Security scan report
Every plugin in the registry gets an automated static scan for suspicious patterns — hardcoded secrets, data exfiltration, destructive commands, obfuscated code and more. Here's what the latest scan found, in plain language.
The ecosystem is largely healthy. Most plugins (60%) have no serious static findings. 15 plugins show critical-risk characteristics (secrets, exfiltration, destructive or obfuscated patterns) and 498 more have critical-severity findings — review them before installing.
51 plugins not yet scanned.
What the scan looks for
The most common findings across all plugins, explained in plain language.
The plugin runs shell commands or spawns subprocesses. Common in CLI/terminal plugins, but worth knowing.
Usually legitimate for terminal tools — mapped to "needs review" rather than high risk.
The plugin evaluates code at runtime (eval, new Function). Powerful, but harder to audit.
Usually legitimate; mapped to "needs review" unless combined with other risk.
The plugin contains commands that can delete files or modify critical system areas (e.g. rm -rf, chmod 777).
High risk — understand exactly what it touches before running.
Parts of the code are deliberately hard to read (encoded blobs, fromCharCode tricks), making review difficult.
Obfuscation is a red flag — what is it hiding?
The plugin contains what looks like an API key, token, or private key written directly in its source code.
Anyone with access to the repo could use this credential. Treat with caution.
Note: shell/subprocess and dynamic code execution are common in CLI & terminal plugins, so they're grouped under "high risk" rather than critical risk.
Critical-risk plugins
15 plugins with secrets, exfiltration, destructive or obfuscated patterns
| Plugin | What it is | Risk | Rule hits |
|---|---|---|---|
| dsh-cyber-sec★ 1 | Authorized security-assessment profile for DeepSeek Harness: scoped network tools, container-backed shell, authorization guard, durable evidence, 21 security skills, 7 specialist subagents | Critical | 11 critical · 6 warning(Destructive commands) |
| dsh-auto-approve★ 3 | Conservative auto-approval preset for DeepSeek Harness sandbox escalations | Critical | 7 critical · 1 warning(Destructive commands) |
| dsh-clawrouter★ 2 | A second brain for your DeepSeek Harness agent — strong-model review before risky tool calls, plus 70 models from one wallet. | Critical | 6 critical(Destructive commands) |
| dsh-remote★ 6 | Remote-access assistant for DeepSeek Harness: /remote command and settings page printing the exact SSH tunnel / reverse-tunnel / reverse-proxy commands (harness intentionally binds loopback only) | Critical | 4 critical(Destructive commands) |
| dsh-terminal-panel★ 2 | A manual Terminal tab for the DeepSeek Harness (dsh) web UI — run commands on the host machine, persistent cwd, sudo password prompt, command history.现在可以在web界面内直接执行命令行了 | Critical | 4 critical(Destructive commands) |
| DeepSeek-Harness-linux-★ 1 | 一个基于官方WebUI二改的Linux桌面端,内置了一个外挂视觉插件(需手动接入API Key),已经迭代了四个版本,可能还是有些小毛病,不过目前用下来暂时没有什么大问题。 | Critical | 4 critical · 13 warning(Destructive commands) |
| dsh-security-scan★ 1 | No description provided. | Critical | 3 critical(Hardcoded secrets) |
| dsh-desktop★ 4 | Desktop shell for DeepSeek Harness Web GUI — auto-installs dsh, native macOS tray, packaged for macOS & Windows. | Critical | 2 critical · 2 warning(Obfuscated code) |
| DeepSeek-harness-wecom★ 4 | WeCom AI Bot text and image bridge for DeepSeek Harness | Critical | 2 critical(Obfuscated code) |
| dsh-openclaw-acp★ 1 | DeepSeek Harness bundle for OpenClaw and WeChat over ACP | Critical | 2 critical(Hardcoded secrets) |
| dsh-image-to-path★ 1 | DSH 插件:让纯文本模型对话也能拖图/贴图——图片自动保存到会话工作区,以文件路径交给模型(多模态模型不受影响) | Critical | 2 critical(Obfuscated code) |
| DeepSeek-harness-lark★ 0 | Feishu and Lark text and image channel plugin for DeepSeek Harness | Critical | 2 critical(Obfuscated code) |
| zeromd★ 32 | Obsidian 零成本同步:iPhone ↔ Mac,GitHub 自动备份。本地优先 + 长期积累。|Local First. Zero-cost Obsidian sync across iPhone, Mac & GitHub. Let knowledge grow over time. | Critical | 1 critical(Destructive commands) |
| DeepSeek-harness-qqbot★ 5 | QQ Bot text and image channel plugin for DeepSeek Harness | Critical | 1 critical(Obfuscated code) |
| dsh-plugin-hub★ 2 | Plugin Store for DeepSeek Harness (DSH): a graphical app-store inside the Harness Web UI — browse, search and one-click install GitHub dsh-plugins (topic:dsh-plugin / #dsh-plugin repos), with local ratings, dependency impact graphs, audit logging and a plugin scaffold guide. | Critical | 1 critical · 1 warning(Hardcoded secrets) |
Automated heuristic scan — may produce false positives. Not a manual review, never an endorsement.
High-risk plugins
498 plugins with critical-severity rule hits (code execution / shell / install) · 84 more with warnings only
| Plugin | What it is | Risk | Rule hits |
|---|---|---|---|
| dsh-desktop★ 21 | DeepSeek Harness Desktop 是一款社区维护的非官方第三方桌面客户端,通过直接加载官方 Web UI,为普通用户提供开箱即用的独立桌面体验:它可以自动复用本机已运行的官方实例,也可以使用安装包内置的 dsh 运行时启动服务,无需用户额外安装 Node.js 或 CLI,并提供智能连接、远程实例连接、托盘常驻、运行时监护和异常恢复等桌面增强。 | High | 17 critical · 3 warning(Dynamic code execution, Shell / subprocess) |
| dsh-hdc-bridge★ 4 | DSH 原生鸿蒙设备桥:hdc 工具让 Agent 完成截图-看图-装包-验证的闭环调试 / DSH-native HarmonyOS device bridge | High | 17 critical(Shell / subprocess, Dynamic code execution) |
| DeepSeek-Harness-Desktop★ 2 | dsh-desktop: DeepSeek Harness 桌面插件 - click-to-launch Codex-like native window over the live dsh web UI. Everything is a plugin - this one is the window. | High | 16 critical · 6 warning(Dynamic code execution, Shell / subprocess) |
| DSH-Desktop★ 18 | DSH-Desktop | High | 15 critical · 1 warning(Dynamic code execution, Shell / subprocess) |
| DSH-Plugin-Market★ 3 | DeepSeek Harness 插件市场:精选目录 + GitHub 实时浏览、中英翻译搜索、安装前静态安全审计闸门。Plugin market for DeepSeek Harness with a pre-install security audit gate. | High | 15 critical(Shell / subprocess, Dynamic code execution) |
| dsh-wsl-workspace★ 2 | WSL workspace support for DeepSeek Harness——无缝的 WSL 工作区使用体验,无需在 WSL 之中再安装一个dsh,安装该插件后在 GUI 里直接添加 WSL 工作区即可。WSL workspace support for DeepSeek Harness — Enjoy a seamless WSL workspace experience without needing to install dsh inside WSL. Once this plugin is installed, you can directly add a WSL workspace right from the GUI. | High | 15 critical(Shell / subprocess, Dynamic code execution) |
| DSH-Plugins-Marketplace★ 28 | DSH插件市场 / DSH Plugin Marketplace: 在 DeepSeek Harness Web GUI 中一键浏览、安装与更新 GitHub topic:dsh-plugin 的全部插件 | browse, install & update all GitHub dsh-plugin plugins in the DSH Web GUI | High | 13 critical(Shell / subprocess, Dynamic code execution) |
| dsh-toy★ 26 | Toy Control Protocol for DSH | High | 12 critical(Dynamic code execution, Shell / subprocess) |
| dsh-side-panel★ 17 | DSH 侧边栏,集成文件浏览器、终端和 Git 审查,方便预览文件。 | High | 12 critical(Dynamic code execution, Shell / subprocess) |
| dsh-sentinel★ 6 | Condition-driven wakeup for DeepSeek Harness: durable file/command/http/process/webhook watches that wake the agent, with dock, sidebar branch, and a global dashboard. | High | 11 critical(Dynamic code execution, Shell / subprocess) |
| dsh-plugin-workshop★ 14 | Steam Workshop-style plugin browser for the DeepSeek Harness (DSH) Web UI - zero-server: GitHub-powered search, trending windows, Chinese search & bilingual translation, plugin-signature filtering, and smart one-click install/update/uninstall with an installed-plugins manager. | High | 10 critical · 1 warning(Shell / subprocess, Dynamic code execution) |
| dsh-desktop-tools★ 2 | DeepSeek Harness 桌面端 + 插件社区 + Agent 社区(270 个开源中文角色预设) | High | 10 critical · 1 warning(Shell / subprocess, Dynamic code execution) |
| plugin-registry★ 35 | DSH 插件生态基建:薄控制台(浏览器面板管理官方 repository 插件,0 patch)+ make-dsh-plugin skill 官方插件开发引导 | High | 10 critical(Dynamic code execution, Shell / subprocess) |
| dsh-vscode★ 2 | DeepSeek Harness for VS Code: right-side chat agent that reads, edits, and runs your project — like Claude Code / Codex / Copilot. | High | 10 critical(Shell / subprocess, Dynamic code execution) |
| dsh-server-deployment★ 2 | 服务器端部署:DeepSeek Harness Web 多用户网关(登录门户 / 每用户实例隔离 / 交付文件抽屉)。部署于远程服务器,用户通过浏览器访问,非本机工具。 | High | 9 critical · 10 warning(Dynamic code execution, Shell / subprocess) |
| Dcode★ 1 | Deepseek-harness 桌面端 | High | 9 critical · 9 warning(Dynamic code execution, Shell / subprocess) |
| superpowers-dsh★ 16 | Superpowers skills for DeepSeek Harness: TDD, debugging, planning, and collaboration skills adapted from obra/superpowers | High | 9 critical · 6 warning(Shell / subprocess, Dynamic code execution) |
| dsh-ssh★ 4 | SSH remote-execution plugin for DeepSeek Harness: ProxyJump chain, SFTP filesystem, subprocess and PTY over ssh2 | High | 9 critical(Shell / subprocess) |
| dsh-doctor★ 3 | DSH 插件:flutter-doctor 风格诊断与修复(安装级 + harness 内检查,安全自动修复)。官方 repository-plugin(.dsh-plugin 格式) | High | 9 critical(Shell / subprocess, Dynamic code execution) |
| dsh-plugin-market★ 2 | DeepSeek Harness plugin market - browse, search & install dsh-plugin topic plugins (dsh 插件市场:浏览/搜索/安装插件) | High | 9 critical(Dynamic code execution, Shell / subprocess) |
Showing the 20 most severe high-risk plugins (sorted by rule hits). Browse all 498 high-risk plugins — or view this week's full report.
Note: "critical" in the Rule hits column is the severity of the matched rules (dynamic code execution, shell / subprocess — common in CLI & terminal plugins). It is not the plugin's risk tier: code-exec / shell / install hits rate High, while only secrets, exfiltration, destructive commands and obfuscation rate Critical.
What we scan, risk levels, and the four dimensions.
Every plugin's detail page shows its own scan report.
Dependency CVEs, sandboxed runtime tests, container installs — coming later.
Scans are automated heuristics — they are not a manual review and never an endorsement. Install third-party plugins at your own risk.