Daily security scan
Date · 2026-08-27 (UTC — plugins first indexed that day)
| Plugin | Risk | Verdict | C/W/I | Manifest | Indexed |
|---|---|---|---|---|---|
| dsh-prompt-injector dsh 通用每轮上下文注入插件:设置页管理提示词清单,每轮对话把每条启用提示词以「上下文注入」提醒行注入模型上下文,让纪律规则(例如 图谱消费/wiki 先查/记忆召回)可靠生效。 | low | pass | 0/0/0 | 0/0 | 2026-08-27 03:02 |
| dsh-obsidian-agent-wiki Searchable SQLite-indexed Obsidian memory for DSH | low | pass | 0/0/2 | 0/0 | 2026-08-27 16:21 |
| dsh_plugin_file_attach Add files to context | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-cognitio 纠错驱动的认知架构插件:分层记忆 + 哨兵自动提醒 + 纠错进化 + 审批仲裁。让 AI 记得你的规矩,换模型换预设都有效;所有自动沉淀,你批准才生效。 | low | pass | 0/0/5 | 0/0 | 2026-08-27 16:21 |
| dsh-float Floating minimal-mode DSH plugin: a transparent terminal TUI over dsh web in a borderless Electron window. | medium | warn | 1/3/7 | 0/0 | 2026-08-27 16:21 |
| dsh-rich-context Agent instruction manager for DSH — edit and template the AGENTS.md files the harness actually reads (global + per-workspace) | low | pass | 0/0/5 | 0/0 | 2026-08-27 16:21 |
| dsh-context-tree Reusable trajectory-tree context, exact-turn forks, and bounded cross-session recall for DSH | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-question-rail DSH web plugin: 模仿 deepseek 网页版界面右侧的问题条 — 右缘一条竖向问题栏,列出当前会话每一轮的用户提问,点击平滑滚动定位。DSH right-edge question rail. | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-access-review-proof | medium | warn | 0/1/0 | 0/0 | 2026-08-27 16:21 |
| dsh-workspace-explorer-picker | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-memory Persistent, searchable, per-project memory for the DSH: decisions, rules, and session context in a queryable DuckDB file, with the rule set injected into every model request — plus a full management UI in the Web Client. | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| vibegap Mini-window for the gaps in vibe coding: vocabulary flashcards (and more panels) that auto-appear while your AI coding agent runs | medium | warn | 0/2/7 | 0/0 | 2026-08-27 16:21 |
| dsh-plugin-autoqueue DSH 无人值守任务队列插件:丢 .md 进收件箱 → AI 自动执行 → 产出报告 | medium | warn | 0/3/13 | 0/0 | 2026-08-27 16:21 |
| dsh-gacha-viz Genshin Impact gacha history visualizer and pity probability calculator for DSH (DSH plugin) | low | pass | 0/0/6 | 0/0 | 2026-08-27 16:21 |
| dsh-steer-button Queue, Steer, and Backlog for DSH. More diverse way to interact with the agent while it's running. | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-subagent-ui Searchable workspace subagent manager for DSH Web | low | pass | 0/0/2 | 0/0 | 2026-08-27 16:21 |
| dsh-image-viewer Zoom, pan, download, gallery, and region-note image viewing for DSH. | medium | warn | 0/2/3 | 0/0 | 2026-08-27 16:21 |
| dsh-code-coverage 解析 DSH session 日志归因 AI 生成文件,叠加 c8 覆盖率,产出 AI vs 人工代码覆盖率对比、高危未测文件清单与信任分。 | medium | warn | 0/1/0 | 0/0 | 2026-08-27 16:21 |
| dsh-orchestrator DSH bundle for one-shot Claude Code and GitHub Copilot Gemini delegation through native subscription logins. | medium | warn | 0/2/0 | 0/0 | 2026-08-27 16:21 |
| dsh-duty-separation-proof Offline content-addressed duty-separation evidence for supplied DSH workflow receipts | medium | warn | 0/1/0 | 0/0 | 2026-08-27 16:21 |
| dsh-essentials-bundle DSH Web UI all-in-one essentials pack — a bundled collection, not a single-feature plugin: chat wallpaper / token usage stats / session manager / per-turn undo with artifact rollback / built-in file explorer & editor. Zero-dependency, inject-only, never overrides core. | medium | warn | 1/1/7 | 0/0 | 2026-08-27 16:21 |
| dsh-workspace-wsl | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-dream DSH host plugin: scheduled background 'dream' (memory consolidation) passes for DSH. npm: dsh-dream | medium | warn | 0/3/0 | 0/0 | 2026-08-27 16:21 |
| dsh-quick-commands | medium | warn | 1/0/7 | 0/0 | 2026-08-27 16:21 |
| dsh-cron Unattended scheduled jobs for the DSH: agent/command tasks on cron schedules | medium | warn | 1/0/3 | 0/0 | 2026-08-27 16:21 |
| dsh-safe-install | medium | warn | 3/1/6 | 0/0 | 2026-08-27 16:21 |
| dsh-gentle-engram DSH adapter for Engram — persistent memory bridge built with Cordis. | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-client-ui-connection-status DSH Web client plugin: a corner pill showing live connection state for the DSH Web UI. npm: dsh-client-ui-connection-status | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-plugin-portal Zero-dependency static portal rendering the @perrylink DSH plugin ecosystem as grouped cards: one page, no build step, no runtime framework. | low | pass | 0/0/0 | 0/0 | 2026-08-27 16:21 |
| dsh-credential-retirement-proof Evidence-only DSH plugin for credential retirement settlement | medium | warn | 0/1/0 | 0/0 | 2026-08-27 16:21 |
| dsh-office-com DSH plugin: COM-driven real Office automation (VBA/pivot/recalc/layout) | medium | warn | 1/0/7 | 0/0 | 2026-08-27 16:21 |
| geometry-knowledge 几何论(共扼谱几何 CSG)知识库插件 for DSH: 纯离线 BM25 检索,零运行时依赖 | low | pass | 0/0/4 | 0/0 | 2026-08-27 16:21 |
| dsh-balance 为 DSH 提供持久化的余额与用量显示插件,让您随时掌握资源消耗情况,无需离开工作区。 | low | pass | 0/0/5 | 0/0 | 2026-08-27 16:21 |
Static heuristic scan + manifest audit — not a full security audit; no code execution or dependency resolution. Risk tiers match the site model: critical in secrets/exfil/destructive/mining is "critical"; other critical-level findings and warnings are "medium" (needs review).
Daily report archive
13 reportsWhat does this daily report cover?
This report covers plugins first indexed by dsh.so on 2026-08-27. For each new plugin it records the name, risk tier, scan verdict, critical/warning/info findings, manifest audit signals, and index time. Plugins that were already in the registry before that date are not included.
How are the risk tiers assigned?
Risk tiers follow the same public model used across the site. Critical is reserved for secrets, exfiltration, destructive commands, or mining; other critical-level findings and warnings are reported as medium (needs review), and low for plugins with no meaningful findings.
Why is this not a full security audit?
The daily scan is a static heuristic scan plus manifest audit. It does not execute code or resolve dependencies, so it cannot prove that a plugin is safe. Use the report to prioritize inspection, not to replace it.
Source: dsh.so security standards · Maintained by dsh.so · Published