npm-safe-forDSH avatar

npm-safe-forDSH

本地优先的 npm 包供应链安全扫描引擎,deepseek harness 插件版本

PluginSecurityCode reviewFileDatabase
Verification
L2 · Structured
Security
Medium
Health
Active
Trust
Silver

What it doesAI

Local-first npm supply chain security scanner for DeepSeek Harness, detecting vulnerabilities in packages.

  • Scans npm packages for known vulnerabilities
  • Uses SQLite for local-first storage
  • Performs static analysis of dependencies

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:nisconder/npm-safe-forDSH

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSED81d68f
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium·100 score
plugin version
scanned commit81d68f2218002026-08-22
latest commit81d68f221800
vet verdictclean · gitscore 100

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-08-22 · activity: Active

• Repo created: 2026-08-22

• Stars: ★ 2 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/nisconder/npm-safe-forDSH

Was this page helpful?