Wangdefa.Memory avatar

Wangdefa.Memory

Wangdefa.Memory 是一个为企业级 Agent 设计的五层记忆体组件,采用「本地优先」的存储策略,达到轻量、可控、可解释。

PluginAI ModelsKnowledgeStorageUI & SkinsMemoryStorage
Verification
L2 · Structured
Security
Medium
Health
Active
Trust
Silver

What it doesAI

Local-first five-layer memory component for enterprise agents to store, retrieve and evolve long-term memory.

  • Five-layer memory: cognition, inference, thinking, experience, transmission
  • Local-first no-vector memory using feature tags
  • Self-cleaning and iterative memory evolution

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:VinsonWild/Wangdefa.Memory

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO AUDITMEDIUM608da5
Automated review · daily
MEDIUM

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

3 critical·1 warning·0 info·4 files scanned
shell ×2code-exec ×1
plugin version1.1.0dsh manifest
scanned commit608da5a6852a2026-08-20
latest commit608da5a6852a

The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Second-opinion scan (vet · parallel evaluation)
vet: suspicious

vet verdict: vet: suspicious · score 68

  • R10 · high [likely] — install 钩子:package.json scripts.postinstall(安装期任意代码执行面)
  • R7 · high [likely] — 硬编码密钥:环境变量密钥赋值

vet is advisory and does not change dsh’s four-tier level.

Risk: Medium3 critical · 1 warning · 0 info

• Static heuristic scan: done (4 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

High-risk findings · 4 / 4

  • criticalChild process module usage (Node.js)scripts/postinstall.js:5
    import { execSync } from 'child_process';
  • criticalShell command execution (exec / execSync)scripts/postinstall.js:39
    execSync(`curl -L -o /tmp/WangdefaMemory.zip ${url}`, { stdio: 'inherit' });
  • criticalShell command execution (exec / execSync)scripts/postinstall.js:47
    execSync(`unzip -o /tmp/WangdefaMemory.zip -d ${installDir}`, { stdio: 'inherit' });
  • warningDownloads a file from the networkscripts/postinstall.js:39
    execSync(`curl -L -o /tmp/WangdefaMemory.zip ${url}`, { stdio: 'inherit' });

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-20 · activity: Active

• Repo created: 2026-08-20

• Stars: ★ 2 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/VinsonWild/Wangdefa.Memory

Was this page helpful?