recowork avatar

recowork

Give your AI a workflow.

PluginAI ModelsAutomationMemory
Verification
L4 · Install tested
Passed
Risk
Critical
Health
Active
Trust
Silver

What it doesAI

Adds work standards, project facts, review criteria, and handoff structure so AI agents can finish, continue, and reuse work.

  • Layers work standards and project facts
  • Captures tasks, standards, review criteria, handoff
  • Works with existing AI agents, no runtime replacement

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:recoluan/recowork
verified

Install method: npm · sandbox install verified (L4) · web smoke unconfirmed (L5)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.3-alpha.2
current
artifact version unstated

✓ = L5 runtime verified · ◐ = L4 testing (install passed · L5 runtime pending) · ○ not a dsh plugin (nothing mounts) · ✗ failed · · untested (never assumed compatible)

Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified◐ L4 testing · install passed○ no plugin features✗ failed
artifact version unstatedgithub2026-09-09

https://github.com/recoluan/recowork

dsh 0.1.3-alpha.2current2026-09-09no plugin features
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: github · https://github.com/recoluan/recowork (version unstated)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Not tested
L2 static
Not tested
L3 static
Unknown
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs, but declares no dsh.bundle and mounts no capability — an ordinary npm dependency without plugin features
no plugin features

ID: recowork@978591@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-09 · expires: 2026-09-16

View checks & evidence
L1 · Found– Not tested

not in scope for web smoke; see prior standard-profile records

L2 · Structured– Not tested

not in scope for web smoke; see prior standard-profile records

L3 · Install spec? Unknown
Install command parsed? Unknown
Source: registry verification · Method: install spec parse · Captured 2026-09-08
no install command parsed
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-08
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:recoluan/recowork · channel GitHub source · outcome ran · exit 0
check took: 4.8s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:recoluan/recowork · channel GitHub source · outcome ran · exit 0
check took: 4.8s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:recoluan/recowork · channel GitHub source · outcome ran · exit 0
check took: 4.8s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:recoluan/recowork · install mode reused L4 scratch
check took: 42ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-09
ready line dsh web: http://127.0.0.1:62628/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-09
path / · HTTP 200 · took 42ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-09
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/recowork.svg)](https://www.dsh.so/artifact/recowork/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/recowork.svg)](https://www.dsh.so/artifact/recowork/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETCRITICALd3e7be
Automated review · daily
CRITICAL

Vet verdict is critical: blocking-level risk. Review before use.

1 critical·4 high·21 medium
plugin version4.1.0
scanned version4.1.0npm2026-09-10
current version4.1.0same version
vet verdictcritical · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
critical
R3
rw.js:2250
直接访问 process.exit(Node 能力逃逸通道)
high
R2
rw.js:6
require('http') 危险内置模块(执行/网络能力触达)
high
R2
rw.js:8
require('child_process') 危险内置模块(执行/网络能力触达)
high
R2
idea-to-project.test.cjs:7
require('node:child_process') 危险内置模块(执行/网络能力触达)
high
R2
import.test.cjs:6
require('node:child_process') 危险内置模块(执行/网络能力触达)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-09-08 · activity: Active

• Repo created: 2026-09-08

• Stars: ★ 5 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/recoluan/recowork

Was this page helpful?