Daily security scan
Date · 2026-09-06 (UTC — plugins first indexed that day)
| Plugin | Risk | Verdict | C/W/I | Manifest | Indexed |
|---|---|---|---|---|---|
| dsh-status-bar Live execution status bar for the DSH web GUI: real-time activity + event-driven LLM achievement summaries with expandable detail reports. | low | pass | 0/0/5 | 0/0 | 2026-09-06 02:13 |
| dhs-connect DSH Connect — ChatGPT model connector for DSH, powered by the Codex app-server. | medium | warn | 2/3/20 | 0/0 | 2026-09-06 02:13 |
| DSH-WebGIS DSH WebGIS Plugin: Map reading, map manipulation, and 3D world comprehension. | low | pass | 0/0/0 | 0/0 | 2026-09-06 06:15 |
| dsh-whale-particles 给 DSH Web 加一个点阵互动背景:点阵可组成鲸鱼或你上传的透明 PNG 照片,每颗粒子有自己独立的平滑外力;既能手动随鼠标扰动,也能切换自动屏保模式(360° 任意方向扫波 + 全屏呼吸躁动),参数面板支持恢复默认。 | low | pass | 0/0/3 | 0/0 | 2026-09-06 06:15 |
| dsh-wellness dsh-wellness | low | pass | 0/0/0 | 0/0 | 2026-09-06 06:15 |
| dsh-skill-injector Auto-inject chosen skills into DSH sessions: each prompt or once at session start, with a settings page and a composer indicator. | medium | warn | 0/1/2 | 0/0 | 2026-09-06 06:15 |
| dsh-split-screen | low | pass | 0/0/4 | 0/0 | 2026-09-06 06:15 |
| dsh-btw enables /btw commands in deepseek-harness (similar to /btw in claude code) | low | pass | 0/0/0 | 0/0 | 2026-09-06 06:15 |
| dsh-team Durable agent teams and web dashboard plugin for DSH | low | pass | 0/0/1 | 0/0 | 2026-09-06 06:15 |
| dsh-commandcode-usage-inline | low | pass | 0/0/0 | 0/0 | 2026-09-06 06:15 |
| dsh-whale-pet dsh的桌面宠物,挂载在WhaleHarbor中 | medium | warn | 0/3/8 | 0/0 | 2026-09-06 06:15 |
| dsh-novel-forge AI 编译纯文本小说工作台 for DSH:大纲导入、道藏/大世界设定、卷与章节规划、逐章 AI 生成 3000-4000 字、九维审稿、全书质检、全本导出。AI novel writing workbench (text-only). | low | pass | 0/0/2 | 0/0 | 2026-09-06 06:15 |
| dsh-adrian-inject-context | low | pass | 0/0/4 | 0/0 | 2026-09-06 06:15 |
| dsh-model-info-fill 模型信息补全:按模型名自动补全上下文、输出上限、思考档位和图片能力 | low | pass | 0/0/4 | 0/0 | 2026-09-06 06:15 |
Static heuristic scan + manifest audit — not a full security audit; no code execution or dependency resolution. Risk tiers match the site model: critical in secrets/exfil/destructive/mining is "critical"; other critical-level findings and warnings are "medium" (needs review).
Daily report archive
23 reportsWhat does this daily report cover?
This report covers plugins first indexed by dsh.so on 2026-09-06. For each new plugin it records the name, risk tier, scan verdict, critical/warning/info findings, manifest audit signals, and index time. Plugins that were already in the registry before that date are not included.
How are the risk tiers assigned?
Risk tiers follow the same public model used across the site. Critical is reserved for secrets, exfiltration, destructive commands, or mining; other critical-level findings and warnings are reported as medium (needs review), and low for plugins with no meaningful findings.
Why is this not a full security audit?
The daily scan is a static heuristic scan plus manifest audit. It does not execute code or resolve dependencies, so it cannot prove that a plugin is safe. Use the report to prioritize inspection, not to replace it.
Source: dsh.so security standards · Maintained by dsh.so · Published