Daily security scan

Date · 2026-08-22 (UTC — plugins first indexed that day)

12
added
0
critical
6
medium
6
low
PluginRiskVerdictC/W/IManifestIndexed
agentscars
A public commons of real AI-agent failure patterns ("scars") — searchable via API and MCP. Live at agentscars.com. Private for now, open-sourcing once ready.
lowpass0/0/40/02026-08-22 00:40
dsh-plugin-session-manager-custom
DeepSeek Harness Web plugin for local session data management
mediumwarn0/1/20/02026-08-22 00:40
dsh-image-tiler
DSH插件:将大图像分割成带标签的800像素图块,并保留概览图,同时保留视觉模型所需的细节。包含设置卡。DSH plugin: slice large images into labeled 800px tiles + overview, preserving detail for vision models. Settings card included.
lowpass0/0/00/02026-08-22 00:40
dsh-hooks-git-ai
A DeepSeek Harness plugin that records which files the agent edited, with which model, and in which session into git-ai
lowpass0/0/00/02026-08-22 00:40
dsh-font-size
DSH Web GUI plugin: 'Conversation font size' slider (12-22 px) in Settings → General.
lowpass0/0/40/02026-08-22 00:40
dsh-jj-vcs
Jujutsu version-control plugin and skill for DeepSeek Harness multi-agent teams
mediumwarn0/3/30/02026-08-22 00:40
dsh-pm
dsh-pm is the ChunSun × DeepSeek Harness reference plugin: an AI-native project-delivery loop driven by ChunSun. Requirements / Runs / Steps / acceptance scenarios & cases / work-memory, a session delivery panel, and 28 chunsun_* model tools — with the platform as the single source of truth. MIT.
lowpass0/0/00/02026-08-22 00:40
dsh-novel-writing
DSH (DeepSeek Harness) 自动化小说写作发布流水线插件:claude-writing-workflow 迁移版 agent 预设 + 小说工作台(可视化/实时渲染/章节编辑)+ 多平台发布配置与数据驱动优化闭环
mediumwarn1/0/40/02026-08-22 00:40
dsh-one-gateway
Private DSH One Gateway — loopback, identity-first ingress for DeepSeek Harness
lowpass0/0/20/02026-08-22 00:40
dsh-lanchat
mediumwarn2/1/100/02026-08-22 00:40
dsh-android
DeepSeek Harness plugin for Android — build, run, and interact with a live emulator or USB device stream inside a conversation, driven entirely through adb.
mediumwarn0/2/70/02026-08-22 00:40
Dsh-dev
Version-aware workspace core for building DeepSeek Harness plugins
mediumwarn0/5/80/02026-08-22 00:40

Static heuristic scan + manifest audit — not a full security audit; no code execution or dependency resolution. Risk tiers match the site model: critical in secrets/exfil/destructive/mining is "critical"; other critical-level findings and warnings are "medium" (needs review).

Daily report archive

8 reports
← Back to security reports

What does this daily report cover?

This report covers plugins first indexed by dsh.so on 2026-08-22. For each new plugin it records the name, risk tier, scan verdict, critical/warning/info findings, manifest audit signals, and index time. Plugins that were already in the registry before that date are not included.

How are the risk tiers assigned?

Risk tiers follow the same public model used across the site. Critical is reserved for secrets, exfiltration, destructive commands, or mining; other critical-level findings and warnings are reported as medium (needs review), and low for plugins with no meaningful findings.

Why is this not a full security audit?

The daily scan is a static heuristic scan plus manifest audit. It does not execute code or resolve dependencies, so it cannot prove that a plugin is safe. Use the report to prioritize inspection, not to replace it.

Source: dsh.so security standards · Maintained by dsh.so · Published

Was this page helpful?