dsh-plugin-vetting

MITLicense declared in the package manifest.

装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让'盲装'变成'知情安装'——恶意模式、越权路径、未检查依赖,一目了然。Static heuristic vetting for third-party DeepSeek Harness plugins: exfiltration, credential access, over-privileged paths, unvetted dependencies.

100

Security score

0 known advisories in v0.5.6

0-100 score computed by this site from verifiable signals only: known OSV.dev advisories affecting this exact version, how recently it was published, and the repository's OpenSSF Scorecard.advisory penalty −0 · staleness penalty −0

Weekly downloads

Downloads across all versions in the last 7 days, from the official npm downloads API (api.npmjs.org).

Unpacked size

Size of v0.5.6 on disk after npm install extracts the tarball, as reported by the npm registry.

43.3 kB

Dependencies

Direct runtime dependencies declared by v0.5.6. Transitive dependencies are not counted here — use the lockfile audit for the full tree.

0

Last publish

When v0.5.6 was published to the registry. Long gaps can indicate an unmaintained package.

5 hours ago

Security advisories

Vulnerabilities affecting v0.5.6 specifically, from OSV.dev — the open database aggregating the GitHub Advisory Database (GHSA) and CVEs. Links open the full advisory.

No known vulnerabilities affect v0.5.6.