All plugins

DSH / BUNDLE / BUNDLES

dsh-plugin-security-audit

v1.0.0chendengyuanxm / dsh-plugin-security-auditb80b3e28bb

InstallableBundlesBundles & other modulesCommunity · Topic auto-analysis

Overview

dsh-plugin-security-audit

Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages.

README / EN

Package documentation

Registry summary

Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- Static pattern matching with light scope approximation — it cannot catch intent-level or multi-step obfuscated attacks. A CLEAN verdict means "no rule matched", never "provably safe". - `critical`+`high` findings escalate the *approval*; the audit never hard -blocks a call by itself. - Reports are in-process only (no persistence, no history UI).