dsh-zhihu-tools avatar

dsh-zhihu-tools

知乎数据开放平台 DSH 静态双面插件:17工具+精美卡片+串行化限流。QQ群1017854502 https://qm.qq.com/q/RAHJuyhQQ

PluginDataWeb search
Verification
L4 · Install tested
Passed
Risk
Critical
Health
Active
Trust
Silver

What it doesAI

DSH plugin that provides 17 tools to fetch Zhihu data (hot, search, etc.) with local settings and browser cards.

  • 17 tools for Zhihu open platform data access
  • Includes local settings page for credential configuration
  • Browser-side shows 4 tool cards with elegant design

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:leolee9086/dsh-zhihu-tools
verified

Install method: GitHub · sandbox install ok, web smoke failed (L5)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.3-alpha.2
current
artifact version unstated

✓ = L5 runtime verified · ◐ = L4 testing (install passed · L5 runtime pending) · ○ not a dsh plugin (nothing mounts) · ✗ failed · · untested (never assumed compatible)

Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified◐ L4 testing · install passed○ no plugin features✗ failed
artifact version unstatedgithub1 failed2026-09-09

https://github.com/leolee9086/dsh-zhihu-tools

dsh 0.1.3-alpha.2current2026-09-09L5 · failed
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: github · https://github.com/leolee9086/dsh-zhihu-tools (version unstated)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Failed
Sandbox install failed
L5 · failed

ID: dsh-zhihu-tools@25a36b@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-09 · expires: 2026-09-16

View checks & evidence
L1 · Found✓ Passed
L2 · Structured✓ Passed
L3 · Install spec✓ Passed
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:leolee9086/dsh-zhihu-tools · channel GitHub source · outcome ran · exit 0
check took: 2.4s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:leolee9086/dsh-zhihu-tools · channel GitHub source · outcome ran · exit 0
check took: 2.4s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:leolee9086/dsh-zhihu-tools · channel GitHub source · outcome ran · exit 0
check took: 2.4s
L5 · Run tested✕ Failed
Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:leolee9086/dsh-zhihu-tools · install mode reused L4 scratch
check took: 0ms
Web boot ready✕ Failed
plugin tree failed to load
HTTP endpoint served✕ Failed

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-zhihu-tools.svg)](https://www.dsh.so/artifact/dsh-zhihu-tools/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-zhihu-tools.svg)](https://www.dsh.so/artifact/dsh-zhihu-tools/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETCRITICAL79a6f8
Automated review · daily
CRITICAL

Vet verdict is critical: blocking-level risk. Review before use.

6 critical·0 high·0 medium
plugin version0.1.0dsh manifest
scanned version0.1.0git2026-09-10
current version0.1.0same version
vet verdictcritical · git

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
critical
R3
.shot-2.mjs:20
直接访问 process.exit(Node 能力逃逸通道)
critical
R3
.shot-1.mjs:18
直接访问 process.exit(Node 能力逃逸通道)
critical
R3
.shot-1.mjs:32
直接访问 process.exit(Node 能力逃逸通道)
critical
R3
.shot-3.mjs:37
直接访问 process.exit(Node 能力逃逸通道)
critical
R3
.shot-4.mjs:38
直接访问 process.exit(Node 能力逃逸通道)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-29 · activity: Active

• Repo created: 2026-09-08

• Stars: ★ 2 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/leolee9086/dsh-zhihu-tools

Was this page helpful?