All plugins

dsh-trust-check

Verified

by liuwenji007 · Security & Policy

Static capability disclosure for DeepSeek Harness plugins — evidence-backed, zero-token, no safety claims.

Verified plugin

Depends on the Cordis runtime or ships a cordis.yml, so it loads as a real dsh plugin.

What we found in the repo

  • — depends on @deepseek-ai/cordis
  • — depends on @deepseek-ai/dsh-client-locale
  • — npm package dsh-trust-check

Installing

Install the package, then register it in your cordis.yml:

npm install dsh-trust-check
# cordis.yml
plugins:
  dsh-trust-check:

Plugin keys and config options vary — check the repo's README before copying this in. dsh is in developer preview and its loader format is still changing.

Before you install

A listing here is not a security audit. The tier above records whether this repo is wired as a real dsh plugin — not whether it is safe to run. A plugin executes with your agent's permissions: your files, your shell, your network. How to vet a dsh plugin before installing

Found malware or an impersonation in this repo? Report this listing

Repository details

Stars
0
Forks
1
Open issues
0
Language
TypeScript
License
MIT
npm package
dsh-trust-check @ 0.1.3
Created
2026-08-27
Last push
2026-08-31

Topics

auditdeepseek-harnessdsh-pluginsecurity

More in Security & Policy