Daily security scan
Date · 2026-10-09 (UTC — plugins first indexed that day)
| Plugin | Risk | Verdict | C/W/I | Manifest | Indexed |
|---|---|---|---|---|---|
| @LQH-A-A-O/dsh-simple-drawing DSH 技能包:layered-art(dsh简易绘图能力包)—— 用代码作画,七条路线(描图重构 / 网格立绘 / 方块角色 / 像素画 / 部件装配 / 赛博拼豆·渐进生长 / 自适应四叉树)。拼豆路线出图同时给「哪个色多少颗」的买豆子清单。 | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @LQH-A-A-O/cad-ppt-skills DSH 整合包:AutoCAD 出图(autocad-draw)+ PPT 制作(pptx-editor)两个 Windows 原生技能 | medium | warn | 1/0/0 | 0/0 | 2026-10-09 16:38 |
| @LQH-A-A-O/dsh-bcut-edit DSH 技能包:bcut-edit —— 用代码剪辑视频(读写必剪草稿工程 / ffmpeg 直出) | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @1900992335/desktop-pack DSH 桌面端整合包:packforge 打包 + 上下文管理 + 插件市场 + 模型代理 | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @hxh230802/pokemon | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @hxh230802/better-sidebar | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @yukitakasama/better-deepseek-harness-codex 更好的 DSH(codex 风格):面向 Coding 用户的 DSH 整合包 —— Codex 风格界面、代码审查、思考强度滑块、费用计量与桌宠(基座 DSH 0.2.0-rc.2) | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
| @hxh230802/smoother-deepseek-harness | low | pass | 0/0/0 | 0/0 | 2026-10-09 16:38 |
Static heuristic scan + manifest audit — not a full security audit; no code execution or dependency resolution. Risk tiers match the site model: critical in secrets/exfil/destructive/mining is "critical"; other critical-level findings and warnings are "medium" (needs review).
Daily report archive
54 reportsWhat does this daily report cover?
This report covers plugins first indexed by dsh.so on 2026-10-09. For each new plugin it records the name, risk tier, scan verdict, critical/warning/info findings, manifest audit signals, and index time. Plugins that were already in the registry before that date are not included.
How are the risk tiers assigned?
Risk tiers follow the same public model used across the site. Critical is reserved for secrets, exfiltration, destructive commands, or mining; other critical-level findings and warnings are reported as medium (needs review), and low for plugins with no meaningful findings.
Why is this not a full security audit?
The daily scan is a static heuristic scan plus manifest audit. It does not execute code or resolve dependencies, so it cannot prove that a plugin is safe. Use the report to prioritize inspection, not to replace it.
Source: dsh.so security standards · Maintained by dsh.so · Published