evoflux avatar

evoflux

Evoflux is an open-source, local-first workspace where AI agents build software, conduct deep research, automate browser tasks, and collaborate in parallel. Connect any model, keep control of your workspace and data, and take complex work from idea to completion—all in one place.

Ecosystem appAI ModelsBrowserAutomationNetworkWeb searchTerminal / ShellFile
Verification
L5 · Ecosystem app
Risk
Low
Health
Active
Trust
Silver

Install verification: Ecosystem app: not installed via dsh plugin add, so the L1-L5 plugin install-verification ladder does not apply; the security scan still runs.Install verification details →

What it doesAI

Open-source local-first workspace where AI agents build software, conduct research, and automate browsers.

  • AI agents build software in a local-first workspace
  • Conduct deep research and automate browser tasks
  • Connect any model, keep control of workspace and data
aiAIweb-searchAIterminalAIfileAI

Capability tags are AI-inferred or rule-extracted from the README (see badge) — vocabulary-limited, not install-verified. AI = inferred; README = literal keyword from the readme.

Installation

GitHub repository

Ecosystem apps are not installable via dsh plugin add: desktop / web shells install or deploy through their own release channel (GitHub Releases or the project site).

The level reads L5 · Ecosystem plugin / L5 · Ecosystem app per the three-way classification (the L1-L5 ladder does not rate them); the security scan still runs.

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.2.0-rc.1dsh 0.1.7-rc.2dsh 0.1.7-rc.1dsh 0.1.6-alpha.2dsh 0.1.6-alpha.1
v3.0.4·····
v3.0.3·····
v3.0.0·····
v2.0.9·····
v2.0.5·◼···
Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified○ ecosystem plugin◼ ecosystem app✗ failed
v3.0.4github2026-10-02

https://github.com/evoelsewhere/evoflux

Ecosystem app: not installed via dsh plugin add (a desktop / web shell) — its level reads L5 · Ecosystem app.

v3.0.3github2026-09-30

https://github.com/evoelsewhere/evoflux

◼prehistory2026-09-30ecosystem app
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: unknown
  • • Plugin artifact: github · https://github.com/evoelsewhere/evoflux#v3.0.3
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
No install verdict — an ecosystem app, not installable via `dsh plugin add`; ships through its own release channel (shown as L5 · Ecosystem app; the L1-L5 ladder does not rate it)
ecosystem app

ID: evoflux@v3.0.3@dshunknown · profile: l4-sandbox

Issued: 2026-09-30 · expires: 2026-10-07

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-10-02
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-10-02
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec github:evoelsewhere/evoflux#v3.0.3 · channel GitHub source · outcome ran · exit 0
check took: 14.7s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec github:evoelsewhere/evoflux#v3.0.3 · channel GitHub source · outcome ran · exit 0
check took: 14.7s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec github:evoelsewhere/evoflux#v3.0.3 · channel GitHub source · outcome ran · exit 0
check took: 14.7s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec github:evoelsewhere/evoflux#v3.0.3 · install mode reused L4 scratch
check took: 1.0s
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-30
ready line dsh web: http://127.0.0.1:57836/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-30
path / · HTTP 200 · took 1.0s
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-30
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

v3.0.0github2026-09-29

https://github.com/evoelsewhere/evoflux

Ecosystem app: not installed via dsh plugin add (a desktop / web shell) — its level reads L5 · Ecosystem app.

v2.0.9github2026-09-27

https://github.com/evoelsewhere/evoflux

Ecosystem app: not installed via dsh plugin add (a desktop / web shell) — its level reads L5 · Ecosystem app.

v2.0.5github2026-09-25

https://github.com/evoelsewhere/evoflux

◼dsh 0.1.7-rc.22026-09-25ecosystem app
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.2
  • • Plugin artifact: github · https://github.com/evoelsewhere/evoflux#v2.0.5
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
No install verdict — an ecosystem app, not installable via `dsh plugin add`; ships through its own release channel (shown as L5 · Ecosystem app; the L1-L5 ladder does not rate it)
ecosystem app

ID: evoflux@v2.0.5@dsh0.1.7-rc.2 · profile: l4-sandbox

Issued: 2026-09-25 · expires: 2026-10-02

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-10-02
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-10-02
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:evoelsewhere/evoflux#v2.0.5 · channel GitHub source · outcome ran · exit 0
check took: 18.8s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:evoelsewhere/evoflux#v2.0.5 · channel GitHub source · outcome ran · exit 0
check took: 18.8s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:evoelsewhere/evoflux#v2.0.5 · channel GitHub source · outcome ran · exit 0
check took: 18.8s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:evoelsewhere/evoflux#v2.0.5 · install mode reused L4 scratch
check took: 24ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-25
ready line dsh web: http://127.0.0.1:56625/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-25
path / · HTTP 200 · took 24ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-25
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/evoflux.svg)](https://www.dsh.so/artifact/evoflux/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSEDcb56a9
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium
plugin version—
scanned versionv3.0.4git2026-10-05
current versionv3.0.4same version
vet verdictclean · git

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-10-05 · activity: Active

• Repo created: 2026-08-03

• Stars: ★ 11 · Forks: 4

• Health: Active — committed within last 30 days

Source

GitHub: github.com/evoelsewhere/evoflux

Was this page helpful?