Overview
dsh-plugin-security-audit
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- Static pattern matching with light scope approximation — it cannot catch intent-level or multi-step obfuscated attacks. A CLEAN verdict means "no rule matched", never "provably safe". - `critical`+`high` findings escalate the *approval*; the audit never hard -blocks a call by itself. - Reports are in-process only (no persistence, no history UI).
