All plugins

dsh-plugin-sentinel

Likely

by BotonJ · Security & Policy

DSH plugin security auditor — static pre-install audit for DeepSeek Harness plugin bundles. Zero-dep, in-memory tar parsing, lexical strip scanner.

Likely plugin

Follows the dsh package or skill conventions, but we found no direct runtime dependency.

What we found in the repo

  • npm package dsh-plugin-sentinel

Installing

Install the package, then register it in your cordis.yml:

npm install dsh-plugin-sentinel
# cordis.yml
plugins:
  dsh-plugin-sentinel:

Plugin keys and config options vary — check the repo's README before copying this in. dsh is in developer preview and its loader format is still changing.

Before you install

A listing here is not a security audit. The tier above records whether this repo is wired as a real dsh plugin — not whether it is safe to run. A plugin executes with your agent's permissions: your files, your shell, your network. How to vet a dsh plugin before installing

Found malware or an impersonation in this repo? Report this listing

Repository details

Stars
0
Forks
1
Open issues
2
Language
JavaScript
License
MIT
npm package
dsh-plugin-sentinel @ 0.1.0
Created
2026-08-15
Last push
2026-08-15

Topics

deepseek-harnessdsh-pluginsecurity

More in Security & Policy