每日安全扫描日报

日期 · 2026-09-06 (UTC,覆盖当日 00:00–24:00 新增入库的插件)

14
当日新增
0
严重
3
需注意
11
低风险
插件风险扫描结论C/W/I清单审计收录时间
dsh-status-bar
Live execution status bar for the DSH web GUI: real-time activity + event-driven LLM achievement summaries with expandable detail reports.
低风险pass0/0/50/02026-09-06 02:13
dhs-connect
DSH Connect — ChatGPT model connector for DSH, powered by the Codex app-server.
需注意warn2/3/200/02026-09-06 02:13
DSH-WebGIS
DSH WebGIS Plugin: Map reading, map manipulation, and 3D world comprehension.
低风险pass0/0/00/02026-09-06 06:15
dsh-whale-particles
给 DSH Web 加一个点阵互动背景:点阵可组成鲸鱼或你上传的透明 PNG 照片,每颗粒子有自己独立的平滑外力;既能手动随鼠标扰动,也能切换自动屏保模式(360° 任意方向扫波 + 全屏呼吸躁动),参数面板支持恢复默认。
低风险pass0/0/30/02026-09-06 06:15
dsh-wellness
dsh-wellness
低风险pass0/0/00/02026-09-06 06:15
dsh-skill-injector
Auto-inject chosen skills into DSH sessions: each prompt or once at session start, with a settings page and a composer indicator.
需注意warn0/1/20/02026-09-06 06:15
dsh-split-screen
低风险pass0/0/40/02026-09-06 06:15
dsh-btw
enables /btw commands in deepseek-harness (similar to /btw in claude code)
低风险pass0/0/00/02026-09-06 06:15
dsh-team
Durable agent teams and web dashboard plugin for DSH
低风险pass0/0/10/02026-09-06 06:15
dsh-commandcode-usage-inline
低风险pass0/0/00/02026-09-06 06:15
dsh-whale-pet
dsh的桌面宠物,挂载在WhaleHarbor中
需注意warn0/3/80/02026-09-06 06:15
dsh-novel-forge
AI 编译纯文本小说工作台 for DSH:大纲导入、道藏/大世界设定、卷与章节规划、逐章 AI 生成 3000-4000 字、九维审稿、全书质检、全本导出。AI novel writing workbench (text-only).
低风险pass0/0/20/02026-09-06 06:15
dsh-adrian-inject-context
低风险pass0/0/40/02026-09-06 06:15
dsh-model-info-fill
模型信息补全:按模型名自动补全上下文、输出上限、思考档位和图片能力
低风险pass0/0/40/02026-09-06 06:15

静态启发式扫描 + 语义清单审计,非完整安全审计;不执行代码、不解析依赖。风险等级映射与站点一致:secrets/外泄/破坏性/挖矿类 critical 为"严重",其余 critical 级与警告归入"需注意"(medium)。

历史日报归档

23 期
← 返回安全报告

这份日报覆盖什么?

这份日报覆盖 2026-09-06 首次被 dsh.so 收录的插件。对每个新增插件记录名称、风险等级、扫描结论、严重/警告/提示发现数、manifest 审计信号和收录时间。此前已在注册表中的插件不会包含在内。

风险等级是如何划分的?

风险等级沿用站点的公开模型。密钥、外传、破坏性或挖矿类 critical 判为“严重”,其余 critical 判为“高风险”;medium 与 low 分别表示需要关注和当前无发现。

为什么这不是完整安全审计?

日报是静态启发式扫描加 manifest 审计,不执行代码,也不解析依赖,因此不能证明插件绝对安全。请用它来优先安排检查,而不是替代检查。

来源:dsh.so 安全标准 · 由 dsh.so 维护 · 发布于

这页有帮助吗?