huaweicloud-devkit avatar

huaweicloud-devkit

Official Huawei Cloud plugin for AI agents — skills, MCP tools, safety guardrails, and cloud sandbox to help AI agents build, deploy, and operate on Huawei Cloud securely.

PluginDeveloperNetworkSecurity
Verification
L5 · Run tested
Passed
Risk
Medium
Health
Active
Trust
Silver

What it doesAI

Official Huawei Cloud plugin for AI agents to securely build, deploy, and operate on Huawei Cloud with skills and MCP tools.

  • Provides Huawei Cloud skills and MCP tools for AI agents
  • Includes safety guardrails and a cloud sandbox
  • Supports secure build, deploy, and operate workflows

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add huaweicloud-devkit
verified 1.1.1

Install method: npm · sandbox install verified (L5)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.3-alpha.2
current
1.1.1

✓ = L5 runtime verified · ◐ = L4 testing (install passed · L5 runtime pending) · ○ not a dsh plugin (nothing mounts) · ✗ failed · · untested (never assumed compatible)

Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified◐ L4 testing · install passed○ no plugin features✗ failed
1.1.1npm✓ 1 runtime-verified2026-09-09

huaweicloud-devkit

dsh 0.1.3-alpha.2current2026-09-09L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: npm · huaweicloud-devkit@1.1.1
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.3-alpha.2

ID: huaweicloud-devkit@1.1.1@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-09 · expires: 2026-09-16

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-09
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-09
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec huaweicloud-devkit · channel npm package · outcome ran · exit 0
check took: 7.3s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec huaweicloud-devkit · channel npm package · outcome ran · exit 0
check took: 7.3s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec huaweicloud-devkit · channel npm package · outcome ran · exit 0
check took: 7.3s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec huaweicloud-devkit · install mode reused L4 scratch
check took: 114ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-09
ready line dsh web: http://127.0.0.1:58655/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-09
path / · HTTP 200 · took 114ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-09
verdict active · entries 150
match: include:huaweicloud-devkit · @deepseek-ai/dsh-mcp-client · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/huaweicloud-devkit.svg)](https://www.dsh.so/artifact/huaweicloud-devkit/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/huaweicloud-devkit.svg)](https://www.dsh.so/artifact/huaweicloud-devkit/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM0fad14
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·6 high·28 medium
plugin version1.1.2dsh manifest
scanned version1.1.2npm2026-09-10
current version1.1.2same version
vet verdictsuspicious · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R10
package.json
install 钩子:package.json scripts.postinstall(安装期任意代码执行面)
high
R11
session-manager.mjs:718
解码还原的敏感路径(template):sandbox deploy nginx: nginx is not installed. Install it first: Detect OS: source /etc/os-release && echo $ID apt: s
high
R11
session-manager.mjs:718
解码还原的敏感路径(template):sandbox deploy nginx: nginx is not installed. Install it first: Detect OS: source /etc/os-release && echo $ID apt: s
high
R11
session-manager.mjs:718
解码还原的敏感路径(template):sandbox deploy nginx: nginx is not installed. Install it first: Detect OS: source /etc/os-release && echo $ID apt: s
high
R11
session-manager.mjs:718
解码还原的敏感路径(template):sandbox deploy nginx: nginx is not installed. Install it first: Detect OS: source /etc/os-release && echo $ID apt: s
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-09-08 · activity: Active

• Repo created: 2026-09-08

• Stars: ★ 45 · Forks: 11

• Health: Active — committed within last 30 days

Source

GitHub: github.com/huaweicloud/huaweicloud-devkit

Was this page helpful?