All plugins

DSH / BUNDLE / BUNDLES

dsh-poison-guard

v0.2.0zoahdev / dsh-poison-guard9d98a4a8e4

InstallableBundlesBundles & other modulesCommunity · Topic auto-analysis

Overview

dsh-poison-guard

Pre-install supply-chain poison scanner for DeepSeek Harness plugins: AST analysis (NodeSecure JS-X-Ray) + deobfuscation decoder + regex heuristics to catch credential exfiltration, dynamic code execution, obfuscated imports, and install-time scripts.

README / EN

Package documentation

Registry summary

Pre-install supply-chain poison scanner for DeepSeek Harness plugins: AST analysis (NodeSecure JS-X-Ray) + deobfuscation decoder + regex heuristics to catch credential exfiltration, dynamic code execution, obfuscated imports, and install-time scripts.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- Static only — does not execute the plugin or observe runtime behavior. - Obfuscation can be made undecidable; stronger obfuscators (e.g. `javascript-obfuscator` with string-array + control-flow flattening) may still hide the payload. - The AST layer is tuned to `aggressive` sensitivity for maximum visibility; a benign plugin that does real `eval`/`child_process` work will also be flagged. - No sandbox policy is enforced here; pair it with the harness sandbox.