概览
dsh-plugin-security-audit
Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages.
README / ZH
插件文档
目录摘要
Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages.
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
- Static pattern matching with light scope approximation — it cannot catch intent-level or multi-step obfuscated attacks. A CLEAN verdict means "no rule matched", never "provably safe". - `critical`+`high` findings escalate the *approval*; the audit never hard -blocks a call by itself. - Reports are in-process only (no persistence, no history UI).
