安全扫描报告

插件市场里的每个插件都会自动做一次静态扫描,检查可疑模式——硬编码密钥、数据外传、破坏性命令、代码混淆等,采用 vet 主导的三档风险模型。以下是最新扫描发现的总结,用通俗语言说明。

16,868
已扫描插件
16464
低风险
107
需注意
0
严重
低风险 (99%) 需注意 (1%) 严重 (0%)

生态整体健康。大多数插件(100%)没有严重发现。0 个插件被评为严重(vet critical,或密钥 / 外传 / 破坏性 / 挖矿等阻断模式)。另有 107 个需注意——安装前请亲自复查。

34 个插件尚未扫描。

风险模型:vet 主导的三档

独立的第二台静态引擎(@jieai/dsh-plugin-vet)作为主判。dsh 的扫描补齐它未覆盖的缺口,并对阻断模式做硬性守门。两者合并为三档——低 · 中 · 严重——原先的“高”档已退休。

16464
低(融合)
107
中(融合)
0
严重(融合)
16636
vet 覆盖 · 65 个跳过

vet 判定为 低 / 中 / 严重;“高”档已不存在。dsh 只在发现阻断模式(密钥、外传、破坏性、挖矿)时强制升级为严重,或在 vet 不可用时兜底。每个插件的详情页都同时展示融合档位与 vet 证据。

扫描检查什么

所有插件里最常见的发现,用通俗语言说明。

🖥️Shell / subprocess
513 处命中

The plugin runs shell commands or spawns subprocesses. Common in CLI/terminal plugins, but worth knowing.

Usually legitimate for terminal tools — mapped to "needs review" rather than high risk.

⚡Dynamic code execution
258 处命中

The plugin evaluates code at runtime (eval, new Function). Powerful, but harder to audit.

Usually legitimate; mapped to "needs review" unless combined with other risk.

💥Destructive commands
114 处命中

The plugin contains commands that can delete files or modify critical system areas (e.g. rm -rf, chmod 777).

High risk — understand exactly what it touches before running.

🔑Hardcoded secrets
29 处命中

The plugin contains what looks like an API key, token, or private key written directly in its source code.

Anyone with access to the repo could use this credential. Treat with caution.

🕵️Obfuscated code
22 处命中

Parts of the code are deliberately hard to read (encoded blobs, fromCharCode tricks), making review difficult.

Obfuscation is a red flag — what is it hiding?

🌐Data exfiltration
2 处命中

The plugin may send data to external endpoints (webhooks, tunnels, third-party servers).

Review what data could leave your machine before installing.

说明:Shell/子进程与动态代码执行在 CLI 与终端插件中很常见,因此归入“需注意”(中档),而非严重风险。

严重插件

0 个插件被评为严重——vet critical,或密钥 / 外传 / 破坏性 / 挖矿等阻断(blocking)模式

最近一次扫描未发现严重插件。

自动启发式扫描——可能存在误报。非人工审核,绝非背书。

需注意(中)

107 个插件被评为中——vet suspicious,或仅有 dsh 证据需要二次确认

插件风险
dsh-web-profile★ 0中
@dgagf111/dsh-hydrasearch★ 0中
@Justin-Mai/dsh-stock-view★ 1中
dsh-smart-reminder★ 0中
dsh-upgrade-kit★ 0中
dsh-tmwebdriver★ 0中
dsh-remote★ 0中
claude-in-dsh★ 3中
cli★ 5中
dsh-remote★ 0中
dsh-desktop★ 2中
dsh-cordis-mcp★ 1中
vision-toolkit-for-dsh-v0.1-maybe-★ 1中
dsh-auto-classifier★ 1中
dsh-launcher★ 0中
dsh-balance-plugin★ 64中
dsh-convmap★ 1中
paper-workbench★ 0中
conjugate-spectral-geometry★ 2中
dsh-balance★ 2中

展示前 20 个中风险插件。浏览全部 107 个中风险插件 — 或 查看报告归档。

📖
扫描如何工作

扫描什么、风险等级、vet 主导的三档模型。

🔍
浏览全部插件

每个插件详情页都有各自的三档扫描报告。

⚙️
深度审计(规划中)

依赖 CVE 与更深入的运行时行为测试——后续推出。

扫描是自动启发式——不是人工审核,也绝非背书。安装第三方插件风险自负。

这页有帮助吗?