npm-safe-fordsh
阻止 AI 安装有风险的 npm 包:元数据审核与供应链深度扫描,14 个 agent 工具、22 项安全检查,本地 SQLite 缓存。
nisconder
@nisconder
⬇ 2
★ 5
main
安装
dsh plugin --profile web add github:nisconder/npm-safe-fordsh
需要可复现安装时,可在仓库后追加 #commit 固定提交。
阻止 AI 安装有风险的 npm 包:元数据审核与供应链深度扫描,14 个 agent 工具、22 项安全检查,本地 SQLite 缓存。
该插件未提供要点说明,请参考仓库 README。
agent-toolsaideepseek-harnessdshllmnpm
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/nisconder/npm-safe-fordsh |
| 许可证 | Apache-2.0 |
| 主要语言 | main |
| 下载量 | 2 |
| GitHub 星标 | 5 |
| 最近推送 | 2026-08-29 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# npm-safe for DeepSeek Harness
**Stop AI agents before they install a risky npm package.**
[](https://www.npmjs.com/package/@npm-safe/dsh-tool-npm-safe)
[](https://www.npmjs.com/package/@npm-safe/dsh-tool-npm-safe)
[](https://github.com/nisconder/npm-safe-forDSH/actions/workflows/ci.yml)
[](LICENSE)
[](https://nodejs.org)
**14 agent tools · 22 security checks · integrity-verified deep scans · local SQLite cache**
[Install](#30-second-install) · [See what it catches](#what-it-catches) · [Tool catalog](#14-agent-tools) · [中文](README_zh.md)
`npm-safe-forDSH` is a supply-chain security gate for
[DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness). It lets an
agent inspect npm package metadata and published tarballs **before** an install,
then returns evidence, a risk level, and an explainable score inside the same
conversation.
> If this makes your agent workflow safer, please **Star the repository**. It
> helps other DSH users find an independent security tool.
## 30-second install
```bash
dsh plugin --profile tui add @npm-safe/dsh-tool-npm-safe --allow-build=better-sqlite3
dsh --profile tui
```
Restart a running profile after installation. Then ask:
```text
Deep-scan fast-glob before installing it. Explain every finding.
```
For a quick metadata-only check:
```text
Use check_package to check lodash.
```
The plugin is declared as a native DSH bundle, so the official `dsh plugin`
command installs the package and activates its `cordis.patch.yml` layer.
`--allow-build=better-sqlite3` grants build permission only to the SQLite
driver used for the local cache; pnpm continues to block install scripts from
other dependencies. Your selected DSH model provider must already be
configured; a DeepSeek API key is only required when DeepSeek is the selected
provider.
## What it catches
| Signal | Metadata scan | Deep scan |
|---|:---:|:---:|
| Suspicious lifecycle scripts and install hooks | ✅ | ✅ |
| Typosquatting, abandoned packages, risky maintainers | ✅ | ✅ |
| Non-standard registries and remote binaries | ✅ | ✅ |
| Tarball integrity mismatch and unsafe archive paths | — | ✅ |
| Obfuscated code, embedded secrets, shell/network execution | — | ✅ |
| Native binaries, WebAssembly, oversized or truncated content | — | ✅ |
Metadata scans are fast and remain the default. Set `deep: true` to download
the same-origin published tarball, verify npm integrity metadata, and inspect
bounded source content entirely in memory.
```text
package: fast-glob@3.3.3
level: safe
score: 88/100
integrity: verified
files scanned: 91
findings: 1 low, 0 medium, 0 high, 0 critical
```
## Why use it in an agent
| Typical agent workflow | With npm-safe-forDSH |
|---|---|
| Installs first and audits later | Checks before the install decision |
| Trusts package names and download counts | Evaluates maintainers, scripts, provenance signals, and content |
| Returns a pass/fail with little context | Returns findings, evidence, severity, score, and recommendations |
| Repeats registry traffic | Uses a local SQLite cache and rate limiting |
| Checks one package manually | Supports batch checks, watchlists, refresh jobs, and CI gates |
## 14 agent tools
| Tool | Purpose |
|---|---|
| `check_package` | Check one package, optionally with `deep: true` |
| `check_packages` | Rate-limited batch checking |
| `search_packages` | Search the npm registry |
| `watch_add` / `watch_remove` / `watch_list` | Manage a persistent watchlist |
| `rules_list` / `rule_enable` / `rule_disable` | Inspect and toggle rules |
| `rule_set_severity` | Override a rule severity |
| `settings_get` / `settings_set` | Read or update engine settings |
| `ci_scan` | Scan a project's dependencies as a security gate |
| `refresh_all` | Refresh the watchlist as a background DSH job |
## Security model
- Core detection is deterministic and local-first; no package source is sent
to an external LLM by default.
- Deep scans reject cross-origin tarballs and enforce archive size, file count,
decompression, path, and scanned-text limits.
- Findings are evidence, not a guarantee that a package is safe. Review high
impact packages and pin versions in production.
- See the complete [scanner rules](packages/core/SCANNER_RULES.md) and
[security policy](SECURITY.md).
## Use the engine directly
```bash
pnpm add @npm-safe/core-dsh
```
```ts
import { NpmSafeEngine } from "@npm-safe/core-dsh";
const engine = new NpmSafeEngine();
const report = await engine.checkPackage("lodash", { deep: true });
console.log(report.level, report.score, report.findings);
await engine.close();
```
## Develop from source
Requires Node.js 22.19+ and Corepack.
```bash
git clone https://github.com/nisconder/npm-safe-forDSH.git
cd npm-safe-forDSH
corepack enable
corepack prepare pnpm@11.7.0 --activate
pnpm install
pnpm run build
pnpm run typecheck
pnpm run test
```
Live registry smoke tests:
```bash
node scripts/smoke.mjs lodash
node scripts/smoke-facade.mjs
```
The workspace contains [`@npm-safe/core-dsh`](packages/core) and the
[`@npm-safe/dsh-tool-npm-safe`](packages/tool-npm-safe) bundle. DSH peer
packages are aligned to the `0.1.0-rc.6` family; upgrades must remain aligned
while DeepSeek Harness is in developer preview.
## Documentation
- [Plugin package and examples](packages/tool-npm-safe/README.md)
- [Engine API](packages/core/API.md)
- [Architecture](packages/core/ARCHITECTURE.md)
- [Scanner rules](packages/core/SCANNER_RULES.md)
- [Contributing](CONTRIBUTING.md)
This project adapts the engine from
[`nisconder/npm-safe`](https://github.com/nisconder/npm-safe) for DeepSeek
Harness. It is an independent community project and is not affiliated with or
endorsed by DeepSeek.
## License
[Apache-2.0](LICENSE) — Copyright 2026 Nisconder, InfiniteScope, Escap1ng, StoryBegins.
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。