Skills Plugins MCP Prompt Model 博客 我的中心

dsh-plugin-vetting

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

truelove-dreamer @truelove-dreamer ⬇ 3,194 ★ 4

Install

dsh plugin --profile web add dsh-plugin-vetting
Download install manifest

For reproducible installs, append #commit to pin a specific revision.

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

No highlight list provided; see the repository README.

  1. Install and start DeepSeek Harness: npx @deepseek-ai/dsh web
  2. Run the install command above (the CLI resolves the plugin and verifies its source)
  3. Confirm with dsh plugins list; restart Harness if required

Plugins run with your dsh process permissions and may execute code during installation. Read the repository source and license first, and check for destructive commands or excessive access. This site only indexes; it does not vouch for third-party plugins.

Repositorygithub.com/truelove-dreamer/dsh-plugin-vetting
LicenseNot declared (see repo)
Primary language
Downloads3,194
GitHub stars4
Last push
Cataloged2026-08-15
CategorySecurity & Permissions

Facts come from a public catalog snapshot (2026-09-16); descriptions are rewritten by us.

Sources: the public DeepSeek Harness plugin catalog and each plugin's GitHub repository. This is an independent third-party directory with no affiliation to or endorsement from DeepSeek, High-Flyer, or the plugin authors.

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。