dshm_client avatar

dshm_client

deepseek harnes HarmonyOS PC client

PluginDesktopFile
Verification
L2 · Structured
Security
Medium
Health
Active
Trust
Silver

What it doesAI

HarmonyOS PC desktop client for DeepSeek Harness, wrapping the official web UI in ArkWeb with local service discovery and file bridging.

  • ArkUI native shell + ArkWeb full-screen web UI
  • Service discovery and launcher via loopback HTTP
  • File selection and download bridge

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:sol5766/dshm_client

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO AUDITWARNINGe6d79f
Automated review · daily
WARNING

No critical findings, but warning-level issues were detected (file writes, remote imports, base64 decoding, downloads).

0 critical·2 warning·1 info·3 files scanned
plugin version
scanned commite6d79f78e6512026-08-20
latest commite6d79f78e651

The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Second-opinion scan (vet · parallel evaluation)
vet: clean

vet verdict: vet: clean · score 94

  • R14 · medium [likely] — 脚本下载即执行:curl 下载落盘(脚本随包分发,安装/运行期任意代码执行面)

vet is advisory and does not change dsh’s four-tier level.

Risk: Medium0 critical · 2 warning · 1 info

• Static heuristic scan: done (3 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

High-risk findings · 2 / 2

  • warningHTTP request to a raw IP addressreference/launcher/start-dsh.sh:14
    for u in http://127.0.0.1:8080 http://127.0.0.1:3080; do
  • warningDownloads a file from the networkreference/launcher/start-dsh.sh:30
    if [ -n "$url" ] && curl -s -m 2 -o /dev/null "$url/"; then

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-20 · activity: Active

• Repo created: 2026-08-20

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/sol5766/dshm_client

Was this page helpful?