instruction-scan avatar

instruction-scan

PluginDeveloperFileVision / OCR
Verification
L1 · Found
Security
Low
Health
Active
Trust
Unrated

What it doesAI

Selectively overrides DSH's built-in AGENTS.md instruction injection using configurable four-layer scanning, enabled only for user-selected presets.

  • Four scanning layers: cwd, project, parents, global
  • scanParents walks every ancestor to root, no depth limit
  • User selects presets in Web GUI; disable restores built-in

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:sidleo/instruction-scan

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUMe5c564
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·0 medium·80 score
plugin version0.2.4dsh manifest
scanned commite5c564fdc74f2026-08-22
latest commit581a8697777a
vet verdictsuspicious · npmscore 80

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R2
index.js:243
new Function / new AsyncFunction 动态执行
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-22 · activity: Active

• Repo created: 2026-08-22

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/sidleo/instruction-scan

Was this page helpful?