SEMANTIC DIRECTORY · plugin-directory-semantic-v3-18
Plugin & Supply-Chain Security Audit
在Plugin、Skill、包或依赖安装、激活前后进行静态Security审查和Source验证,包括恶意模式与投毒检测、能力披露、SBOM、漏洞库比对、哈希校验、风险评分和安装门禁。排除运行时行为防护。
Leaf membership
45 plugins
@npm-safe/dsh-tool-npm-safe@npm-safe/dsh-tool-npm-safeCatalog AnalyzedDeepSeek Harness plugin that blocks risky npm installs with metadata and deep supply-chain scansCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.4Evidence updated2026-09-09Public signals576 downloads@perrylink/dsh-skill-pack-security-provider@perrylink/dsh-skill-pack-security-providerCatalog AnalyzedProvider plugin for dsh-skill-pack-security: registers the pack's skills/ (zh) or skills-en/ (en) edition on ctx.skills AND the plugin_vet supply-chain gate tool on ctx.tools (license/SBOM/commit-lock/malware scans + five-dimension risk card). Ships bothCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact2.2.10Evidence updated2026-09-09Public signalsNo public usage signalsDeepGuardSoberReport-AI/DeepGuardCatalog AnalyzedA dsh plugin security audit agents team can trigger a security audit and provide a security audit report by submitting an issueCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-capability-receiptdongsheng123132/dsh-capability-receiptCatalog AnalyzedContent-addressed receipts for skills actually loaded by DeepSeek HarnessCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals4 starsdsh-capcheckheming-gmh/dsh-capcheckCatalog AnalyzedV0 capability-disclosure scanner for DeepSeek Harness (DSH) cordis plugins -- zero-execution static analysis of which sensitive services a plugin declares/referencesCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals1 starsdsh-guardwalliiiweiii/dsh-guardwallCatalog AnalyzedVets local, npm, and GitHub plugin source before installation, blocks configured high-risk tool calls at runtime, audits output secret patterns, and writes HMAC-chained local audit logs.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-install-guardniaccky/dsh-install-guardCatalog Analyzednpm 安装门禁Plugin:在 DeepSeek Harness 执行 npm install 前审计漏洞、许可证、体积与包健康度,自动放行/询问/拦截。CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-malware-auditrand0wn/dsh-malware-auditCatalog AnalyzedReal AST-based scan of installed plugins for malicious-intent patterns (dynamic eval, cross-plugin writes, exfiltration-shaped network calls), with an optional periodic schedule and auto-quarantine on critical findings.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-plugin-auditwefio/dsh-plugin-auditCatalog AnalyzedDSH plugin from wefio/dsh-plugin-auditCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-plugin-auditdsh-plugin-auditCatalog AnalyzedSecurity audit plugin for DeepSeek Harness: static permission profiling and a runtime sentinel for third-party pluginsCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.4Evidence updated2026-09-10Public signals951 downloadsdsh-plugin-checkdsh-plugin-checkCatalog AnalyzedCheck the dsh plugins you already installed against a registry of verified packages: which ship a broken package, which are pinned to a dsh version that no longer exists, and which run code on your machine at install time. Drafts the issue that fixes eachCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.0Evidence updated2026-09-09Public signals366 downloadsdsh-plugin-firewallMkaliezZ/dsh-plugin-firewallCatalog AnalyzedOffline-first static admission scanner for DeepSeek Harness community plugins: inspect a plugin package before you trust it.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-plugin-gateyoukongling/dsh-plugin-gateCatalog AnalyzedStandalone pre-install security gate for DeepSeek Harness plugins, with npm, Git, and local source review.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-plugin-gate863683348/dsh-plugin-gateCatalog AnalyzedInstallation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals1 starsdsh-plugin-guardGuojin0826/dsh-plugin-guardCatalog AnalyzedDeepSeek Harness PluginSecurity体检:静态代码 + 依赖审查 + AI 在线审计,绿/黄/红三级报告面板。CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-plugin-guardMangShe3-0/dsh-plugin-guardCatalog AnalyzedOffline-first security scanner for DeepSeek Harness plugins: prompt injection, ransomware, exfiltration, and supply-chain risks.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-plugin-guardtaxueseek/dsh-plugin-guardCatalog AnalyzedStatic-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.CompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-plugin-inspectordsh-plugin-inspectorCatalog AnalyzedKnow what a DeepSeek Harness plugin does before you install it — static pre-install analysis of a plugin directory or tarballCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.9.0Evidence updated2026-09-09Public signalsNo public usage signals
Categories are public semantic index facts, not a final recommendation. Compatibility, permissions, and source evidence remain separate.