All plugins

dsh-plugin-security-audit

Likely

by chendengyuanxm · Security & Policy

Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages. 动态 Cordis 插件静态安全审查。

Likely plugin

Follows the dsh package or skill conventions, but we found no direct runtime dependency.

What we found in the repo

  • npm package dsh-plugin-security-audit

Installing

Install the package, then register it in your cordis.yml:

npm install dsh-plugin-security-audit
# cordis.yml
plugins:
  dsh-plugin-security-audit:

Plugin keys and config options vary — check the repo's README before copying this in. dsh is in developer preview and its loader format is still changing.

Before you install

A listing here is not a security audit. The tier above records whether this repo is wired as a real dsh plugin — not whether it is safe to run. A plugin executes with your agent's permissions: your files, your shell, your network. How to vet a dsh plugin before installing

Found malware or an impersonation in this repo? Report this listing

Repository details

Stars
0
Forks
0
Open issues
0
Language
JavaScript
License
MIT
npm package
dsh-plugin-security-audit @ 1.0.0
Created
2026-08-15
Last push
2026-08-15

Topics

cordisdeepseek-harnessdshdsh-pluginsecurity-auditstatic-analysis

More in Security & Policy