概览
dsh-secure-audit
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
This plugin is a read-only, heuristic aid. It is not a security product, not a certification, and not a substitute for a proper threat model. Read this before relying on it. **Detection is heuristic.** - The injection rules are a fixed pattern table (English + Chinese). They can miss novel or obfuscated attacks (false negatives) and can over-flag benign phrasing (false positives). `allow` means "no rule fired", not "safe". Fail-open timeouts and truncation downgrade to `allow` with an explicit warning — treat those as "not fully scanned". - The optional model classifier runs only on `review` verdicts, only when configured, and depends on a local model you operate (the built-in adapter targets Ollama / Llama-Guard). Without a classifier, ambiguous cases stay at `review` for a human. **Redaction is type-limited.** - Only the listed PII types are masked (CN mobile / ID / bank card, email, IPv4, API keys, URL credentials). Chinese names, addresses, and other context-sensitive PII are NOT covered. Regex + structural validation cuts false positives (order numbers) but cannot guarantee zero misses. **The audit is a posture snapshot.** - Nine fixed checks; every report carries a `limitations` field stating what that run does not cover. - File-permission checks use POSIX mode bits; **Windows ACLs are not inspected** (Node has no native ACL API). - Live listening-port ground truth runs on **Linux only** (`/proc/net`); other platforms rely on env/config evidence. - Session-file PII sampling covers up to 10 files by default; raise `sampleLimit` for large session directories. - The live `deps-supply-chain` registry lookup is **opt-in** (`supplyChainLive: true`) and sends installed plugin names+versions to registry.npmjs.org; offline inventory is the default. - Absence of findings does not imply the machine is secure. **Compatibility.** - Tested against `@deepseek-ai/dsh-tools` 0.1.2-alpha.2 only. DSH is pre-1.0; verify against your pinned version. Live loading in a Cordis host was validated at the dsh-tools registration/execution contract level, not in a fully running host — install, run `security_audit`, and re-verify after upgrading either side. **Legal.** - Provided under MIT, "as is", without warranty of any kind (see [LICENSE](LICENSE)). - Unofficial third-party tool; not affiliated with, endorsed by, or sponsored by DeepSeek (see the top disclaimer).
