每日安全扫描日报

日期 · 2026-08-22 (UTC,覆盖当日 00:00–24:00 新增入库的插件)

12
当日新增
0
严重
6
需注意
6
低风险
插件风险扫描结论C/W/I清单审计收录时间
agentscars
A public commons of real AI-agent failure patterns ("scars") — searchable via API and MCP. Live at agentscars.com. Private for now, open-sourcing once ready.
低风险pass0/0/40/02026-08-22 00:40
dsh-plugin-session-manager-custom
DeepSeek Harness Web plugin for local session data management
需注意warn0/1/20/02026-08-22 00:40
dsh-image-tiler
DSH插件:将大图像分割成带标签的800像素图块,并保留概览图,同时保留视觉模型所需的细节。包含设置卡。DSH plugin: slice large images into labeled 800px tiles + overview, preserving detail for vision models. Settings card included.
低风险pass0/0/00/02026-08-22 00:40
dsh-hooks-git-ai
A DeepSeek Harness plugin that records which files the agent edited, with which model, and in which session into git-ai
低风险pass0/0/00/02026-08-22 00:40
dsh-font-size
DSH Web GUI plugin: 'Conversation font size' slider (12-22 px) in Settings → General.
低风险pass0/0/40/02026-08-22 00:40
dsh-jj-vcs
Jujutsu version-control plugin and skill for DeepSeek Harness multi-agent teams
需注意warn0/3/30/02026-08-22 00:40
dsh-pm
dsh-pm is the ChunSun × DeepSeek Harness reference plugin: an AI-native project-delivery loop driven by ChunSun. Requirements / Runs / Steps / acceptance scenarios & cases / work-memory, a session delivery panel, and 28 chunsun_* model tools — with the platform as the single source of truth. MIT.
低风险pass0/0/00/02026-08-22 00:40
dsh-novel-writing
DSH (DeepSeek Harness) 自动化小说写作发布流水线插件:claude-writing-workflow 迁移版 agent 预设 + 小说工作台(可视化/实时渲染/章节编辑)+ 多平台发布配置与数据驱动优化闭环
需注意warn1/0/40/02026-08-22 00:40
dsh-one-gateway
Private DSH One Gateway — loopback, identity-first ingress for DeepSeek Harness
低风险pass0/0/20/02026-08-22 00:40
dsh-lanchat
需注意warn2/1/100/02026-08-22 00:40
dsh-android
DeepSeek Harness plugin for Android — build, run, and interact with a live emulator or USB device stream inside a conversation, driven entirely through adb.
需注意warn0/2/70/02026-08-22 00:40
Dsh-dev
Version-aware workspace core for building DeepSeek Harness plugins
需注意warn0/5/80/02026-08-22 00:40

静态启发式扫描 + 语义清单审计,非完整安全审计;不执行代码、不解析依赖。风险等级映射与站点一致:secrets/外泄/破坏性/挖矿类 critical 为"严重",其余 critical 级与警告归入"需注意"(medium)。

历史日报归档

8 期
← 返回安全报告

这份日报覆盖什么?

这份日报覆盖 2026-08-22 首次被 dsh.so 收录的插件。对每个新增插件记录名称、风险等级、扫描结论、严重/警告/提示发现数、manifest 审计信号和收录时间。此前已在注册表中的插件不会包含在内。

风险等级是如何划分的?

风险等级沿用站点的公开模型。密钥、外传、破坏性或挖矿类 critical 判为“严重”,其余 critical 判为“高风险”;medium 与 low 分别表示需要关注和当前无发现。

为什么这不是完整安全审计?

日报是静态启发式扫描加 manifest 审计,不执行代码,也不解析依赖,因此不能证明插件绝对安全。请用它来优先安排检查,而不是替代检查。

来源:dsh.so 安全标准 · 由 dsh.so 维护 · 发布于

这页有帮助吗?