dsh-plugin-vetting

Source candidate

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

Author: truelove-dreamer · Security & Permissions · Catalog snapshot: 2026-09-04

What it may solve

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

Imported third-party catalog description; not a Registry verification conclusion.

Sources and public signals

truelove-dreamer/dsh-plugin-vetting

5 stars · 2945 downloads

Signals were provided by the source catalog and do not imply quality or safety. 2026-09-04

What can currently be confirmed

Not tested

DSH compatibility

No exact-version test is available.

Not tested

Security analysis

No Registry security conclusion is available.

Not tested

Functional verification

No functional smoke evidence is available.

Not tested

Permissions

Plugin permissions have not been resolved.

Not tested

Exact artifact

Version and integrity have not been resolved.

Continue checking with the plugin manager

Describe your task in a DSH conversation and mention dsh-plugin-vetting. The plugin manager can find this candidate through Registry, then inspect its actual source and version locally.

Get the plugin manager command