Security scan report
Every plugin in the registry gets an automated static scan for suspicious patterns — hardcoded secrets, data exfiltration, destructive commands, obfuscated code and more, using a vet-led three-tier risk model. Here's what the latest scan found, in plain language.
The ecosystem is largely healthy. Most plugins (100%) have no critical findings. 0 plugins are rated critical (vet-critical, or blocking secrets / exfiltration / destructive / mining patterns). 107 more need review — install only after inspecting them yourself.
34 plugins not yet scanned.
Risk model: vet-led three-tier
A second, independent static engine (@jieai/dsh-plugin-vet) is the primary judge. dsh's scan fills gaps it doesn't cover and acts as a hard guard on blocking patterns. Together they collapse to three tiers — low · medium · critical — the old "high" tier is retired.
vet judges low / medium / critical; the "high" tier no longer exists. dsh only raises to critical when it finds blocking patterns (secrets, exfiltration, destructive, mining) or backfills when vet is unavailable. Per-plugin detail pages show both the fused tier and the vet evidence.
What the scan looks for
The most common findings across all plugins, explained in plain language.
The plugin runs shell commands or spawns subprocesses. Common in CLI/terminal plugins, but worth knowing.
Usually legitimate for terminal tools — mapped to "needs review" rather than high risk.
The plugin evaluates code at runtime (eval, new Function). Powerful, but harder to audit.
Usually legitimate; mapped to "needs review" unless combined with other risk.
The plugin contains commands that can delete files or modify critical system areas (e.g. rm -rf, chmod 777).
High risk — understand exactly what it touches before running.
The plugin contains what looks like an API key, token, or private key written directly in its source code.
Anyone with access to the repo could use this credential. Treat with caution.
Parts of the code are deliberately hard to read (encoded blobs, fromCharCode tricks), making review difficult.
Obfuscation is a red flag — what is it hiding?
The plugin may send data to external endpoints (webhooks, tunnels, third-party servers).
Review what data could leave your machine before installing.
Note: shell/subprocess and dynamic code execution are common in CLI & terminal plugins, so they are grouped under "needs review" (medium) rather than critical risk.
Critical plugins
0 plugins rated critical — vet-critical or blocking patterns (secrets / exfiltration / destructive / mining)
No critical plugins found in the latest scan.
Automated heuristic scan — may produce false positives. Not a manual review, never an endorsement.
Needs review (medium)
107 plugins rated medium — vet suspicious, or dsh-only evidence that needs a second look
| Plugin | What it is | Risk | Rule hits |
|---|---|---|---|
| dsh-web-profile★ 0 | — | Medium | 3 critical · 4 warning(Shell / subprocess) |
| @dgagf111/dsh-hydrasearch★ 0 | TinyFish + AnySearch web search and fetch provider for DSH: one failover-chain provider with an operator-controlled backend priority and a settings card. | Medium | 3 critical · 3 warning(Hardcoded secrets) |
| @Justin-Mai/dsh-stock-view★ 1 | DSH 右上角行情盯盘插件:A 股 / ETF / 港股 / 美股 自选股 + 加密货币实时行情 | Medium | 3 critical(Hardcoded secrets) |
| dsh-smart-reminder★ 0 | Smart calendar reminder & schedule assistant for DSH Web GUI: lunar calendar, holidays, system notifications on macOS/Windows, and WeCom/platform push integration. | Medium | 3 critical(Shell / subprocess) |
| dsh-upgrade-kit★ 0 | DSH 装备升级套件:看钱(dsh-cost 费用面板)、看文件(file-preview 预览)、搜外网(research-mcp)、看图片(vision-bridge)。一条命令全装。 | Medium | 2 critical · 14 warning(Destructive commands) |
| dsh-tmwebdriver★ 0 | One tool, infinite reach: arbitrary JS in your real logged-in browser. Unlike fixed-action plugins, browser_execute_js does anything DevTools can — read, click, type, fill, navigate, screenshot, CDP. Plus list_tabs/snapshot/type. Zero-setup, self-healing. | Medium | 2 critical · 11 warning(Dynamic code execution) |
| dsh-remote★ 0 | Remote access suite for DSH: QR pairing, HMAC sessions, cloudflared tunnel and PWA. Zero installs on any device. | Medium | 1 critical · 27 warning(Shell / subprocess) |
| claude-in-dsh★ 3 | 在 dsh web 里用本机 Claude Code 驱动会话:原生渲染、权限档、模型/effort、命令面板、broker 托管进程 | Medium | 1 critical · 18 warning(Dynamic code execution) |
| cli★ 5 | AtlasCloud CLI installers and release artifacts | Medium | 1 critical · 8 warning(Shell / subprocess) |
| dsh-remote★ 0 | Operate DSH from your phone: self-hosted relay + desktop plugin tunnel with a mobile-adapted web UI. MIT | Medium | 1 critical · 6 warning(Shell / subprocess) |
| dsh-desktop★ 2 | DSH 桌面端(macOS / Windows):双击即用的官方 dsh「瘦壳」——不内置 dsh、首次运行自动安装,无需 Node/npm 等任何环境,带版本管理与回滚、App 内更新、插件管理与干净卸载。 | Medium | 1 critical · 5 warning(Destructive commands) |
| dsh-cordis-mcp★ 1 | DSH 插件:把 DSH 的动态 Cordis 工具集(inspect/define/run/stop/undefine)以 MCP 暴露给 Claude Code。端点强制身份认证,token 可在 DSH 设置页配置。 | Medium | 1 critical · 5 warning(Shell / subprocess) |
| vision-toolkit-for-dsh-v0.1-maybe-★ 1 | Zero-dependency vision OCR/Q&A toolkit (CLI + local web GUI) for OpenAI-compatible VLMs: Zhipu GLM, Qwen, OpenAI, OpenRouter, SiliconFlow | Medium | 1 critical · 4 warning(Dynamic code execution) |
| dsh-auto-classifier★ 1 | — | Medium | 1 critical · 3 warning(Shell / subprocess) |
| dsh-launcher★ 0 | macOS 程序坞一键启动 DSH 的快捷启动器 / One-click DSH launcher for macOS Dock | Medium | 1 critical · 3 warning(Destructive commands) |
| dsh-balance-plugin★ 64 | deepSeek 余额监控与用量统计(DSH 动态 Cordis 插件):余额监控 · 官方充值入口 · 用量统计 · 三方插件管理 | Medium | 1 critical · 2 warning(Shell / subprocess) |
| dsh-convmap★ 1 | DSH web 插件:在主对话区左缘中部渲染「对话地图」刻度(每条 = 一轮用户提问),hover 梯度展开并预览该轮提问/回复摘要,点击跳转(未渲染的老轮次自动分页加载后再跳),滚动时当前轮次自动高亮。 | Medium | 1 critical · 2 warning(Shell / subprocess) |
| paper-workbench★ 0 | — | Medium | 1 critical · 2 warning(Shell / subprocess) |
| conjugate-spectral-geometry★ 2 | Conjugate Spectral Geometry - Geometric Theory of quantum error correction: 12-volume/117-paper index + DeepSeek RAG knowledge AI (Open WebUI). | Medium | 1 critical · 1 warning(Shell / subprocess) |
| dsh-balance★ 2 | DSH web 插件:输入框下方状态栏展示当前供应商的余额/用量 —— DeepSeek 官方余额 + 本会话花费,Kimi Coding、OpenCode Go、GLM Coding Plan 等订阅用量(支持的供应商见 README)。按 provider 判断、2 秒轮询实时切换、5 分钟缓存。 | Medium | 1 critical · 1 warning(Shell / subprocess) |
Showing the first 20 medium plugins. Browse all 107 medium plugins — or view the report archive.
What we scan, and the three-tier vet-led risk model.
Every plugin's detail page shows its own 3-tier report.
Dependency CVEs and deeper runtime behavior tests — coming later.
Scans are automated heuristics — they are not a manual review and never an endorsement. Install third-party plugins at your own risk.