dsh-plugin-vet avatar

dsh-plugin-vet

@wulun811 · Tool · Registry
Unverified

Trust pipeline for deepseek-harness plugins: deterministic static scan (11 rules) + LLM-driven audit protocol + two-part scorecard, with optional runtime guard (T1 sentinel / T2 fs & child_process hooks) and honeypot decoys. Monitor-and-alert only — vet never blocks or kills on its own.

AutomationSecurityAI ModelsNew2forked 0
Install

This plugin is a GitHub repository with the dsh-plugin topic — the repository README is the authoritative install source. Use the template below, adapting the package name / path from the README:

dsh plugin --profile web add $dsh-plugin-vet

Local development? dsh --profile web --patch ./cordis.yml with an absolute plugin path — see Plugin Development.GitHub source? dsh plugin --profile web add github:$wulun811/$dsh-plugin-vet — needs a prepare script in the repo (see packaging).

DSH.SOHIGH-RISKSCAN15 FILES
690bcf
Automated review · daily
HIGH-RISK

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

1 critical·0 warning·0 info·15 files scanned
code-exec ×1
scanned commit690bcf9d17752026-08-16
latest commit

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Facts
Repositorywulun811/dsh-plugin-vet
LicenseMIT
CategoryTool
StatusUnverified
Last commit2026-08-16
Indexed2026-08-16
About this entry: verified to exist via the GitHub API on 2026-08-13. Compatibility is the author's claim; dsh.so has not independently tested it. See the changelog for version compatibility.
Join the community

Questions or feedback? Official Discussions is the project’s canonical support channel; Discord has an active community. dsh.so itself improves via plugin submissions and your feedback.

Was this page helpful?