# dsh-route-fence-linter — DeepSeek Harness plugin install manifest

> Generated: 2026-09-18 14:55 · Source: https://deepseekmodel.com/plugins

## Overview

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

## Plugin info

| Category | Maintainer | GitHub stars | License | Primary language | Last push |
| --- | --- | --- | --- | --- | --- |
| Security & Permissions | Vladimir-Kryshchenko | 0 | — | — | — |

## Install

```bash
dsh plugin --profile web add github:Vladimir-Kryshchenko/dsh-route-fence-linter
```

## Steps

1. Install and start DeepSeek Harness (DSH, MIT-licensed open-source agent runtime) — `npx @deepseek-ai/dsh web`
2. Run the command above; the CLI resolves the plugin and verifies its source
3. Confirm with dsh plugins list; restart Harness if needed

> To pin a revision, append #commit to the repository spec.

## Audit before installing

Plugins run with your dsh process permissions and may execute code during installation. Read the repository source and license first, check for destructive commands or excessive access, and pin a commit hash for reproducible installs. This manifest is compiled by DeepseekModel from a public plugin catalog for reference only and does not vouch for third-party plugins.

---

- Repository: https://github.com/Vladimir-Kryshchenko/dsh-route-fence-linter
- Plugin page: https://deepseekmodel.com/plugin-detail?id=vladimir-kryshchenko%2Fdsh-route-fence-linter
- Source: https://deepseek-harness-plugin.com/zh-CN/plugins/ · Generated 2026-09-16
