2026-W38

Published 2026-09-14

← All reports
14977
scanned
0
critical
103
need review
14658
low risk

This week

Critical-risk plugins

0 plugins rated critical — vet-critical or blocking patterns (secrets / exfiltration / destructive / mining)

PluginRisk
None

Needs review (medium)

103 plugins rated medium — vet suspicious, or retired "high" hits like code execution / shell

PluginRisk
dsh-web-profile ★ 1Medium
dsh-smart-reminder ★ 0Medium
dsh-tmwebdriver ★ 0Medium
dsh-v-explorer ★ 1Medium
dsh-remote ★ 0Medium
claude-in-dsh ★ 3Medium
dsh-upgrade-kit ★ 1Medium
cli ★ 3Medium
dsh-remote ★ 0Medium
dsh-cordis-mcp ★ 2Medium
vision-toolkit-for-dsh-v0.1-maybe- ★ 1Medium
dsh-auto-classifier ★ 1Medium
dsh-launcher ★ 1Medium
dsh-balance-plugin ★ 60Medium
dsh-convmap ★ 2Medium
dsh-moodball ★ 1Medium
paper-workbench ★ 0Medium
dsh-balance ★ 3Medium
conjugate-spectral-geometry ★ 2Medium
dsh-better-tool-ui ★ 1Medium

Showing the 20 most severe.

Automated heuristic scan (static analysis) — a scalable first line of defense; may produce false positives. Not a manual review.

Weekly report archive

6 reports

What does this weekly report measure?

This report measures the automated static scan state of the dsh.so plugin registry during 2026-W38: the number of scanned plugins, the distribution across three tiers (low, medium, critical), and the plugins whose risk tier changed since the previous archive.

Why isn't this report an endorsement?

A report row reflects public repository metadata and heuristic rule matches, not a manual audit or runtime verification. False positives and false negatives are possible, so risk flags are a reason to inspect a plugin before install rather than a substitute for that inspection.

Source: dsh.so security standards · Maintained by dsh.so · Published

Was this page helpful?