Overview
dsh-poison-guard
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- Static only — does not execute the plugin or observe runtime behavior. - Obfuscation can be made undecidable; stronger obfuscators (e.g. `javascript-obfuscator` with string-array + control-flow flattening) may still hide the payload. - The AST layer is tuned to `aggressive` sensitivity for maximum visibility; a benign plugin that does real `eval`/`child_process` work will also be flagged. - No sandbox policy is enforced here; pair it with the harness sandbox.
