWeb search
Verification
L4 · Install tested
Passed
Risk
Low
Health
Active
Trust
Silver

What it doesAI

Removes the dsh web login token and local-network access restriction, exposing shell/file tools to remote users.

  • Removes startup token, signed cookies, and API host trust checks
  • Treats remote page as localhost; removes loopback gating for settings
  • Fully disables auth; binding 0.0.0.0 exposes RCE; trusted networks only

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:ya-b/dsh-web-open-access
verified

Install method: GitHub · sandbox install verified (L4) · L5 pending

Verification & Compatibility

Records are archived per dsh version under test: each card shows the newest real L1–L5 verdicts on that version (static levels included; fall back to all-time newest with a carried note when absent).

External credentials (plugin-level): none detected

Per-dsh-version verification (L1–L5)
dsh 0.1.3-alpha.1current2026-09-07L5 pending
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.1
  • • Plugin artifact: github · https://github.com/ya-b/dsh-web-open-access (version unstated)
Levels (newest real verdicts on this version)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Not tested
Sandbox install passed (L4)
L5 pending

ID: dsh-web-open-access@c0955c@dsh0.1.3-alpha.1 · profile: l4-sandbox

Issued: 2026-09-07 · expires: 2026-09-14

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-07
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-07
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:ya-b/dsh-web-open-access · channel GitHub source · outcome ran · exit 0
check took: 2.3s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:ya-b/dsh-web-open-access · channel GitHub source · outcome ran · exit 0
check took: 2.3s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:ya-b/dsh-web-open-access · channel GitHub source · outcome ran · exit 0
check took: 2.3s
L5 · Run tested– Not tested

This level was not executed in this scan.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-web-open-access.svg)](https://www.dsh.so/artifact/dsh-web-open-access/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-web-open-access.svg)](https://www.dsh.so/artifact/dsh-web-open-access/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSEDdbd81c
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium
plugin version0.1.2-open-accessdsh manifest
scanned commitdbd81c731b7f2026-09-07
latest commitdbd81c731b7f
vet verdictclean · git

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-09-06 · activity: Active

• Repo created: 2026-09-06

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/ya-b/dsh-web-open-access

Was this page helpful?