deepseek-harness-plugins avatar

deepseek-harness-plugins

deepseek harness plugins view

Plugin开发GitHub 集成代码审查
验证
L2 · 结构化
安全
中风险
健康
活跃
信任

功能介绍AI

Aggregates, displays, and security-reviews DeepSeek Harness community plugins with a searchable web page.

  • Daily automatic discovery of GitHub repos with dsh-plugin topic
  • Searchable web directory with filters by category and official mark
  • Multi-language plugin descriptions with Chinese preference

由 AI 基于 README 自动生成,仅供参考。

安装

dsh plugin --profile web add github:writeCasually/deepseek-harness-plugins

Install method: GitHub · 尚未在容器中测试 (L3+)

兼容性

DSH VersionStatus
not statedDeclared — not tested

要求

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

安全报告

自动静态扫描,非人工审核。

DSH.SO AUDIT严重风险feb038
自动审查 · 每日更新
严重风险

扫描发现阻断级严重问题(硬编码密钥、数据外传端点、破坏性操作、挖矿特征)。该插件应视为高风险。

5 严重·1 警告·14 提示·8 扫描文件数
code-exec ×3shell ×2
插件版本
扫描版本feb03883eff12026-08-20
当前版本a8623c2af9cf

扫描结果仅对「扫描版本」有效。扫描后 7 天内的新提交不会触发 outdated,评级仍然有效;超过 7 天未重新扫描才显示 outdated。

免责声明:这是自动化静态分析,不构成安全保证。安装前请自行审查。

第二意见扫描(vet · 并行评估期)
vet:干净

vet 判定:vet:干净 · score 94

  • R9 · medium [likely] — 正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯)
  • R3 · info [certain] (downgraded) — 直接访问 process.exit(Node 能力逃逸通道)
  • R3 · info [certain] — 只读 process 成员(能力触达面):process.argv
  • R3 · info [certain] — 只读 process 成员(能力触达面):process.argv
  • R3 · info [certain] — 只读 process 成员(能力触达面):process.env

vet 仅作参考,不改变 dsh 的四档等级。

风险:中风险5 critical · 1 warning · 14 info

• 静态启发式扫描:已完成(8 个文件)

• 依赖漏洞:需深度审计(L3+)

• 权限沙箱:需运行时测试(L4+)

高危发现 · 6 / 6

  • critical使用 child_process 子进程模块(Node.js)scripts/security-review.mjs:79
    re: /\bchild_process\.(?:exec|execSync|spawnSync)\s*\(|require\(\s*['"]node:child_process['"]\s*\)[^;\n]{0,60}\.(?:exec|execSync)\s*\(|(?:^|
  • critical使用 child_process 子进程模块(Node.js)scripts/security-review.mjs:80
    explanation: '通过子进程 shell 执行命令(child_process.exec/execSync)',
  • critical使用 child_process 子进程模块(Node.js)scripts/security-review.mjs:545
    } else if (/eval\s*\(|new\s+Function\s*\(/i.test(cmd) || /child_process\.exec(Sync)?\s*\(/i.test(cmd)) {
  • criticalspawn() 开启 shell: truescripts/security-review.mjs:86
    explanation: '子进程以 shell 模式启动(spawn(...,{shell:true}))',
  • critical命令管道传给 shell(curl/wget | sh)scripts/security-review.mjs:56
    explanation: '下载远程脚本并直接执行(curl/wget | sh)',
  • warning加密货币挖矿特征scripts/security-review.mjs:139
    re: /\b(?:xmrig|moneroocean|cryptonight|stratum\+tcp|kryptex|nanominer)\b/i,

静态启发式扫描,可能误报——使用前请自行审查源码。

活跃度

最近提交 2026-08-20 · 活跃度:活跃

• 仓库创建: 2026-08-20

• 星标: ★ 2 · 复刻: 0

• 健康度: 活跃 — 近 30 天有提交

来源

GitHub: github.com/writeCasually/deepseek-harness-plugins

这页有帮助吗?