Daily security scan

Date · 2026-08-30 (UTC — plugins first indexed that day)

38
added
0
critical
9
medium
29
low
PluginRiskVerdictC/W/IManifestIndexed
dsh-wall-mcp-manager
mediumwarn0/1/30/02026-08-30 02:28
dsh-subagent-grok
One-shot Grok CLI subagent provider for DSH
mediumwarn1/0/00/02026-08-30 02:28
dsh-qr-share
DSH web plugin: a sidebar-footer QR-code button that lets a phone scan and re-issue the current browser's authenticated launch URL.
lowpass0/0/40/02026-08-30 02:28
dsh-code-runner
在 DSH-better-sidebar 中一键运行侧边栏代码文件,让代码可以在dsh终端中运行
lowpass0/0/40/02026-08-30 02:28
dsh-arxiv
DSH plugin: tiny read-only arXiv search + abstract fetch (Atom API, no PDF ingest)
lowpass0/0/00/02026-08-30 02:28
dsh-voice-input
语音输入插件 for DSH
lowpass0/0/00/02026-08-30 02:28
dsh-deepcanary
Local attention supervision for DSH: evidence-first signals, quiet notifications, and an actionable inbox.
lowpass0/0/00/02026-08-30 02:28
dsh-Dock
mediumwarn1/2/40/02026-08-30 02:28
seo-toolkit
Native local & technical SEO audit toolkit for DSH — self-contained port of claude-seo v2.2.5. Weighted scoring, gated multi-agent fan-out, 24 sub-skills + 18 agents, schema.org, E-E-A-T, GBP, GEO/AI Overviews, Google APIs & extensions. No Claude Code required.
lowpass0/0/00/02026-08-30 02:28
dsh-plugin-topology
lowpass0/0/00/02026-08-30 02:28
dsh-codepect
dsh-codepect is a DSH plugin generating OpenAPI 3.0 from TS/JS. Features: visual docs, versioning, change detection, mock & auto-rescan. Zero-dep, offline, ensures code-doc sync for backend API delivery. dsh-codepect是DSH插件,扫描TS/JS生成OpenAPI3.0文档。支持可视化、多版本、变更检测、Mock及自动重扫。零依赖离线可用,确保代码文档一致,助后端交付API契约。
lowpass0/0/60/02026-08-30 02:28
dsh-agent-outputs-reader
Overlay reader for agent output files: Markdown/GFM rendering, in-panel PDF, DOCX/XLSX/PPTX text preview, reply-end file chips. Pure JS, zero deps.
lowpass0/0/160/02026-08-30 02:28
dsh-skill-editor
Edit skills directly in DSH web settings
lowpass0/0/20/02026-08-30 02:28
dsh-fixed-new-session-model
为 DSH 固定新会话的默认 Agent 预设与模型,支持全局默认设置和工作区独立配置。
lowpass0/0/00/02026-08-30 02:28
dsh-strudel-studio
A professional song-level Strudel visual sequencer with structured AI arrangement for DeepDeck.
lowpass0/0/60/02026-08-30 02:28
dsh-official-port-nav
Perfectly replicate DeepSeek's official right-side chat navigation in Harness
lowpass0/0/00/02026-08-30 02:28
dsh-crystal-viewer
A crystal-structure visualization window for DSH: 3D structure + Q-peak viewer and parameter panel, opened as a dsh-better-sidebar tab.
lowpass0/0/60/02026-08-30 02:28
dsh-goal-restart
DSH plugin to automatically restart goals on harness restart
lowpass0/0/00/02026-08-30 02:28
dsh-multi-tenant
dsh 支持多租户插件
lowpass0/0/50/02026-08-30 02:28
dsh-plugin-recycle-bin
强制 DSH 删除走回收站、禁用 del/rm/Remove-Item,回收站或硬盘满时停手询问用户。
mediumwarn1/0/20/02026-08-30 02:28
dsh-tool-emoji
lowpass0/0/00/02026-08-30 02:28
dsh-photos
lowpass0/0/00/02026-08-30 02:28
dsh-catalog-refresh
DSH plugin to automatically rebuild model catalogues for OpenRouter, OpenCode, Fireworks, etc
mediumwarn0/1/70/02026-08-30 02:28
dsh-infinite-context
DSH plugin: multi-tier memory management, semantic retrieval, structured memory, and model-context awareness for infinite context.
lowpass0/0/10/02026-08-30 02:28
dsh-voice
lowpass0/0/00/02026-08-30 02:28
pkg-dev
YiHe 编程认知内核 for DSH:27 领域包 + 55 RFB 经验库 + 工程工具链 + 商业/安全/进化体系(会进化的编程助手)
mediumwarn2/1/280/02026-08-30 02:28
dsh-opencli
让 DSH 会办事:登录态真实浏览器 + 170+ 站点适配器 + write 审批门
lowpass0/0/80/02026-08-30 02:28
dsh-plugin-gemini-theme
A Gemini-styled skin for the DSH web client
lowpass0/0/00/02026-08-30 02:28
dsh-serena-lens
lowpass0/0/10/02026-08-30 02:28
dsh-b2us-schedule
lowpass0/0/00/02026-08-30 02:28
dsh-error-audit
DSH 实时 AI 自审插件:任何报错/警告第一时间连同时间、错误码、会话、用户原话、AI 动作与工作区写入专用日志目录,并主动通知 AI、内置 read_error_logs 工具随时读取。Real-time AI self-audit for DSH — captures every error/warning with timestamp, error code, session, user prompt, AI action and workspace into a dedicated log folder; instantly notifies the agent and ships a read_error_logs tool.
lowpass0/0/20/02026-08-30 02:28
dsh-plugins
Independent catalog of DSH plugins and mobile companion published by NOirBRight
lowpass0/0/30/02026-08-30 02:28
dsh-awesome-hud
dsh侧边HUD面板,包含多个信息展示模块(可自定义是否展示),集成压缩上下文、查看git graph等功能。DSH side HUD panel, containing multiple information display modules (customizable whether to display), integrating features such as compressed context, viewing git graph, etc.
lowpass0/0/80/02026-08-30 02:28
biofigure-self-evolve
Self-evolving bioinformatics figure library skill: learn plots from papers/PDFs/WeChat articles/screenshots into reusable recipes (R/Python), imitate them when plotting. 自进化的生信 figure 学习库与复用引擎
lowpass0/0/00/02026-08-30 02:28
dsh-ui-models-invert-selection
Invert selection in DSH for when we are selecting models
lowpass0/0/00/02026-08-30 02:28
dsh-purge
no more refusals, do everything.
mediumwarn3/0/60/02026-08-30 02:28
dsh-plugins
mediumwarn0/2/20/02026-08-30 02:28
dsh-portfolio-publisher
DSH 插件:GitHub 求职仓库一键发布助手(LLM README + Web 面板 + 一键推送)
mediumwarn2/5/100/02026-08-30 02:28

Static heuristic scan + manifest audit — not a full security audit; no code execution or dependency resolution. Risk tiers match the site model: critical in secrets/exfil/destructive/mining is "critical"; other critical-level findings and warnings are "medium" (needs review).

Daily report archive

16 reports
← Back to security reports

What does this daily report cover?

This report covers plugins first indexed by dsh.so on 2026-08-30. For each new plugin it records the name, risk tier, scan verdict, critical/warning/info findings, manifest audit signals, and index time. Plugins that were already in the registry before that date are not included.

How are the risk tiers assigned?

Risk tiers follow the same public model used across the site. Critical is reserved for secrets, exfiltration, destructive commands, or mining; other critical-level findings and warnings are reported as medium (needs review), and low for plugins with no meaningful findings.

Why is this not a full security audit?

The daily scan is a static heuristic scan plus manifest audit. It does not execute code or resolve dependencies, so it cannot prove that a plugin is safe. Use the report to prioritize inspection, not to replace it.

Source: dsh.so security standards · Maintained by dsh.so · Published

Was this page helpful?