验证
L1 · 已找到
安全
严重
健康
活跃
信任
未评级
功能介绍AI
DSH runtime appearance/theming plugin: built-in palettes, light/dark/system modes, VS Code theme import and persistent theme library.
- Built-in color palettes and dual-seed theme generation
- Import themes from Open VSX and VS Code
- Persistent theme library with light/dark variants
由 AI 基于 README 自动生成,仅供参考。
安装
dsh plugin --profile web add github:MangMax/dsh-themesInstall method: GitHub · 尚未在容器中测试 (L3+)
兼容性
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
要求
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
安全报告
自动静态扫描,非人工审核。
DSH.SO VETCRITICAL85fe10
安全审查自动审查 · 每日更新
CRITICAL
vet 判定为严重(critical):存在阻断级风险,使用前务必审查。
2 严重·1 高·4 中·0 分数
插件版本
0.1.8dsh 清单扫描版本
85fe103cc2792026-08-21当前版本
85fe103cc279vet 判定
critical · npm分数 0vet 为 AST 静态扫描(npm 发布物或 git 源码)。
`[](https://www.dsh.so/artifact/dsh-themes-2/)`免责声明:这是自动化静态分析,不构成安全保证。安装前请自行审查。
风险详情
| 风险等级 | 规则 | 位置 | 描述 |
|---|---|---|---|
| critical | R3 | index.cjs:3 | 直接访问 process.getBuiltinModule(Node 能力逃逸通道) |
| critical | R3 | index.cjs:3 | 直接访问 process.getBuiltinModule(Node 能力逃逸通道) |
| high | R2 | index.js:7 | new Function / new AsyncFunction 动态执行 |
| medium | R9 | client.js:8 | 递归无终止条件粗检:t 直接自调用且函数体内无条件分支 |
| medium | R2 | index.cjs:3 | require() 动态模块加载(npm 包内能力触达) |
静态启发式扫描,可能误报——使用前请自行审查源码。
活跃度
最近提交 2026-08-17 · 活跃度:活跃
• 仓库创建: 2026-08-21
• 星标: ★ 1 · 复刻: 0
• 健康度: 活跃 — 近 30 天有提交
来源
GitHub: github.com/MangMax/dsh-themes
