863683348/dsh-plugin-gate0

dsh-plugin-gate

Installation safety gate for DeepSeek Harness plugins: an antivirus-style scanner that inspects a plugin source (local directory or npm tarball) for malicious install scripts, dangerous permissions/fs usage, secret exfiltration, and network callbacks before you run 'dsh plugin add'

包名
dsh-plugin-gate
版本
1.0.1
许可证
MIT
最近更新
2026年8月17日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:863683348/dsh-plugin-gate

Usage

Ask the agent to scan a plugin before installing it (the plugin also injects prompt guidance that tells the agent to do this automatically):

gate_scan target: "npm:dsh-plugin-some-package"
gate_scan target: "npm:dsh-plugin-some-package@1.2.3"   # pinned version
gate_scan target: "./downloaded-plugin"                 # local directory

Result shape:

{
  "verdict": "BLOCK" | "WARN" | "PASS",
  "score": 254,
  "summary": { "high": 0, "medium": 1, "low": 3, "categories": { "network": 4 } },
  "network": { "hosts": [...], "unallowlisted": [...], "readAndSendFiles": [...] },
  "hits": [{ "rule": "fetch_call", "category": "network", "severity": "medium",
             "file": "lib/index.js", "line": 12, "evidence": "...", "hint": "..." }],
  "recommendations": [...]
}

Verdict semantics

  • BLOCK — at least one high-severity signature. Do not install until the maintainer ships a clean rebuild you can scan again.
  • WARN — medium-severity patterns that need manual review (network I/O, home-path writes, base64 blobs). Inspect every hit in context.
  • PASS — no risky signatures. Heuristic only — keep normal caution with unknown maintainers.

Context-aware rules: exec()/execSync() hits are downgraded when the file does not import child_process (typical RegExp#exec false positive); code-context rules (exec, eval, curl|sh, PowerShell…) are downgraded to low when found in comments or documentation (examples, not behavior) — while secrets and webhooks stay flagged even in comments. Dependencies installed from git/http/file URLs are flagged as risky_dependency, and >4000-char minified lines as minified_line (low).

Configuration

KeyDefaultMeaning
maxFiles1000hard cap on scanned files per directory walk
maxFileBytes2 MiBper-file text cap
includeNodeModulesfalsedescend into node_modules
maxTarballBytes32 MiBnpm tarball download cap
allowlistHosts[]hosts never listed as unallowlisted
promptSectiontrueinject agent guidance
sectionOrder5prompt section order