dsh-plugin-vetting

truelove-dreamer

为了您的电脑安全,装插件前先体检:静态扫描恶意模式(外传/凭据/混淆/持久化)与高权限误用,覆盖传递依赖与官方包哈希基线(防供应链篡改),可选插件工具调用闸。

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

安装命令

dsh plugin --profile web add dsh-plugin-vetting

该命令来自上游目录,本站的自动审核尚未覆盖它——执行前请自行核对仓库。

安装后运行 dsh --profile web --dump-config 并重启对应 profile。插件会以你的本机权限运行第三方代码,安装前请检查源码。

信号

GitHub Stars4
30 天下载2778
分发方式NPM
收录时间2026-08-15

第三方安全扫描

4 项严重code-exec ×4扫描 6 个文件

静态代码分析结果,数据来自 dsh.so(扫描于 2026-08-22)。它检查的是代码里的危险调用模式,不等同于安全审计,也和本站「已验证」(真机启动验证)是两种不同的信号。

相关链接

同类插件