{ "schema_version": 6, "generated_at": "2026-08-28T06:53:12.591Z", "plugins": [ { "id": "omdsh-dev/dsh-open-in-vscode", "name": "dsh-open-in-vscode", "author": "omdsh-dev", "description": "Open DeepSeek Harness workspace directories in VS Code directly from the web GUI.", "repo_url": "https://github.com/omdsh-dev/dsh-open-in-vscode", "homepage": "https://github.com/omdsh-dev/dsh-open-in-vscode", "stars": 54, "forks": 6, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-16T05:24:58Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "在 DeepSeek Harness Web 界面中直接打开工作区目录到 VS Code:侧边栏每个真实 Workspace 行的 … 菜单里新增一行 在 VSCode 中打开。", "en": "Open a workspace directory in VS Code straight from the DeepSeek Harness web GUI: every real Workspace row in the sidebar gains an Open in VSCode row inside its … overflow menu." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "lib/index.js", "line": 304, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 101, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 113, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 2220, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5391 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5392 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5393 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5394 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5400 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5401 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5402 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5403 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 1283, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 2641, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 2698, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4454 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4455 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4456 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4457 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4463 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4464 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4465 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4466 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 json-schema.org)", "file": "lib/index.js", "line": 877 }, { "explanation": "访问第三方网络地址(如 json-schema.org)", "file": "lib/index.js", "line": 12612 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/resolve.ts", "line": 12 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8aed144abdc158a332aa73bce42fc217d962f751", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh-notification", "name": "dsh-notification", "author": "omdsh-dev", "description": "Desktop notifications for DeepSeek Harness turn completions, with per-outcome controls and include/exclude keyword rules.", "repo_url": "https://github.com/omdsh-dev/dsh-notification", "homepage": "https://github.com/omdsh-dev/dsh-notification", "stars": 76, "forks": 10, "open_issues": 4, "watchers": 0, "pushed_at": "2026-08-19T07:12:27Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness Web GUI 的桌面通知插件。当会话结束一轮任务时,浏览器通过系统 Notification API 弹出通知,让你切到别的标签页也能知道 DSH 已经完成。按结束状态开关 + 关键词包含/排除规则,精确控制哪些完成要提醒。", "en": "Desktop notifications for the DeepSeek Harness web GUI. When a session finishes a turn, the browser shows a system notification (via the Notification API), so you can switch tabs and still know when DSH is done. Per-outcome toggles and include/exclude keyword" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 431 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 432 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 433 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 434 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 435 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 436 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 438 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 440 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 441 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 442 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 443 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 444 } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "ddec603395a223deb46c75b74274c41849c6a131", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Anionex/dsh-turn-rewind", "name": "dsh-turn-rewind", "author": "Anionex", "description": "deepseek harness对话和代码状态回退插件 | DSH — rewind conversation and workspace state, powered by a persistent Change Ledger", "repo_url": "https://github.com/Anionex/dsh-turn-rewind", "homepage": "https://github.com/Anionex/dsh-turn-rewind", "stars": 104, "forks": 7, "open_issues": 7, "watchers": 1, "pushed_at": "2026-08-26T05:26:45Z", "archived": false, "language": "JavaScript", "license": "BSD-3-Clause", "topics": [ "agent-rewind", "cordis-plugin", "deepseek-harness", "dsh", "dsh-plugin", "marisa-plugin", "restore-point", "turn-rewind", "workspace-safety" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 提供 Turn 级项目文件恢复,并可选择从恢复后的这一轮继续新对话。", "en": "DSH Turn Rewind is maintained by anionex. If you would like to follow my future work, follow me on X or GitHub." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 287 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/engine.js", "line": 469 }, { "explanation": "访问第三方网络地址(如 dsh.local)", "file": "lib/rewind-host.js", "line": 108 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b1b85f18aaaaf71d76c84613429ce04d71f69620", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "hust-open-atom-club/oh-dsh", "name": "oh-dsh", "author": "hust-open-atom-club", "description": " 一套 DSH runtime,Desktop、Web 与 TUI 三种开发体验。", "repo_url": "https://github.com/hust-open-atom-club/oh-dsh", "homepage": "https://dsh.openatom.club/", "stars": 287, "forks": 23, "open_issues": 19, "watchers": 4, "pushed_at": "2026-08-27T15:41:29Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agent", "cordis", "dsh", "dsh-plugin", "dsh-plugins" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "本仓库的文档会被人和 agent 阅读,因此范围内的每篇文档都以英文和简体中文维护。本页定义配对约定、检查、范围与排除规则;translation-rules.md 定义如何翻译;terminology.md 是术语真源。agent 的日常工作遵循根 AGENTS.md 中的轻量路径;扩展版 .agents/skills/dsh-translate-docs 工作流仅在用户显式调用时可用。", "en": "🖥️ Three interaction surfaces Use the same ohdsh command to start Desktop, Web, or TUI. All surfaces share sessions, credentials, skins, and plugin caches while keeping separate Profiles." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "scripts/smoke-client.cjs", "line": 143, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugins/plugin-marketplace/src/host/platform.ts", "line": 245 }, { "explanation": "访问第三方网络地址(如 oh-dsh-preview.internal)", "file": "plugins/plugin-marketplace/src/host/preview-proxy.ts", "line": 76 }, { "explanation": "访问第三方网络地址(如 open.bigmodel.cn)", "file": "plugins/vision/src/client/index.tsx", "line": 22 }, { "explanation": "访问第三方网络地址(如 example.invalid)", "file": "tests/update-manager.test.ts", "line": 41 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "49a1bd0aa4f98487d8120de590864414b9cbdee1", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Ruler4396/dsh-launcher", "name": "dsh-launcher", "author": "Ruler4396", "description": "DeepSeek Harness 的 Windows 轻量启动器:开机自启 + 独立小窗口,双击即用。", "repo_url": "https://github.com/Ruler4396/dsh-launcher", "homepage": "https://github.com/Ruler4396/dsh-launcher", "stars": 182, "language": "C#", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "launcher" ], "category": "plugin", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-14T00:00:00Z", "official": false, "compatibility": "compatible", "privacy_risk": false, "privacy_notes": [], "security_notes": [], "forks": 6, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-26T09:41:18Z", "archived": false, "description_i18n": { "zh": "DeepSeek Harness 的 Windows 轻量启动器:开机自启 + 独立小窗口,双击即用。", "en": "A lightweight Windows launcher for DeepSeek Harness: starts at login, runs in a small standalone window, and opens with a double click." }, "kind": "code", "reviewed_commit": "", "risk_level": "low", "risk_notes": [], "risk_evidence": [] }, { "id": "Nagi-ovo/dsh-visualize", "name": "dsh-visualize", "author": "Nagi-ovo", "description": "在 DSH 对话中生成交互式可视化|Render model-generated interactive cards inside DSH conversations", "repo_url": "https://github.com/Nagi-ovo/dsh-visualize", "homepage": "https://github.com/Nagi-ovo/dsh-visualize", "stars": 224, "forks": 4, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-27T21:36:31Z", "archived": false, "language": "TypeScript", "license": "BSD-3-Clause", "topics": [ "data-visualization", "deepseek-harness", "dsh-plugin", "interactive-visualization" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "让 DSH 不只回答一段文字。模型调用 visualize 后,Web UI 会在对话里直接出现一张可交互卡片,用来做模拟器、图表、对比面板或 UI mockup。", "en": "DSH does not have to answer with text alone. When the model calls visualize, the Web UI renders an interactive card inside the conversation for simulators, charts, comparison panels, and UI mockups." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e86f68fe66b980a0ebeed8ef7409522b0b720bed", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "NanmiCoder/dsh-agent-teams", "name": "dsh-agent-teams", "author": "NanmiCoder", "description": "AgentTeams plugin for DeepSeek Harness", "repo_url": "https://github.com/NanmiCoder/dsh-agent-teams", "homepage": "https://github.com/NanmiCoder/dsh-agent-teams", "stars": 1135, "forks": 90, "open_issues": 44, "watchers": 2, "pushed_at": "2026-08-27T03:37:39Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agentteams", "deepseekharness", "dsh", "dsh-agent-teams", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "dsh-agent-teams 让当前 DeepSeek Harness 会话成为队长:创建可续聊的子 Agent、把目标拆成有依赖的任务,并通过直达消息协调成员工作。", "en": "dsh-agent-teams turns the current DeepSeek Harness session into a captain that can assemble durable sub-agents, split a goal into dependency-aware tasks, and coordinate work through direct messages." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/client/ActivityPanel.tsx", "line": 292, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 x)", "file": "src/index.ts", "line": 179 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "tsdown.config.ts", "line": 72 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "0c21e5d2f45ec1ea7c9ee89ffc4ee77d1cb9262e", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "AdamPlatin123/awesome-dsh-plugins", "name": "awesome-dsh-plugins", "author": "AdamPlatin123", "description": "前部索引仓库(Radar):自动扫描发现所有 dsh 插件候选,经测试合格的移入后序精选目录仓库。", "repo_url": "https://github.com/AdamPlatin123/awesome-dsh-plugins", "homepage": "https://github.com/AdamPlatin123/awesome-dsh-plugins", "stars": 1421, "language": "Shell", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "awesome-list" ], "category": "plugin", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-14T00:00:00Z", "official": false, "compatibility": "compatible", "privacy_risk": false, "privacy_notes": [], "security_notes": [], "forks": 147, "open_issues": 8, "watchers": 0, "pushed_at": "2026-08-28T06:45:28Z", "archived": false, "description_i18n": { "zh": "前部索引仓库(Radar):自动扫描发现所有 dsh 插件候选,经测试合格的移入后序精选目录仓库。", "en": "A front-index repository (Radar): automatically scans and discovers DSH plugin candidates, then moves tested candidates into the downstream curated directory repositories." }, "kind": "code", "reviewed_commit": "", "risk_level": "low", "risk_notes": [], "risk_evidence": [] }, { "id": "bruc3van/awesome-dsh-plugin", "name": "awesome-dsh-plugin", "author": "bruc3van", "description": "用 30 秒找到适合你的 DeepSeek Harness 插件:告诉你插件解决什么问题、适合谁、从哪里开始。", "repo_url": "https://github.com/bruc3van/awesome-dsh-plugin", "homepage": "https://github.com/bruc3van/awesome-dsh-plugin", "stars": 291, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "awesome-list" ], "category": "plugin", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-14T00:00:00Z", "official": false, "compatibility": "compatible", "privacy_risk": false, "privacy_notes": [], "security_notes": [], "forks": 50, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-28T04:45:41Z", "archived": false, "description_i18n": { "zh": "用 30 秒找到适合你的 DeepSeek Harness 插件:告诉你插件解决什么问题、适合谁、从哪里开始。", "en": "Find the right DeepSeek Harness plugin in 30 seconds: tells you what problem a plugin solves, who it is for, and where to start." }, "kind": "code", "reviewed_commit": "", "risk_level": "low", "risk_notes": [], "risk_evidence": [] }, { "id": "Small-tailqwq/dsh-deep-whale", "name": "dsh-deep-whale", "author": "Small-tailqwq", "description": "Whale Girl skin series for DeepSeek Harness. 适用于 DeepSeek Harness 的,鲸鱼娘系列皮肤。", "repo_url": "https://github.com/Small-tailqwq/dsh-deep-whale", "homepage": "https://github.com/Small-tailqwq/dsh-deep-whale", "stars": 1777, "forks": 54, "open_issues": 16, "watchers": 1, "pushed_at": "2026-08-25T14:11:29Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness Web GUI 的鲸鱼娘主题皮肤系列(独立分发仓库)。", "en": "Whale-girl themed skin series for the DeepSeek Harness Web GUI (standalone distribution repository)." }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "orca-link/src/client/composer-collapse.ts", "line": 381, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "orca-link/src/client/composer-collapse.ts", "line": 494, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "orca-link/src/client/composer-motion.ts", "line": 322, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "orca-link/src/client/window-resume.ts", "line": 33, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": ".agents/skills/dsh-skin-install/scripts/stage-mutual-exclusion.mjs", "line": 25 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "orca-link/src/client/icons.ts", "line": 22 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "skin-manager/lib/client.js", "line": 405 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "cfd4a52071561a8a98de646770cbc79b5496a3de", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Electricitysheep/dsh-handbook", "name": "dsh-handbook", "author": "Electricitysheep", "description": "DeepSeek Harness (dsh) 从 0 到 1 深度手册:安装/插件开发/性能调优/实测案例/同模型多 Agent 实测对比(中文 + 英文 PDF)", "repo_url": "https://github.com/Electricitysheep/dsh-handbook", "homepage": "https://github.com/Electricitysheep/dsh-handbook", "stars": 696, "forks": 31, "open_issues": 0, "watchers": 3, "pushed_at": "2026-08-22T08:57:27Z", "archived": false, "language": "HTML", "license": "unknown", "topics": [ "agent", "agent-framework", "ai-agents", "beginners", "deepseek", "deepseek-ai", "dsh-plugin", "getting-started", "guide", "harness", "llm", "tutorial" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "description_i18n": { "zh": "> DeepSeek Harness 中文手册 × 生态观察中心——从 0 到 1 玩转 dsh,跟着 780 帖讨论区看懂生态 · 中文 · English", "en": "> From zero to one with DeepSeek Harness — the beginner's encyclopedia for DeepSeek's open-source agent runtime." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8f1f0b208694232c0caa4ce7461544c03b388cc3", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "wink-run/tokenbank", "name": "tokenbank", "author": "wink-run", "description": "Token Bank — the local LLM gateway that sits between your AI agents and every provider. Know where tokens go · Spend less with smart routing to Ollama, Groq, GitHub Models · Earn by sharing idle quota on a community P2P network. One-click onboarding for Cursor, Claude Code, Codex CLI, Gemini CLI — no agent changes. Full trace, seamless model swap", "repo_url": "https://github.com/wink-run/tokenbank", "homepage": "https://tokenbank.wink.run", "stars": 83, "language": "JavaScript", "license": "Apache-2.0", "topics": [ "agent", "anthropic", "claudecode", "codex", "cursor", "dsh", "dsh-plugin", "llm", "llm-gateway", "llm-gateway-system", "llm-proxy", "llm-router", "local", "local-first", "observability", "openai", "openclaw", "token", "token-usage", "tokenhub" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-14T10:03:43.084Z", "forks": 12, "open_issues": 3, "watchers": 1, "pushed_at": "2026-08-26T07:07:22Z", "archived": false, "description_i18n": { "zh": "> 个人AI中枢 · Token 管家 > > 用的明白 · 用的节省 · 用的简单 · 越用越懂你 · 闲置赚钱", "en": "Token Bank — the local LLM gateway that sits between your AI agents and every provider. Know where tokens go · Spend less with smart routing to Ollama, Groq, GitHub Models · Earn by sharing idle quota on a community P2P network. One-click onboarding for Cursor, Claude Code, Codex CLI, Gemini CLI — no agent changes. Full trace, seamless model swap" }, "description_i18n_checked_at": "2026-08-14T14:37:23.837Z", "kind": "code", "reviewed_commit": "", "risk_level": "high", "risk_notes": [ "访问第三方网络地址", "读取凭据类环境变量并发送到网络,可能泄露密钥", "使用动态代码或子进程执行" ], "risk_evidence": [] }, { "id": "Nagi-ovo/dsh-find-plugins", "name": "dsh-find-plugins", "author": "Nagi-ovo", "description": "", "repo_url": "https://github.com/Nagi-ovo/dsh-find-plugins", "homepage": "https://github.com/Nagi-ovo/dsh-find-plugins", "stars": 169, "language": "JavaScript", "license": "unknown", "topics": [ "agent-skills", "deepseek-harness", "dsh-plugin", "plugin-discovery" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-14T10:03:43.084Z", "forks": 1, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-15T15:58:22Z", "archived": false, "description_i18n": { "zh": "对 DSH 说一句「有没有插件能……」,它就会从全 GitHub 的 dsh-plugin topic 里找出候选,解释差别,等你选好以后再安装和验证。", "en": "Ask DSH, \"is there a plugin for this?\" It searches the GitHub dsh-plugin topic, explains the best matches, waits for your choice, then installs and verifies the selected plugin." }, "description_i18n_checked_at": "2026-08-14T14:37:23.837Z", "kind": "code", "reviewed_commit": "", "risk_level": "high", "risk_notes": [ "读取凭据类环境变量并发送到网络,可能泄露密钥" ], "risk_evidence": [] }, { "id": "Jayden-X-L/forkprobe", "name": "forkprobe", "author": "Jayden-X-L", "description": "Compare multiple skills on the same task and pick the winner.", "repo_url": "https://github.com/Jayden-X-L/forkprobe", "homepage": "https://jayden-x-l.github.io/forkprobe/", "stars": 71, "forks": 5, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-19T08:42:44Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent-workflow", "ai-agents", "claude-code", "codex", "deepseek-harness", "dsh-plugin", "pptx", "research-writing", "skill-comparison", "skills" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "别猜哪个 AI Skill 有用,直接并排看结果。", "en": "Find the skill that actually helps." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "docs/assets/site-pages.js", "line": 88, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "dsh-plugin/lib/index.js", "line": 82 }, { "explanation": "访问第三方网络地址(如 jayden-x-l.github.io)", "file": "package.json", "line": 6 }, { "explanation": "访问第三方网络地址(如 worker.test)", "file": "services/telemetry-worker/test/index.test.mjs", "line": 79 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "707d02b5a03c280237bb6d602bd8f1d09accf13e", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Alex-Yanggg/awesome-DSH-plugin", "name": "awesome-DSH-plugin", "author": "Alex-Yanggg", "description": "A meticulously curated list of useful plugins, extensions, tools and development resources built for DSH, covering productivity enhancement, functional expansion, debugging utilities and custom development modules.", "repo_url": "https://github.com/Alex-Yanggg/awesome-DSH-plugin", "homepage": "https://github.com/Alex-Yanggg/awesome-DSH-plugin", "stars": 87, "language": "Python", "license": "CC0-1.0", "topics": [ "agents", "awesome", "awesome-list", "deepseek", "dsh-plugin", "plugins" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-14T10:03:43.084Z", "forks": 86, "open_issues": 51, "watchers": 0, "pushed_at": "2026-08-15T03:22:05Z", "archived": false, "description_i18n": { "zh": "> 面向 DeepSeek Harness(DSH)的社区精选、厂商中立 Plugin 索引——覆盖开发工具、数据工作流、媒体、运维与日常生活等场景。", "en": "A meticulously curated list of useful plugins, extensions, tools and development resources built for DSH, covering productivity enhancement, functional expansion, debugging utilities and custom development modules." }, "description_i18n_checked_at": "2026-08-14T14:37:23.837Z", "kind": "code", "reviewed_commit": "", "risk_level": "moderate", "risk_notes": [ "访问第三方网络地址" ], "risk_evidence": [] }, { "id": "LaplaceYoung/oh-my-dsh", "name": "oh-my-dsh", "author": "LaplaceYoung", "description": "oh-my-dsh:面向 DSH (DeepSeek Harness) 的插件生态——700+ 插件,只通过扩展接缝注册,不修改 agent-loop 骨架", "repo_url": "https://github.com/LaplaceYoung/oh-my-dsh", "homepage": "https://github.com/LaplaceYoung/oh-my-dsh", "stars": 54, "forks": 3, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-15T07:29:10Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "agent", "deepseek-harness", "dsh-ecosystem", "dsh-plugin", "oh-my-dsh" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "37b66715ce55f1ad7669f12d73c7a56763e90eeb", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "hikariming/dshfind", "name": "dshfind", "author": "hikariming", "description": "DSH (DeepSeek Harness) 原理学习、插件市场与最佳实践 · Learn DSH principles, plugin marketplace & best practices", "repo_url": "https://github.com/hikariming/dshfind", "homepage": "https://dshfind.com", "stars": 233, "language": "MDX", "license": "unknown", "topics": [ "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-14T10:03:43.084Z", "forks": 14, "open_issues": 21, "watchers": 0, "pushed_at": "2026-08-28T03:00:18Z", "archived": false, "description_i18n": { "zh": "DSH (DeepSeek Harness) 原理学习、插件市场与最佳实践 · Learn DSH principles, plugin marketplace & best practices", "en": "The learning & sharing community for DeepSeek Harness (DSH)" }, "description_i18n_checked_at": "2026-08-14T14:37:23.837Z", "kind": "code", "reviewed_commit": "", "risk_level": "high", "risk_notes": [ "访问第三方网络地址", "读取凭据类环境变量并发送到网络,可能泄露密钥", "存在疑似混淆内容", "存在 Base64 解码行为" ], "risk_evidence": [] }, { "id": "vlln/plugin-registry", "name": "plugin-registry", "author": "vlln", "description": "DSH 插件生态基建:薄控制台(浏览器面板管理官方 repository 插件,0 patch)+ make-dsh-plugin skill 官方插件开发引导", "repo_url": "https://github.com/vlln/plugin-registry", "homepage": "https://github.com/vlln/plugin-registry", "stars": 57, "forks": 5, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-27T08:37:51Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "console", "deepseek-harness", "dsh", "dsh-plugin", "dsh-repository-plugin", "plugin-management", "ui" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 官方机制管「插件是什么、怎么跑」;本仓库补两件事(面板结构见 console README,开发引导见下文):", "en": "DeepSeek Harness's official mechanisms define \"what a plugin is and how it runs\"; this repository adds two things (panel structure: console README; guidance: below):" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json", "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json", "依赖 yaml@2.4.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ " ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险", "file": "package.json" }, { "explanation": "依赖 yaml@2.4.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/plugin/console/lib/index.mjs", "line": 660 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "packages/plugin/console/tests/discovery/enumerate.spec.ts", "line": 92 }, { "explanation": "访问第三方网络地址(如 x)", "file": "packages/plugin/console/tests/discovery/store.spec.ts", "line": 32 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 registry.npmmirror.com)", "file": "packages/plugin/console/tests/versions.spec.ts", "line": 58 }, { "explanation": "访问第三方网络地址(如 registry.npmmirror.com)", "file": "packages/plugin/console/tests/versions.spec.ts", "line": 59 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b0ae1ea03a6c04c548dd10bf58f0fe7a70a92b29", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "alingalingling/ui-status-label", "name": "ui-status-label", "author": "alingalingling", "description": "把你鲸鱼娘思考时的 deep diving 自定义成任意你想要的样子", "repo_url": "https://github.com/alingalingling/ui-status-label", "homepage": "https://github.com/alingalingling/ui-status-label", "stars": 42, "forks": 3, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-15T08:57:01Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "把你的鲸鱼娘思考时的 deep diving 自定义成任意你想要的样子。" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "pingfanfan/hello-dsh", "name": "hello-dsh", "author": "pingfanfan", "description": "从零开始,看懂 DeepSeek Harness 的「万物皆可插件」— 零基础插件开发教程(含 22 个中文技能实例)| Zero-to-plugin tutorial for DeepSeek Harness", "repo_url": "https://github.com/pingfanfan/hello-dsh", "homepage": "https://github.com/pingfanfan/hello-dsh/blob/main/docs/hello-dsh.md", "stars": 85, "forks": 6, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-14T13:42:33Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "ai-agent", "chinese", "cordis", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "tutorial" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "→ 完整教程:Hello DSH", "en": "→ Full tutorial: Hello DSH" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "0ee1f4ce1136077c2f6d08a09c21b7b092395e1d", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "xiaobright/dsh-anchored-standard", "name": "dsh-anchored-standard", "author": "xiaobright", "description": "Two-phase DeepSeek Harness preset: Minimal-aligned bootstrap, then full Standard tools (Project2 98/99)", "repo_url": "https://github.com/xiaobright/dsh-anchored-standard", "homepage": "https://github.com/xiaobright/modeltest", "stars": 3779, "forks": 115, "open_issues": 17, "watchers": 4, "pushed_at": "2026-08-28T03:10:01Z", "archived": false, "language": "JavaScript", "license": "NOASSERTION", "topics": [ "deepseek", "deepseek-harness", "dsh-plugin", "llm-agent" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码 combo-anchored/cot-drip.mjs 呈现 Cordis 插件骨架(apply(ctx))", "description_i18n": { "zh": "实验性 DeepSeek Harness agent preset 集合——一个基础模式、两个实时锚定变体和一个预制 会话模式:把模型轨迹锚定在 Minimal 条件上(真实的 Minimal 工具 schema、不注入自动 上下文),会话产生持久信号后晋升到小型 resident 目录,重型 Standard 工具按需解锁。", "en": "Experimental DeepSeek Harness agent presets — a base mode, two live-anchor variants, and one seeded prefab mode — that anchor a session's model trajectory on the Minimal condition" }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ shared/toolchoice-adapter.mjs" ], "risk_evidence": [ { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "shared/toolchoice-adapter.mjs" }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "prefab/instantiate.mjs", "line": 316 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "combo-anchored/custom-bash.mjs", "line": 129 }, { "explanation": "访问第三方网络地址(如 example.test)", "file": "test/toolchoice-adapter.test.mjs", "line": 155 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "25f21aefaf8ddc414da54d2e581e43740d977c6e", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "libukai/awesome-deepseek-harness", "name": "awesome-deepseek-harness", "author": "libukai", "description": "DeepSeek Harness 终极指南:快速入门、资源推荐、精选插件与实用工具 |The Ultimate Guide to DeepSeek Harness: QuickStart, Resources, Plugins&Toolkit", "repo_url": "https://github.com/libukai/awesome-deepseek-harness", "homepage": "https://x.com/libukai", "stars": 215, "forks": 59, "open_issues": 49, "watchers": 0, "pushed_at": "2026-08-28T02:20:46Z", "archived": false, "language": "unknown", "license": "unknown", "topics": [ "agent", "agent-harness", "awesome-list", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "plugins" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9f2be1099138ea9f1f78c29d6d2b9122c0e1e79d", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "titanwings/dsh-automation", "name": "dsh-automation", "author": "titanwings", "description": "DSH 自动化插件:让 Coding 任务按计划在全新 Agent Session 中运行,并由用户或 Agent 创建和管理定时任务。 / Run coding tasks in fresh Agent sessions and manage schedules from DSH Web or an Agent.", "repo_url": "https://github.com/titanwings/dsh-automation", "homepage": "https://github.com/titanwings/dsh-automation", "stars": 83, "forks": 8, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-23T19:19:30Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "automation", "coding-agent", "cordis", "deepseek-harness", "dsh", "dsh-bundle", "dsh-plugin", "scheduled-tasks" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 1478, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 2836, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 2893, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4649 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4650 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4651 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4652 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4658 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4659 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4660 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 4661 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "package.json", "line": 88 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 814 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 816 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 817 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 818 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 820 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 823 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 824 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 825 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 826 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 827 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 828 }, { "explanation": "访问第三方网络地址(如 developer.mozilla.org、en.wikipedia.org、json-schema.org、moment.github.io)", "file": "lib/index.js", "line": 11870 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/build.mjs", "line": 66 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f8f43b2873a3f9dd57d86d61eb401770b2bc9ca5", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "lhh010/dsh-ui-whale", "name": "dsh-ui-whale", "author": "lhh010", "description": "【求⭐】🐋DSH Web UI 全手绘像素鲸鱼伙伴插件:会话标题栏常驻,平时眨眼/偶尔摆尾/动胸鳍,思考运行时持续动起来,回合完成头顶喷水,点击还会冒爱心,不工作时还会偷懒睡觉,零核心改动。 【喜欢的话就点点star⭐吧~】", "repo_url": "https://github.com/lhh010/dsh-ui-whale", "homepage": "https://github.com/lhh010/dsh-ui-whale", "stars": 29, "forks": 0, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-28T05:28:51Z", "archived": false, "language": "TypeScript", "license": "BSD-3-Clause", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "description_i18n": { "zh": "DSH Web UI 的常驻像素鲸鱼伙伴插件:会话标题栏(标题行右侧)常驻一只小鲸鱼,随会话快照实时反应——零核心改动。", "en": "A resident pixel-whale companion plugin for the DSH Web UI: a small whale lives permanently in the session title bar (right side of the title row) and reacts in real time to the session snapshot — zero core changes." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "ba1f21013ff749ebe95bf0414ffcc7fbb6ca596f", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "bowenliang123/dsh-context", "name": "dsh-context", "author": "bowenliang123", "description": "The best DeepSeek Harness plugin for context insight and management, with context dashboard / browser and context command, for context statistics, composition, breakdown, evolution details, understanding how the context is made of, and how it evolves. 一站式 DeepSeek Harness 上下文可视化插件,Context 面板及浏览器与 Context 命令,透视上下文组成、演进、压缩、剪枝等事件与动作。", "repo_url": "https://github.com/bowenliang123/dsh-context", "homepage": "https://www.npmjs.com/package/dsh-context", "stars": 1126, "forks": 28, "open_issues": 2, "watchers": 7, "pushed_at": "2026-08-28T06:11:15Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "cordis-plugin", "deepseek-harness", "deepseek-harness-plugin", "dsh-external", "dsh-plugin", "dsh-plugins" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "en": "The best DeepSeek Harness plugin for Agent's context insights and management." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/client/components/contextModal.tsx", "line": 92, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/client.spec.mjs", "line": 54, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/helpers/viewBed.mjs", "line": 129, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/hmr-safety.client.spec.mjs", "line": 30, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/real-react.client.spec.mjs", "line": 71, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "tsdown.config.ts", "line": 50 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "1ddd99978f4e1057291180c07e03cc31758957a2", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "c3ll256/dsh-toy", "name": "dsh-toy", "author": "c3ll256", "description": "Toy Control Protocol for DSH", "repo_url": "https://github.com/c3ll256/dsh-toy", "homepage": "https://github.com/c3ll256/dsh-toy", "stars": 63, "forks": 6, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-14T11:42:30Z", "archived": false, "language": "TypeScript", "license": "BSD-3-Clause", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "dsh-toy 是一个 DeepSeek Harness 插件,用于将小玩具接入 DSH。", "en": "dsh-toy is a DeepSeek Harness plugin for connecting small toys to DSH." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.monsterparty.cc、monsterparty.cn)", "file": "lib/index.js", "line": 535 }, { "explanation": "访问第三方网络地址(如 api.monsterparty.cc、monsterparty.cn)", "file": "lib/index.js", "line": 592 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/intiface-download.ts", "line": 47 }, { "explanation": "访问第三方网络地址(如 monsterparty.cn)", "file": "tests/monsterparty.spec.ts", "line": 27 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "adece3467506c9e40e1393baca89f20caff20c2c", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Nwflower/dsh-chat-import", "name": "dsh-chat-import", "author": "Nwflower", "description": "Import 14+ external agent chat histories (Claude Code, Codex, ChatGPT, Cursor, Gemini, Reasonix, opencode, ZCode, Grok Build, OpenClaw, Pi, Hermes, Kimi CLI, DSH) into DeepSeek Harness as resumable sessions — full-fidelity, reverse export/sync, bundle backup. | 从 Claude Code、Codex、Reasonix 等 Agent 工具导入历史消息到 DeepSeek Harness 并继续对话。", "repo_url": "https://github.com/Nwflower/dsh-chat-import", "homepage": "https://www.npmjs.com/package/dsh-chat-import", "stars": 116, "forks": 16, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-27T15:46:44Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "agent", "ai-agents", "automation", "chatgpt", "claude-code", "codex", "cursor", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "gemini", "import", "jsonl", "migration", "openai", "plugin", "sessions", "transcript" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "便捷导入十余种外部 Agent 聊天历史,在 DeepSeek Harness 中继续对话,还可导出或写回 Claude Code、Codex、Kimi 等。", "en": "Import 15+ external agent conversation histories into DeepSeek Harness as full-fidelity, resumable sessions — and export / sync back to Claude Code, Codex, Kimi, or a portable interchange bundle." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 530, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 606, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/client.js", "line": 799 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/discovery.mjs", "line": 71 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b27250cc8b90e361fb237deab82774f6cde2cf58", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "HeiGeAi/deepseek-harness-skin", "name": "deepseek-harness-skin", "author": "HeiGeAi", "description": "DeepSeek Harness 换肤系统:21 套内置皮肤 + 一张图生成整套配色的自定义皮肤。数据源驱动,保对比度推导,构建期校验可读性。", "repo_url": "https://github.com/HeiGeAi/deepseek-harness-skin", "homepage": "https://github.com/HeiGeAi/deepseek-harness-skin", "stars": 51, "forks": 4, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-14T03:09:09Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "css", "dark-mode", "deepseek-harness", "dsh-plugin", "skin", "theme", "ui-theme" ], "category": "plugin", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "description_i18n": { "zh": "主题插件:基于 --dsw-* token 基础样式表(静态尺度 + 别名语义层)的 ThemeRuntime。该服务拥有实时主题偏好(light/dark/system),将 system 通过 prefers-color-scheme 解析为实际主题,并发布不可变的 ThemeSnapshot,通过 theme/change 事件通知变化;它绝不接触 DOM:ui-layout 的呈现器会应用解析后的快照(html { color-scheme }、body[data-ds-dark-theme]", "en": "The place you run agents should look the way you like." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 x)", "file": "tree/packages/client/ui-theme/src/skin-store.ts", "line": 134 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "238d114d1e5bf7358c4cb101b36ae129e70a55fe", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "oil-oil/dsh-vision", "name": "dsh-vision", "author": "oil-oil", "description": "Near-native image understanding for DeepSeek Harness", "repo_url": "https://github.com/oil-oil/dsh-vision", "homepage": "https://github.com/oil-oil/dsh-vision", "stars": 88, "forks": 9, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-18T16:11:50Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "image-understanding", "multimodal", "vision" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "| 当前主模型 | 图片处理方式 | 最终回答者 | | --- | --- | --- | | 支持图片 | 原图直接发送,不压缩、不预先 OCR | 当前模型 |", "en": "| Main model | Image path | Final answer | | --- | --- | --- | | Supports images | Original images are sent directly, without preprocessing or OCR | Current model |" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dashscope.aliyuncs.com、openrouter.ai、tokendance.space、zenmux.ai)", "file": "lib/index.js", "line": 363 }, { "explanation": "访问第三方网络地址(如 dashscope.aliyuncs.com、openrouter.ai、tokendance.space、zenmux.ai)", "file": "lib/index.js", "line": 297 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/see-config.ts", "line": 70 }, { "explanation": "访问第三方网络地址(如 dashscope.aliyuncs.com、zenmux.ai)", "file": "tests/client-settings.test.ts", "line": 17 }, { "explanation": "访问第三方网络地址(如 openrouter.example)", "file": "tests/vision-provider.test.ts", "line": 36 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9446a41dc96bd9fc96a7cc3b3a11365e125c9bd7", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "zenx0x/allinluna", "name": "allinluna", "author": "zenx0x", "description": "Resource-aware multi-agent orchestration for Codex and DeepSeek Harness (All in Flash DSH plugin)", "repo_url": "https://github.com/zenx0x/allinluna", "homepage": "https://github.com/zenx0x/allinluna", "stars": 47, "forks": 1, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-14T01:42:33Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "agent-orchestration", "agent-skills", "ai-agents", "allinflash", "codex", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "luna", "multi-agent", "orchestration" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> 别再把整个项目塞进一个 AI 对话里。", "en": "> Stop running an entire project inside one AI conversation." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugins/deepseek-harness/cli.js", "line": 54 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "723088a7c0d7342f077ad675c6ea72d7e3996536", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "like-study1/Oh-My-DSH", "name": "Oh-My-DSH", "author": "like-study1", "description": "🐳 DeepSeek Harness 插件聚合社区 — 自动同步 dsh-plugin 生态 · 精选目录 · 每 4 小时自动维护 | Oh-My-DSH: a community-maintained catalog of DeepSeek Harness plugins, auto-synced from the dsh-plugin topic", "repo_url": "https://github.com/like-study1/Oh-My-DSH", "homepage": "https://like-study1.github.io/Oh-My-DSH/", "stars": 74, "forks": 21, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-27T22:18:16Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "awesome-deepseek-harness", "awesome-dsh-plugin", "awesome-list", "deepseek-harness", "dsh", "dsh-ecosystem", "dsh-plugin", "plugin-marketplace", "plugins" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "> 汇聚 DeepSeek Harness 生态插件,构建权威、完整、可持续更新的聚合目录。以官方理念“万物皆可插件”(Everything is a Plugin)为指引,服务全球开发者。", "en": "> Aggregating the DeepSeek Harness plugin ecosystem into an authoritative, comprehensive and continuously updated directory, guided by the official philosophy \"Everything is a Plugin.\"" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "ff9e4bd22baa29f8de4b007fe49b83a9eb667dbe", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "WeirdSky924/agent-handoff-skill", "name": "agent-handoff-skill", "author": "WeirdSky924", "description": "Use this cross-platform skill in Codex or Claude Code to establish repository-local continuity memory so a future agent can recover objective, status, decisions, validation, risks, and next actions without relying on previous chat history.", "repo_url": "https://github.com/WeirdSky924/agent-handoff-skill", "homepage": "https://github.com/WeirdSky924/agent-handoff-skill", "stars": 26, "forks": 3, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-27T15:06:34Z", "archived": false, "language": "Python", "license": "unknown", "topics": [ "agent-handoff", "agent-skills", "claude-code", "codex", "context-engineering", "deepseek-harness", "dsh", "dsh-plugin", "session-memory" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 Cordis/DSH 落地标记(cordis.patch.yml/.dsh-plugin/dsh.client 等)", "description_i18n": { "zh": "如果这个 skill 对你的 Agent 接力流程有帮助,欢迎给仓库点一个 Star,让更多人更容易找到它。", "en": "If this skill helps your agent handoff workflow, please consider giving the repository a Star so more people can find it." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "templates/handoff-watch.mjs", "line": 337 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "889826fb1da6de7ff3f310e7d78f73af2a45d59e", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh-custom-tool", "name": "dsh-custom-tool", "author": "omdsh-dev", "description": "Create and manage sandboxed JavaScript tools for DeepSeek Harness with a Monaco editor and model-driven tool lifecycle.", "repo_url": "https://github.com/omdsh-dev/dsh-custom-tool", "homepage": "https://github.com/omdsh-dev/dsh-custom-tool", "stars": 23, "forks": 0, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-16T05:24:56Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 的自定义工具插件:用户在设置界面的「Custom Tool」页用 Monaco(VS Code)编辑器 + TypeScript 智能提示编写自己的 JavaScript 工具;模型也可以通过 custom_tool_create / custom_tool_remove / custom_tools_list 自主扩展和修剪同一套工具。所有工具持久化、热注册,并在下一步写入模型提示词。", "en": "Custom tools for the DeepSeek Harness: users author their own JavaScript tools in the settings UI with a Monaco (VS Code) editor and TypeScript intellisense, and the model grows and prunes the same toolset itself through custom_tool_create /" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "lib/index.js", "line": 587, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 384, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 396, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "lib/index.js", "line": 389 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 154 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7cb95649dca9b380c9a30af96bdbef87a76a2259", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Ayase34/gal-view", "name": "gal-view", "author": "Ayase34", "description": "把dsh会话界面切换成galgame游戏界面的插件", "repo_url": "https://github.com/Ayase34/gal-view", "homepage": "https://github.com/Ayase34/gal-view", "stars": 131, "forks": 9, "open_issues": 4, "watchers": 1, "pushed_at": "2026-08-16T00:02:38Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek", "deepseek-harness", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH Web GUI 会话页的 Galgame 风格对话视图 + 场景元素可视化编辑器(官方 bundle 插件格式)。", "en": "A galgame-style conversation view + scene-element visual editor for the DSH Web GUI session page (official bundle plugin format)." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "scripts/smoke.mjs", "line": 798, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/smoke.mjs", "line": 1016, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": ".dsh-plugin/client/Editor.jsx", "line": 498, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": ".dsh-plugin/client/Editor.jsx", "line": 504 }, { "explanation": "监听键盘输入事件", "file": ".dsh-plugin/client/GalView.jsx", "line": 40, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": ".dsh-plugin/client/GalView.jsx", "line": 71, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": ".dsh-plugin/client/scene.mjs", "line": 207 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": ".dsh-plugin/client/scene.mjs", "line": 392 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/build-client.mjs", "line": 34 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "tests/transcript.test.mjs", "line": 119 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d002fe0e7051c618a2665af3c653f9838cd6aa8a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Nagi-ovo/voyager", "name": "voyager", "author": "Nagi-ovo", "description": "Enhancement suite for Gemini, AI Studio, Claude & ChatGPT — plus a prompt manager for any web UI, DeepSeek Harness included. / 面向 Gemini、AI Studio、Claude 与 ChatGPT 的增强套件;提示词管理器可用于任意 Web UI,含 DeepSeek Harness。", "repo_url": "https://github.com/Nagi-ovo/voyager", "homepage": "https://voyager.nagi.fun/en", "stars": 19863, "forks": 659, "open_issues": 13, "watchers": 23, "pushed_at": "2026-08-26T12:01:01Z", "archived": false, "language": "TypeScript", "license": "GPL-3.0", "topics": [ "ai-studio", "browser-extension", "bun", "chat-management", "chatgpt", "chrome-extension", "claude-ai", "dsh", "dsh-plugin", "edge-addon", "firefox-addons", "gemini", "safari-extension" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "description_i18n": { "zh": "我们热爱 AI 聊天助手,但有时候总觉得它们少了一点\"秩序感\"。", "en": "We love AI chatbots, but sometimes we wish they had just a bit more structure." }, "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-16T04:01:02.723Z", "kind": "code", "reviewed_commit": "", "risk_level": "moderate", "risk_notes": [ "访问第三方网络地址", "读取环境变量并访问第三方地址,需确认未外发敏感信息", "存在 Base64 解码行为" ], "risk_evidence": [] }, { "id": "ccch1mneyyy/working-activity", "name": "working-activity", "author": "ccch1mneyyy", "description": "Lively Working-line extension for pi CLI and DSH", "repo_url": "https://github.com/ccch1mneyyy/working-activity", "homepage": "https://github.com/ccch1mneyyy/working-activity", "stars": 655, "forks": 231, "open_issues": 3, "watchers": 51, "pushed_at": "2026-08-20T08:08:44Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "pi-coding-agent", "pi-plugin", "statusline", "working-line" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 打造的一条实时 \"工作状态行\":模型的实时活动——俏皮思考文案、真正在跑的工具、已耗时、收尾摘要——在 agent 干活时展示出来。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/activity/working-activity/scripts/verify-registration.mjs", "line": 95 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "ce9d75f2510d8ab05113b28d8f7a5f9beeafe3bb", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "adoresever/graph-memory", "name": "graph-memory", "author": "adoresever", "description": "Deepseek Harness、Openclaw知识图谱记忆插件。2026年4月受邀发布在清华大学讨论会。Knowledge Graph + Memory;Knowledge Graph Context Engine for OpenClaw — extracts structured triples from conversations, compresses context 75%, enables cross-session experience reuse", "repo_url": "https://github.com/adoresever/graph-memory", "homepage": "https://github.com/adoresever/graph-memory", "stars": 577, "forks": 84, "open_issues": 12, "watchers": 4, "pushed_at": "2026-08-27T04:13:40Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "claude-code", "codex", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugins", "knowledge-graph", "memory", "openclaw", "openclaw-plugin", "opencode" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "为 AI Agent 提供可检索、可追溯、跨会话的长期记忆 一个宿主无关的图记忆内核,原生接入 DeepSeek Harness,并继续兼容 OpenClaw。", "en": "Traceable, searchable, cross-session memory for AI agents." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "访问第三方网络地址(如 api.openai.com)", "file": "src/engine/embed.ts", "line": 84 }, { "explanation": "访问第三方网络地址(如 api.minimaxi.com、evilminimaxi.com、example.com、example.test)", "file": "test/embed.test.ts", "line": 11 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "83ffb2771022a8d323feefc280ae4f198d8b85e5", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "superdesigndev/superdesign-skill", "name": "superdesign-skill", "author": "superdesigndev", "description": "The design skill for Claude Code, Cursor and any coding agent. Stop shipping AI-slop UI: turn it into shippable, tasteful frontend. Install: npx skills add superdesigndev/superdesign-skill. Powered by superdesign.dev", "repo_url": "https://github.com/superdesigndev/superdesign-skill", "homepage": "https://superdesign.dev", "stars": 467, "forks": 34, "open_issues": 4, "watchers": 0, "pushed_at": "2026-08-21T05:23:23Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "agent-skills", "ai-design", "claude-code", "claude-skill", "claude-skills", "coding-agent", "cursor", "design-agent", "dsh-plugin", "frontend", "superdesign", "ui-design", "ux-design" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "Stop shipping AI-slop UI. Coding agents write great code and mediocre interfaces: generic layouts, default shadcn everything, no taste. Superdesign is the skill that gives your agent design judgment, so the UI it ships actually looks considered." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 superdesign.dev)", "file": "package.json", "line": 27 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f9f05cd988c247dce6c072eaf9ac6b162f2ffc4b", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "tinqiao-oss/engramory", "name": "engramory", "author": "tinqiao-oss", "description": "A portable memory protocol for AI agents — load it as standing rules; a curation discipline + reference spec + optional cap hook.", "repo_url": "https://github.com/tinqiao-oss/engramory", "homepage": "https://github.com/tinqiao-oss/engramory", "stars": 176, "forks": 11, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-20T07:29:09Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent-memory", "ai-agents", "claude-code", "codex", "deepseek-harness", "dsh-plugin", "knowledge-base", "llm-memory", "long-term-memory", "markdown", "memory", "prompt-engineering", "zero-dependency" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "一套有主见、零基础设施的、面向小规模 / 本地 / 文件式智能体记忆的协议 —— 一套强约束的策展纪律 + 一个校验器(tools/engramory_doctor.py),以常驻规则形式加载(CLAUDE.md / AGENTS.md / 宿主的规则文件)。它不是数据库、不是框架、也不是按相关性加载的 skill。记忆就是一个文件夹:一堆小小的、人能直接读的 markdown 文件,加一个每次会话都加载的索引。没有数据库、没有向量、没有服务器——就是你能打开、能读、能改、能 diff", "en": "An opinionated, zero-infrastructure memory *protocol for small-scale, local, file-based agent memory** — a strict curation discipline plus a validator (tools/engramory_doctor.py), loaded as standing rules (CLAUDE.md /" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "39efc183a55cb3d2c56e11a42b2b5e059a193ce3", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "liceses/dsh-gitbash-preset", "name": "dsh-gitbash-preset", "author": "liceses", "description": "DeepSeek Harness 插件:一键安装「极简模式 (Git Bash)」agent preset —— 把 DSH 自带极简模式中的 bash 调用映射到 Git for Windows 的 bash(MSYS),让 Windows 上的极简模式真正可用。", "repo_url": "https://github.com/liceses/dsh-gitbash-preset", "homepage": "https://github.com/liceses/dsh-gitbash-preset", "stars": 137, "forks": 0, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-16T17:54:06Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin", "dsh-plugins" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "DSH 自带的极简模式在 Windows 上无法使用,失败有两层原因:" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 33 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "db21575b52e249f6a2eeeef0eb9ff92dc72943c8", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Vladimir-Human/humanizer-ru", "name": "humanizer-ru", "author": "Vladimir-Human", "description": "Скилл для ИИ-агентов: находит и убирает следы машинной генерации из русского текста. 38 паттернов, 39 regex-маркеров с реестром доказательств, слепые парные прогоны, файловый слой снятия C2PA/EXIF/XMP. Пакет на PyPI и онлайн-демо | Russian AI-writing humanizer skill, PyPI: humanizer-ru, live demo", "repo_url": "https://github.com/Vladimir-Human/humanizer-ru", "homepage": "https://skills.sh/vladimir-human/humanizer-ru/humanizer-ru", "stars": 117, "forks": 8, "open_issues": 4, "watchers": 2, "pushed_at": "2026-08-28T06:14:53Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent-skills", "ai", "ai-detection", "ai-writing", "c2pa", "claude", "claude-code", "claude-skills", "codex", "cursor", "dsh-plugin", "gemini-cli", "humanizer", "llm", "nlp", "opencode", "russian", "russian-nlp", "text-humanization", "watermarks" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "An agent skill that finds and removes traces of machine generation from Russian-language text. It rewrites AI-sounding prose into human prose without distorting the meaning, and it leaves live human writing alone: a false positive costs more than a miss." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "3106135980c9de04889047f52a13f31e6fa06726", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "yjh051108/dsh-super-injector", "name": "dsh-super-injector", "author": "yjh051108", "description": "", "repo_url": "https://github.com/yjh051108/dsh-super-injector", "homepage": "https://github.com/yjh051108/dsh-super-injector", "stars": 152, "forks": 19, "open_issues": 25, "watchers": 1, "pushed_at": "2026-08-24T19:11:01Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> ## 🎉 v0.3.0 重大声明(2026-08-14) > > 从经验补丁到源码契约——注入器完成规范重构。" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险", "file": "package.json" }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "src/index.ts", "line": 1454, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "src/index.ts", "line": 1506, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/index.ts", "line": 245 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c08136a526e7515dca106441e65cf7fccf63bbae", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Zhiyuan-Fan/Awesome-DeepSeek-Harness-Plugins", "name": "Awesome-DeepSeek-Harness-Plugins", "author": "Zhiyuan-Fan", "description": "Curated DeepSeek Harness (DSH) plugins, extensions, tools, skills, clients, runtimes, integrations, and verified references — English and Chinese.", "repo_url": "https://github.com/Zhiyuan-Fan/Awesome-DeepSeek-Harness-Plugins", "homepage": "https://github.com/Zhiyuan-Fan/Awesome-DeepSeek-Harness-Plugins", "stars": 390, "forks": 40, "open_issues": 6, "watchers": 0, "pushed_at": "2026-08-25T11:41:31Z", "archived": false, "language": "unknown", "license": "MIT", "topics": [ "agent-harness", "ai-agents", "awesome-list", "bilingual", "curated-list", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "extensions", "llm-tools", "plugins" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "description_i18n": { "zh": "每日维护的 DeepSeek Harness(DSH)公开插件与扩展精选目录,涵盖工具、技能、模型提供商、记忆、自动化、运行时、桌面客户端、浏览器集成与开发者工具。", "en": "A concise, daily-curated directory of public plugins and extensions for DeepSeek Harness (DSH), the open-source DeepSeek agent harness. Explore tools, skills, model providers, memory, automation, runtimes, desktop clients, browser integrations, and developer tools." }, "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-16T04:01:02.723Z", "kind": "code", "reviewed_commit": "", "risk_level": "moderate", "risk_notes": [ "访问第三方网络地址" ], "risk_evidence": [] }, { "id": "ZSeven-W/dsh-noema", "name": "dsh-noema", "author": "ZSeven-W", "description": "Noema long-term memory plugin for DSH: durable, inspectable agent memory with recall tools and a settings page.", "repo_url": "https://github.com/ZSeven-W/dsh-noema", "homepage": "op.zseven.tech", "stars": 127, "forks": 7, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-21T14:50:44Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-memory", "ai-agents", "coding-agent", "deepseek-harness", "dsh", "dsh-plugin", "long-term-memory", "mcp", "memory", "noema", "plugin", "typescript" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH Noema 将 DeepSeek Harness 与 Noema —— 一个面向编码智能体的本地优先、非向量记忆系统 —— 连接起来,让智能体能够跨会话保留持久知识,而不是每次对话都从零开始。", "en": "DSH Noema connects DeepSeek Harness with Noema — a local-first, non-vector memory system for coding agents — so an Agent keeps durable knowledge across sessions instead of starting every conversation from zero." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9cc3ab1ee00de04bf318be9cf2b102ae668ceeb2", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "WYH66666666/DSH-Transparent-UI-Plugin", "name": "DSH-Transparent-UI-Plugin", "author": "WYH66666666", "description": "是一层高自由度的玻璃质感主题,套在 DeepSeek Harness 网页端。顶栏、侧边栏、输入框、统计行、轨迹视图都成了磨砂玻璃片。玻璃模糊度、磨砂度、背景(流体或自定义壁纸,壁纸还能单独调模糊和磨砂)全都能在设置卡片里自由调节。关掉开关就回到原生界面,不改 DSH 任何一行源码。", "repo_url": "https://github.com/WYH66666666/DSH-Transparent-UI-Plugin", "homepage": "https://github.com/WYH66666666/DSH-Transparent-UI-Plugin", "stars": 388, "forks": 21, "open_issues": 21, "watchers": 1, "pushed_at": "2026-08-22T02:10:10Z", "archived": false, "language": "JavaScript", "license": "AGPL-3.0", "topics": [ "deepseek-harness", "deepseek-harness-plugin", "dsh", "dsh-plugin", "theme" ], "category": "plugin", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d94431a95bd147c11ef3fe95fa1915d1e96b028b", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "anysearch-team/anysearch-dsh", "name": "anysearch-dsh", "author": "anysearch-team", "description": "AnySearch web search provider and advanced search tools for DeepSeek Harness (DSH)", "repo_url": "https://github.com/anysearch-team/anysearch-dsh", "homepage": "https://www.anysearch.com", "stars": 318, "forks": 6, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-26T06:25:54Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-tools", "anysearch", "deepseek-harness", "dsh", "dsh-plugin", "typescript", "web-search" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/live-e2e.mjs" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/check-package.mjs", "line": 8 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/live-e2e.mjs" }, { "explanation": "访问第三方网络地址(如 api.anysearch.com、httpbin.dev)", "file": "scripts/live-e2e.mjs", "line": 85 }, { "explanation": "访问第三方网络地址(如 api.anysearch.com)", "file": "src/client.ts", "line": 26 }, { "explanation": "访问第三方网络地址(如 api.anysearch.test)", "file": "tests/batch.spec.ts", "line": 70 }, { "explanation": "访问第三方网络地址(如 api.anysearch.test、example.test、first.test、result.test)", "file": "tests/client.spec.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 api.anysearch.test、example.test)", "file": "tests/fetch-provider.spec.ts", "line": 12 }, { "explanation": "访问第三方网络地址(如 a.test、api.anysearch.com、api.anysearch.test、b.test)", "file": "tests/provider.spec.ts", "line": 29 }, { "explanation": "访问第三方网络地址(如 a.test、api.anysearch.test、example.test、finance.test)", "file": "tests/tools.spec.ts", "line": 71 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "dce7a51c74b80f8fa51e53f510a572ab6dd60f28", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "PC2005-cloud/dsh-pet", "name": "dsh-pet", "author": "PC2005-cloud", "description": "DSH 桌面宠物:一行命令装好即用的透明动画小桌宠,支持多开、大小位置随心配置;还内置 DIY 素材链,能用 AI 视频自造专属宠物", "repo_url": "https://github.com/PC2005-cloud/dsh-pet", "homepage": "https://github.com/PC2005-cloud/dsh-pet", "stars": 457, "forks": 29, "open_issues": 12, "watchers": 0, "pushed_at": "2026-08-25T19:54:02Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "desktop-pet", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "一只住在 DeepSeek Harness Web 界面里的桌面宠物:待机呼吸、随机动作(含打瞌睡)、偶尔转向、屏幕漫游、点击反应、可拖拽。", "en": "A desktop pet living inside the DeepSeek Harness Web UI: idle breathing, random actions (including dozing off), occasional turns, screen wandering, click reactions, and draggable." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "82ba588c7f849a62f1af5df81250e2ca8154c3a3", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "LX2000WASD/dsh-web-plugin-manager", "name": "dsh-web-plugin-manager", "author": "LX2000WASD", "description": "在 Web UI 中一键管理 DeepSeek Harness (DSH) 插件:查看、实时启停、安装/卸载、更新检测、健康检查(依赖/冲突/兼容性分析)、环境管理、插件市场。bundle 与非 bundle 插件全覆盖", "repo_url": "https://github.com/LX2000WASD/dsh-web-plugin-manager", "homepage": "https://github.com/LX2000WASD/dsh-web-plugin-manager", "stars": 67, "forks": 3, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-27T07:21:21Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "在 Web UI 中一键管理 DeepSeek Harness (DSH) 插件:查看、实时启停、安装/卸载、更新检测、健康检查(依赖/冲突/兼容性分析)、环境管理、插件市场。bundle 与非 bundle 插件全覆盖。", "en": "Manage DeepSeek Harness (DSH) plugins from the Web UI: inspect, live enable/disable, install/remove, update checks, health checks (dependency/conflict/compatibility analysis), environment management, and a plugin marketplace. Covers both bundle and non-bundle" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "tencent-connect/dsh-qqbot", "name": "dsh-qqbot", "author": "tencent-connect", "description": "让 QQ Bot 接入 DeepSeek Harness(dsh)的官方插件", "repo_url": "https://github.com/tencent-connect/dsh-qqbot", "homepage": "https://github.com/tencent-connect/dsh-qqbot", "stars": 80, "forks": 13, "open_issues": 14, "watchers": 1, "pushed_at": "2026-08-27T14:00:18Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin", "qqbot" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "基于 deepseek-harness (dsh) 的 QQ Bot IM 插件,将 QQ 消息平台作为 dsh agent 的前端协议驱动。", "en": "A QQ Bot IM plugin for deepseek-harness (dsh), driving the dsh agent loop with the QQ messaging platform as the frontend protocol." }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ src/gateway/bootstrap.ts", "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68) @ " ], "risk_evidence": [ { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "src/gateway/bootstrap.ts" }, { "explanation": "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68)", "file": "" }, { "explanation": "访问第三方网络地址(如 api.bot.qq.com)", "file": "src/gateway/bootstrap.ts", "line": 35 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/media/vision-tool.ts", "line": 168 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "5b5e9b8a374f7289bd398b266dd845137a081784", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "beancookie/awesome-dsh-plugin", "name": "awesome-dsh-plugin", "author": "beancookie", "description": "Awesome DeepSeek Harness (DSH) Plugin", "repo_url": "https://github.com/beancookie/awesome-dsh-plugin", "homepage": "https://beancookie.github.io/awesome-dsh-plugin/", "stars": 123, "forks": 87, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-27T07:27:42Z", "archived": false, "language": "HTML", "license": "CC0-1.0", "topics": [ "awesome", "awesome-list", "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "official": false, "compatibility": "compatible", "compatibility_reason": "检测到 DSH 插件标记(cordis/.dsh-plugin/dsh.bundle 等)", "description_i18n": { "zh": "DeepSeek Harness (DSH) 插件精选集。", "en": "Awesome DeepSeek Harness (DSH) Plugin." }, "privacy_risk": true, "privacy_notes": [], "security_notes": [], "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-16T04:01:02.723Z", "kind": "code", "reviewed_commit": "", "risk_level": "high", "risk_notes": [ "读取浏览器 Cookie/存储并发送到网络", "访问第三方网络地址" ], "risk_evidence": [] }, { "id": "liyupi/dsh-kun-like-pet", "name": "dsh-kun-like-pet", "author": "liyupi", "description": "Kun Like 桌宠 —— DeepSeek Harness 桌面宠物插件:右下角小坤宠随 Agent 工作状态切换 9 种动作,任务完成播放「你干嘛~哎哟」", "repo_url": "https://github.com/liyupi/dsh-kun-like-pet", "homepage": "https://github.com/liyupi/dsh-kun-like-pet", "stars": 86, "forks": 5, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-14T06:54:53Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "cordis", "deepseek-harness", "desktop-pet", "dsh", "dsh-plugin", "ikun", "plugin" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码 scripts/validate.mjs 呈现 Cordis 插件骨架(apply(ctx))", "description_i18n": { "zh": "> DeepSeek Harness(DSH)桌面宠物插件 —— 一只住在 Web 界面右下角的小坤宠。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "87bb6e1762618dd7727d285ffeeadd86a3799425", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Ychris12138/dsh-usage-stats", "name": "dsh-usage-stats", "author": "Ychris12138", "description": "Provider balances, subscription quotas, and token-usage analytics for the DeepSeek Harness Web GUI (dsh web).", "repo_url": "https://github.com/Ychris12138/dsh-usage-stats", "homepage": "https://github.com/Ychris12138/dsh-usage-stats", "stars": 129, "forks": 16, "open_issues": 6, "watchers": 0, "pushed_at": "2026-08-28T04:44:21Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek", "deepseek-harness", "deepseek-harness-plugin", "deepseek-harness-plugin-dev", "deepseek-harness-plugins", "dsh", "dsh-plugin", "dsh-plugins" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 网页端提供多供应商账户监测与 Token 用量分析。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 604, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 198.18.x.x、api.z.ai、usage.invalid)", "file": "lib/accounts.js", "line": 220 }, { "explanation": "访问第三方网络地址(如 api.kimi.com、api.minimax.io、api.minimaxi.com、api.z.ai)", "file": "lib/subscriptions.js", "line": 22 }, { "explanation": "访问第三方网络地址(如 api.ollama.com、api.passionapi.com、evil.example、late-provider.example.com)", "file": "scripts/test-accounts.mjs", "line": 38 }, { "explanation": "访问第三方网络地址(如 api.kimi.com、api.minimax.io、api.z.ai、minimax.io)", "file": "scripts/test-subscriptions.mjs", "line": 49 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7c88a445b73f78af7df6082fd671d22a293acb6d", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "omdsh-dev/dsh-mnemon", "name": "dsh-mnemon", "author": "omdsh-dev", "description": "Three-tier memory control plane for DeepSeek Harness: persistent runtime context, searchable project documents, pluggable long-term memory, smart routing, supervised agent workflows, WebUI, and headless tools.", "repo_url": "https://github.com/omdsh-dev/dsh-mnemon", "homepage": "https://github.com/Grivn/dsh-mnemon#readme", "stars": 263, "forks": 16, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-28T06:20:10Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-memory", "context-management", "cross-session-memory", "deepseek-harness", "document-search", "dsh-plugin", "llm-memory", "local-first", "long-term-memory", "memory-orchestration", "memory-provider", "multi-agent-memory", "persistent-memory", "pluggable-memory", "project-documents", "project-memory", "runtime-memory", "semantic-recall", "shared-agent-memory", "working-memory" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "| 层级 | 适合保存 | 如何进入 Agent 上下文 | 由谁管理 | |---|---|---|---| | 运行时 | 偏好、协作规则、项目约定、环境事实 | USER.md / MEMORY.md 每轮紧凑投影 | dsh-mnemon Host 确定性管理 |", "en": "| Tier | Keep here | How it reaches the Agent | Managed by | |---|---|---|---| | Runtime | Preferences, collaboration rules, project conventions, environment facts | Compact USER.md / MEMORY.md projection on every turn | Deterministic dsh-mnemon Host |" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/sidebar-entry.ts", "line": 26 }, { "explanation": "访问第三方网络地址(如 api.supermemory.ai、workspace-1.example、workspace-2.example)", "file": "tests/client-settings.spec.tsx", "line": 42 }, { "explanation": "访问第三方网络地址(如 memory.example)", "file": "tests/rpc.spec.ts", "line": 84 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7def5b2bddd4ecb746f09b0c8dee8032e72c690d", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Devin-AXIS/deepseek-design", "name": "deepseek-design", "author": "Devin-AXIS", "description": "DeepSeek Harness 可编辑设计系统:AI 生成、可视化编辑、模板市场与 PPT|Native Design & PPT Studio for DeepSeek Harness.", "repo_url": "https://github.com/Devin-AXIS/deepseek-design", "homepage": "https://github.com/Devin-AXIS/iPolloWork", "stars": 587, "forks": 140, "open_issues": 4, "watchers": 66, "pushed_at": "2026-08-27T10:40:51Z", "archived": false, "language": "JavaScript", "license": "NOASSERTION", "topics": [ "ai-design", "deepseek", "deepseek-harness", "design", "design-studio", "dsh-plugin", "ipollowork", "ipollowork-plugin", "plugin", "ppt", "presentation", "prototyping", "visual-editor" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Design 是由 iPolloWork 推出、专为 DeepSeek Harness 构建的原生可视化设计系统。" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#4", "依赖 @hono/node-server@1.8.0 存在已知漏洞(GHSA-92pp-h63x-v22m, GHSA-frvp-7c67-39w9, GHSA-hgxw-5xg3-69jx) @ ", "依赖 adm-zip@0.5.16 存在已知漏洞(GHSA-xcpc-8h2w-3j85) @ ", "依赖 hono@4.0.0 存在已知漏洞(GHSA-2234-fmw7-43wr, GHSA-26pp-8wgv-hjvm, GHSA-2gcr-mfcq-wcc3) @ ", "依赖 postcss@8.5.8 存在已知漏洞(GHSA-6g55-p6wh-862q, GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93) @ ", "依赖 sharp@0.34.5 存在已知漏洞(GHSA-f88m-g3jw-g9cj) @ " ], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "packages/deepseek-idesign/lib/index.js", "line": 137, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/deepseek-idesign/lib/index.js", "line": 1099, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/deepseek-idesign/lib/index.js", "line": 1150, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "packages/deepseek-ippt/lib/index.js", "line": 137, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/deepseek-ippt/lib/index.js", "line": 1099, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/deepseek-ippt/lib/index.js", "line": 1150, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "packages/deepseek-ivideo/lib/hyperframes/commands/contrast-audit.browser.js", "line": 16, "confidence": 1 }, { "explanation": "依赖 @hono/node-server@1.8.0 存在已知漏洞(GHSA-92pp-h63x-v22m, GHSA-frvp-7c67-39w9, GHSA-hgxw-5xg3-69jx)", "file": "" }, { "explanation": "依赖 adm-zip@0.5.16 存在已知漏洞(GHSA-xcpc-8h2w-3j85)", "file": "" }, { "explanation": "依赖 hono@4.0.0 存在已知漏洞(GHSA-2234-fmw7-43wr, GHSA-26pp-8wgv-hjvm, GHSA-2gcr-mfcq-wcc3)", "file": "" }, { "explanation": "依赖 postcss@8.5.8 存在已知漏洞(GHSA-6g55-p6wh-862q, GHSA-fxqj-rqcc-2cmp, GHSA-qx2v-qp2m-jg93)", "file": "" }, { "explanation": "依赖 sharp@0.34.5 存在已知漏洞(GHSA-f88m-g3jw-g9cj)", "file": "" }, { "explanation": "访问第三方网络地址(如 json-schema.org)", "file": "packages/deepseek-idesign/lib/index.js", "line": 2507 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d960f7af908433a06b811263f8b4d7f8f9c5c62a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "whyihaveyou/dsh-suite", "name": "dsh-suite", "author": "whyihaveyou", "description": "The living DeepSeek Harness plugin directory — refreshed hourly, compat-tested daily, with an in-app plugin store and scaffolder. DSH 插件活目录:每小时刷新,每日兼容实测,内置插件商店与脚手架。", "repo_url": "https://github.com/whyihaveyou/dsh-suite", "homepage": "https://whyihaveyou.github.io/dsh-suite/", "stars": 49, "forks": 10, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-28T05:27:51Z", "archived": false, "language": "HTML", "license": "MIT", "topics": [ "agent-framework", "awesome-list", "cordis", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "plugins", "scaffold" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "别再翻 dsh-plugin topic 了,这里都是还能跑的插件。", "en": "Stop scrolling the dsh-plugin topic. Find plugins that still work." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c431ceacf851a46807afb776bb7855a466424b53", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "HanaAyane/dsh-reasoning-effort", "name": "dsh-reasoning-effort", "author": "HanaAyane", "description": "DSH适用的Codex风格的思考强度滑块,以及大肥鱼跑步滑块。Codex-style model and reasoning-effort slider for DeepSeek Harness", "repo_url": "https://github.com/HanaAyane/dsh-reasoning-effort", "homepage": "https://github.com/HanaAyane/dsh-reasoning-effort", "stars": 117, "forks": 8, "open_issues": 4, "watchers": 0, "pushed_at": "2026-08-17T13:21:36Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek", "deepseek-harness", "dsh-plugin", "reasoning-effort" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "中文首页现在位于 README.md。", "en": "A Codex-style model and reasoning-effort control, built directly into DeepSeek Harness." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "83bc8c548749d7156a03d11d875d8117e9b5d994", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "awesome-dsh-plugin/dsh-find-plugin", "name": "dsh-find-plugin", "author": "awesome-dsh-plugin", "description": "Find DSH plugins inside the agent — live GitHub dsh-plugin topic search, star-ranked / 会话内搜索发现 DSH 插件", "repo_url": "https://github.com/awesome-dsh-plugin/dsh-find-plugin", "homepage": "https://github.com/awesome-dsh-plugin/dsh-find-plugin", "stars": 103, "forks": 3, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-19T05:24:43Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "一个用来找插件的插件——就像 skills.sh 的 /find-skills,DSH 版。", "en": "A plugin that finds plugins — think /find-skills from skills.sh, for DSH." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "访问第三方网络地址(如 awesome-dsh-plugin.com)", "file": "lib/index.js", "line": 16 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e7a27eb01606e6deccdaacccb8e0cfd992c0bcdc", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh-data-agent", "name": "dsh-data-agent", "author": "omdsh-dev", "description": "Connect DSH to your database for conversational data analysis and actionable business insights.", "repo_url": "https://github.com/omdsh-dev/dsh-data-agent", "homepage": "https://github.com/omdsh-dev/dsh-data-agent", "stars": 178, "forks": 13, "open_issues": 5, "watchers": 1, "pushed_at": "2026-08-27T04:46:41Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "data-agent", "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "让DeepSeek Harness连接数据库,用对话完成数据分析与商业洞察 自然语言查询 · 自动执行SQL · 连续分析 · Web UI · dsh-tui · 只读保护", "en": " " }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/tool-ZTOS4B33.js", "line": 780 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 188 }, { "explanation": "访问第三方网络地址(如 dsh.internal)", "file": "lib/routes.js", "line": 66 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/tool-ZTOS4B33.js", "line": 721 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7caa266c1036d7e3b42d4bc710350c1406b56957", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "openma-ai/deepseek-harness-tui", "name": "deepseek-harness-tui", "author": "openma-ai", "description": "TUI Plugin of DeepSeek Harness 让DeepSeek Harness在终端跑起来", "repo_url": "https://github.com/openma-ai/deepseek-harness-tui", "homepage": "https://github.com/openma-ai/deepseek-harness-tui", "stars": 64, "forks": 4, "open_issues": 6, "watchers": 1, "pushed_at": "2026-08-28T05:02:55Z", "archived": false, "language": "Rust", "license": "MIT", "topics": [ "agent", "agents", "dsh-plugin", "dsh-plugins", "tui", "tui-rs" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "* Rust/ratatui 编写的高性能程序界面.", "en": "- A high-performance interface written in Rust/ratatui." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "npm/lib/client-run.js", "line": 47, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "npm/lib/boot.js", "line": 189 }, { "explanation": "访问第三方网络地址(如 martty.sh)", "file": "npm/lib/martty-preset.js", "line": 12 }, { "explanation": "访问第三方网络地址(如 dshsuite.dev)", "file": "npm/package.json", "line": 8 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "scripts/tui-client-plugin-registry.test.mjs", "line": 85 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "20f503a8596caf933d864ab86ecff859569c4bab", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Tabbit-Browser/dsh-plugin", "name": "dsh-plugin", "author": "Tabbit-Browser", "description": "Tabbit Broser plugins for Deepseek Harness", "repo_url": "https://github.com/Tabbit-Browser/dsh-plugin", "homepage": "https://www.tabbit.ai", "stars": 95, "forks": 10, "open_issues": 10, "watchers": 0, "pushed_at": "2026-08-22T16:01:13Z", "archived": false, "language": "JavaScript", "license": "unknown", "topics": [ "awesome-dsh-plugin", "browser-automation", "browser-use", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugin-desktop", "dsh-plugin-market", "dsh-plugin-verify", "dsh-plugins", "playwright", "tabbit" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "这是一个为 DeepSeek Harness(DSH)打造的插件。安装后,DSH 中的 Agent 获得控制 Tabbit 浏览器的能力:通过 tabbit-cli——Tabbit 浏览器自带的、任务隔离的 Playwright CLI——操作真实网页、复用真实登录态,完成网页自动化、信息提取、QA 与基准测试等任务。", "en": "A plugin for DeepSeek Harness (DSH) that gives the agent control over your Tabbit Browser: real pages, real login state, and real interactions, driven through tabbit-cli — the task-isolated Playwright CLI owned by the browser itself. Use it for web" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "update-check.js", "line": 56 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7b69a066973d4198d70d91368c7a5643ed7a57ce", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "lire1131/dsh-undo-plugin", "name": "dsh-undo-plugin", "author": "lire1131", "description": "DSH crash-rescue plugin: undo config & plugin-code changes, secret-safe snapshots, one-click SAFE MODE, plus offline CLI/GUI that work even when DSH won't boot.", "repo_url": "https://github.com/lire1131/dsh-undo-plugin", "homepage": "https://github.com/lire1131/dsh-undo-plugin", "stars": 131, "forks": 5, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-28T01:27:25Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "rollback", "snapshot", "undo" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH 崩溃急救插件:配置与插件代码一键回滚、快照密钥脱敏、一键安全模式,DSH 起不来时也能用(离线 CLI/GUI)。", "en": "DSH crash-rescue plugin: undo config & plugin-code changes, secret-safe snapshots, one-click SAFE MODE, plus offline CLI/GUI that work even when DSH won't boot." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "HuanLinOTO/dsh-plugin-mineru", "name": "dsh-plugin-mineru", "author": "HuanLinOTO", "description": "向模型暴露 MinerU 文档解析工具,将 PDF/图片/DOCX/PPTX/XLSX 转为结构化 Markdown/JSON | Exposes MinerU document-parsing tools to the model, converting PDF/images/DOCX/PPTX/XLSX into structured Markdown/JSON", "repo_url": "https://github.com/HuanLinOTO/dsh-plugin-mineru", "homepage": "https://github.com/HuanLinOTO/dsh-plugin-mineru", "stars": 43, "forks": 2, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-27T18:18:50Z", "archived": false, "language": "TypeScript", "license": "NOASSERTION", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH 插件:向模型暴露 MinerU 文档解析工具。MinerU 可将 PDF、图片、DOCX、PPTX、XLSX 等文件转换为结构化的 Markdown / JSON。" }, "risk_level": "moderate", "risk_notes": [ "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json" ], "risk_evidence": [ { "explanation": "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "vlln/dsh-navbar", "name": "dsh-navbar", "author": "vlln", "description": "DSH 插件:对话节点导航条(右缘节点串快速跳转 user 消息)。官方 bundle 插件,dsh plugin --profile web add 安装", "repo_url": "https://github.com/vlln/dsh-navbar", "homepage": "https://github.com/vlln/dsh-navbar", "stars": 59, "forks": 1, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-28T03:20:18Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin", "plugin", "ui" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d89ba74f4e0403462a5e4c4feeec84a3e7a1cca2", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "yyyyukari/dsh-plugin-workshop", "name": "dsh-plugin-workshop", "author": "yyyyukari", "description": "Steam Workshop-style plugin browser for the DeepSeek Harness (DSH) Web UI - zero-server: GitHub-powered search, trending windows, Chinese search & bilingual translation, plugin-signature filtering, and smart one-click install/update/uninstall with an installed-plugins manager.", "repo_url": "https://github.com/yyyyukari/dsh-plugin-workshop", "homepage": "https://github.com/yyyyukari/dsh-plugin-workshop", "stars": 25, "forks": 1, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-17T14:53:20Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "workshop" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness(DSH)的创意工坊式插件浏览器——零服务器、单包开箱即用,内置在 DSH Web UI 侧栏「新会话」按钮正下方。", "en": "A Steam Workshop-style plugin browser for DeepSeek Harness (DSH) — zero-server, single-package, living right inside the DSH Web UI sidebar, directly under the \"New Session\" button." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "tianji-qingtian/dsh-model-router", "name": "dsh-model-router", "author": "tianji-qingtian", "description": "模型路由与成本优化器:简单问题 flash 直答、故障自动降级、会话 token/缓存/成本实时面板 | Model router & cost optimizer for DeepSeek Harness: flash quick-answers for simple questions, failure fallback, live token/cache/cost panel", "repo_url": "https://github.com/tianji-qingtian/dsh-model-router", "homepage": "https://github.com/tianji-qingtian/dsh-model-router", "stars": 7, "forks": 0, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-25T07:37:39Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh-plugin", "model-router" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness(dsh)的模型路由与成本优化插件。简单问题直接在便宜模型上作答(零前缀、无缓存税),瞬态故障自动降级,并在输入框下方实时显示每个会话的 token / 缓存命中 / 成本统计。", "en": "Model Router & Cost Optimizer for DeepSeek Harness (dsh). Answers simple questions directly on the cheap model (zero prefix, no cache tax), degrades gracefully on transient provider failures, and shows live per-session token / cache-hit / cost figures right" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "tsdown.config.mjs", "line": 64 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "121ee7d4d9f0b7e063ff1533d8ac20c2bf63f128", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Moeblack/dsh-message-edit", "name": "dsh-message-edit", "author": "Moeblack", "description": "DSH 插件:分支式消息编辑、重掷、重试与版本时间线 | DSH plugin: branch-based message editing, reroll, retry, version timeline", "repo_url": "https://github.com/Moeblack/dsh-message-edit", "homepage": "https://github.com/Moeblack/dsh-message-edit", "stars": 44, "forks": 15, "open_issues": 16, "watchers": 0, "pushed_at": "2026-08-16T11:33:37Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "dsh-message-edit(npm · GitHub)为 DeepSeek Harness 补充基于事件溯源的「消息编辑与重生成」能力。插件不改写历史事件,也不修改 DSH 引擎内部;每次编辑、重生成或重试都会从目标回合之前创建一个新会话版本,原会话始终保留并可随时切回。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 message-edit.local)", "file": "index.mjs", "line": 637 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/build.mjs", "line": 10 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/InlineMessageEdit.tsx", "line": 38 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b78a167064ca612f1c400060d2bfc1dc9bc46436", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "147228/dsh-xiaoyao-skins", "name": "dsh-xiaoyao-skins", "author": "147228", "description": "夕小瑶 × DeepSeek Harness Web 皮肤合集、安装器与社区创作工具链", "repo_url": "https://github.com/147228/dsh-xiaoyao-skins", "homepage": "https://147228.github.io/dsh-xiaoyao-skins/", "stars": 23, "forks": 2, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-14T11:02:03Z", "archived": false, "language": "CSS", "license": "NOASSERTION", "topics": [ "ai-agent", "community", "deepseek-harness", "dsh-plugin", "skin", "theme", "xiaoyao" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "一套面向真实 DeepSeek Harness Web profile 的社区皮肤合集表现层插件。每套皮肤都是一个可安装、可卸载、可测试的 DSH,不替换会话、模型、工具、沙箱或插件系统;" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 147228.github.io)", "file": "package.json", "line": 8 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "174f65d9135e932383a8f3a19fa522f16875a139", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "keleus/deepseek-pet", "name": "deepseek-pet", "author": "keleus", "description": "在你的deepseek-harness上养一只吃白饭的大蓝鲸", "repo_url": "https://github.com/keleus/deepseek-pet", "homepage": "https://github.com/keleus/deepseek-pet", "stars": 42, "forks": 4, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-21T02:37:11Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "deepseek-harness-plugin", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Pet 是一个嵌入 DeepSeek Harness 网页的交互式桌宠插件。它会跟随当前任务、 工具调用、上下文占用和活跃会话自动切换 DeepSeek 表情,并通过呼吸、弹跳、倾斜、 视差和淡入动画呈现 Live2D 风格效果。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/styles.js", "line": 37 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "35132a4fcfa1a40e4cab7e0163939cc5b25de38b", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Anionex/dsh-computer-use", "name": "dsh-computer-use", "author": "Anionex", "description": "为 DeepSeek Harness 提供电脑控制插件:新鲜 Accessibility 观测、过期状态拒绝、作用域权限与安全输入(目前支持macos)|Accessibility-first macOS Computer Use bundle for DSH with fresh observations, stale-state rejection, scoped permissions, and safe input.", "repo_url": "https://github.com/Anionex/dsh-computer-use", "homepage": "https://github.com/Anionex/dsh-computer-use", "stars": 34, "forks": 5, "open_issues": 3, "watchers": 1, "pushed_at": "2026-08-22T14:38:27Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "accessibility", "agent-skills", "agent-tools", "appkit", "computer-use", "deepseek", "deepseek-harness", "desktop-automation", "dsh", "dsh-plugin", "gui-automation", "human-in-the-loop", "macos", "native-apps", "typescript" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 提供原生 macOS 控制能力,默认不碰你的真实光标,也不因指针动作抢占前台;Bundle 可以在键盘输入前把目标应用带到前台,保证输入可靠。", "en": "DSH Computer Use is maintained by anionex. If you would like to follow my future work, follow me on X or GitHub." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/artifacts.js", "line": 52, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/service.js", "line": 416, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/types/artifacts.d.ts", "line": 9, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/providers/native-helper.js", "line": 113 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "76bfe8607f61945c1cbb84e73976e601100c13a2", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh-plugin-check", "name": "dsh-plugin-check", "author": "omdsh-dev", "description": "DSH 插件健康检查工具:扫描插件仓库的清单协议 / patch 格式 / 构建陷阱 / hub 收录状态,零依赖只读,注册 plugin_check 工具", "repo_url": "https://github.com/omdsh-dev/dsh-plugin-check", "homepage": "https://github.com/omdsh-dev/dsh-plugin-check", "stars": 27, "forks": 2, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-25T10:27:29Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "diagnostics", "dsh", "dsh-plugin", "linting", "plugin-health" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "DSH 插件健康检查工具 —— 扫描插件仓库,诊断清单协议 / patch 格式 / 构建陷阱 / hub 收录状态,输出合规报告与修复建议。只读,不修改、不构建被检查仓库。", "en": "DSH plugin health-check tool — scans plugin repositories and diagnoses manifest protocol / patch format / build pitfalls / hub inclusion status, outputting compliance reports with fix suggestions. Read-only — it does not modify or build the checked repository." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "16fa22316f11d06476bc2f57fdc0a62843d0c5d5", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "AwesomeHou/dsh-plugin-marketplace", "name": "dsh-plugin-marketplace", "author": "AwesomeHou", "description": "Plugin marketplace for DeepSeek Harness — live-syncs the GitHub dsh-plugin topic (1800+ repos) into a searchable, paginated settings tab with one-click install and agent tools (market_search / market_install).", "repo_url": "https://github.com/AwesomeHou/dsh-plugin-marketplace", "homepage": "https://github.com/AwesomeHou/dsh-plugin-marketplace", "stars": 27, "forks": 4, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-19T07:59:29Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "ai-agent", "cordis", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "plugin", "plugin-marketplace" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "一个 DeepSeek Harness 的永久插件,把 GitHub dsh-plugin topic 变成插件市场——既是 设置 → 插件 里的标签页,也提供一组模型工具,让 agent 自己就能搜索并安装插件。", "en": "A permanent DeepSeek Harness plugin that turns the GitHub dsh-plugin topic into a plugin marketplace — a tab inside 设置 → 插件, plus a pair of model" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "whitelonng/dshcode", "name": "dshcode", "author": "whitelonng", "description": "Community desktop companion for DeepSeek Harness — one-click Electron app for macOS and Windows", "repo_url": "https://github.com/whitelonng/dshcode", "homepage": "https://github.com/whitelonng/dshcode", "stars": 450, "forks": 20, "open_issues": 0, "watchers": 8, "pushed_at": "2026-08-28T02:07:18Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent", "deepseek", "deepseekharness-plugin", "dsh-plugin", "harness" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/dsh-tool-session-query", "description_i18n": { "zh": "DSHCode is a free, open-source desktop AI agent app for macOS and Windows. It wraps the official open-source DeepSeek Harness Web UI and plugin runtime in a single installable Electron application — no Node.js, no terminal, no CLI required." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj) @ " ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj)", "file": "" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9065ac3bf4b1e40bee3f567e1616318f06c26d36", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "bugmaker2/dsh-plugin-template", "name": "dsh-plugin-template", "author": "bugmaker2", "description": "Template for deepseek-harness plugin development.", "repo_url": "https://github.com/bugmaker2/dsh-plugin-template", "homepage": "https://github.com/bugmaker2/dsh-plugin-template", "stars": 47, "forks": 1, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-27T04:58:58Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "这是一个使用 TypeScript + tsdown 开发的最小 DeepSeek Harness 插件 bundle。Harness 加载它时会输出 hello world。", "en": "A minimal TypeScript DeepSeek Harness plugin bundle. It prints hello world when Harness loads it." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "114f75999d8d477951cbd91ee4d1e0f5360d6627", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "kingOfSoySauce/dsh-liang-skin", "name": "dsh-liang-skin", "author": "kingOfSoySauce", "description": "DeepSeek Harness 滑动变阻器皮肤", "repo_url": "https://github.com/kingOfSoySauce/dsh-liang-skin", "homepage": "https://github.com/kingOfSoySauce/dsh-liang-skin", "stars": 147, "forks": 9, "open_issues": 3, "watchers": 1, "pushed_at": "2026-08-21T03:23:04Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 234 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 243 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 247 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 251 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 255 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 269 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 273 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 282 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 291 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 1091 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 1156 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/index.tsx", "line": 502 }, { "explanation": "访问第三方网络地址(如 dsh.local)", "file": "src/index.js", "line": 77 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "976fcbf9b4a91b79f14b90c16cbe0d3f553c2bd3", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Vladimir-Human/ru-marketplace-mcp", "name": "ru-marketplace-mcp", "author": "Vladimir-Human", "description": "Девять российских маркетплейсов и китайский Taobao как MCP-серверы: Wildberries, Ozon, Яндекс Маркет, Детский мир, Авито, Мегамаркет, Lamoda, DNS, Ситилинк. Плюс сравнение цен по всем сразу. Только чтение, ключи не нужны.", "repo_url": "https://github.com/Vladimir-Human/ru-marketplace-mcp", "homepage": "https://github.com/Vladimir-Human/ru-marketplace-mcp/releases/tag/v1.4.1", "stars": 77, "forks": 13, "open_issues": 8, "watchers": 2, "pushed_at": "2026-08-24T10:55:42Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "avito", "citilink", "claude", "detmir", "dns", "dsh-plugin", "ecommerce", "lamoda", "marketplace", "mcp", "mcp-server", "megamarket", "ozon", "price-comparison", "python", "russia", "scraping", "taobao", "wildberries", "yandex-market" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "MCP-серверы для российских и китайских маркетплейсов. Цены, наличие, рейтинги, отзывы и реквизиты продавцов с Wildberries, Ozon, Яндекс Маркета, Детского мира, Авито, AliExpress, Taobao, Мегамаркета, Lamoda, DNS и Ситилинка." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d4dfccf43ea3962c827096f312f5184cc7aa1736", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "THEWOLFWALKER/dsh-notifier", "name": "dsh-notifier", "author": "THEWOLFWALKER", "description": "Unified notification push plugin for DeepSeek Harness (DSH): one minimal notify() API, 8 channel adapters (telegram/dingtalk/feishu/wxpusher/pushplus/serverchan/bark/webhook), dual trigger (auto session events + agent tool).", "repo_url": "https://github.com/THEWOLFWALKER/dsh-notifier", "homepage": "https://github.com/THEWOLFWALKER/dsh-notifier", "stars": 79, "forks": 4, "open_issues": 5, "watchers": 1, "pushed_at": "2026-08-27T14:53:23Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> 你的 agent,装进口袋。 —— 通知、审批、遥控,全在你的手机里。", "en": "> Your agent, in your pocket. — 通知、审批、遥控,全在你的手机里。" }, "risk_level": "moderate", "risk_notes": [ "依赖 axios@1.16.0 存在已知漏洞(GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548) @ ", "依赖 protobufjs@7.2.6 存在已知漏洞(GHSA-2pr8-phx7-x9h3, GHSA-66ff-xgx4-vchm, GHSA-685m-2w69-288q) @ ", "依赖 qs@6.14.2 存在已知漏洞(GHSA-q8mj-m7cp-5q26) @ ", "依赖 ws@8.19.0 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p) @ " ], "risk_evidence": [ { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/admin/api.mjs", "line": 266 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/admin/api.mjs", "line": 267 }, { "explanation": "依赖 axios@1.16.0 存在已知漏洞(GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548)", "file": "" }, { "explanation": "依赖 protobufjs@7.2.6 存在已知漏洞(GHSA-2pr8-phx7-x9h3, GHSA-66ff-xgx4-vchm, GHSA-685m-2w69-288q)", "file": "" }, { "explanation": "依赖 qs@6.14.2 存在已知漏洞(GHSA-q8mj-m7cp-5q26)", "file": "" }, { "explanation": "依赖 ws@8.19.0 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/hook-server.mjs", "line": 4 }, { "explanation": "访问第三方网络地址(如 api.day.app)", "file": "src/adapters/bark.mjs", "line": 3 }, { "explanation": "访问第三方网络地址(如 oapi.dingtalk.com)", "file": "src/adapters/dingtalk.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 open.feishu.cn)", "file": "src/adapters/feishu.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 pushplus.plus)", "file": "src/adapters/pushplus.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 api.sgroup.qq.com、bots.qq.com)", "file": "src/adapters/qq-bot.mjs", "line": 13 }, { "explanation": "访问第三方网络地址(如 sct.ftqq.com、sctapi.ftqq.com)", "file": "src/adapters/serverchan.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 ...、api.chanify.net、api.pushover.net、api2.pushdeer.com)", "file": "src/adapters/spec-channels.mjs", "line": 69 }, { "explanation": "访问第三方网络地址(如 api.telegram.org)", "file": "src/adapters/telegram.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 qyapi.weixin.qq.com)", "file": "src/adapters/wecom-app.mjs", "line": 11 }, { "explanation": "访问第三方网络地址(如 wxpusher.zjiecode.com)", "file": "src/adapters/wxpusher.mjs", "line": 2 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "cc4781e9939210b2d91b63f5448ccef40708a7c2", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Mars-Sea/dsh-commandcode-provider", "name": "dsh-commandcode-provider", "author": "Mars-Sea", "description": "Unofficial DeepSeek Harness LLM provider plugin for Command Code: live model catalog, reasoning-effort support, Models-page card. Ported from pi-commandcode-provider (MIT).", "repo_url": "https://github.com/Mars-Sea/dsh-commandcode-provider", "homepage": "https://github.com/Mars-Sea/dsh-commandcode-provider", "stars": 117, "forks": 8, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-27T00:20:36Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "llm", "llm-provider", "plugin", "provider", "typescript" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "非官方 DeepSeek Harness 的 LLM provider 插件,用于 Command Code,移植自 pi-commandcode-provider(MIT 协议)。", "en": "Unofficial DeepSeek Harness LLM provider plugin for Command Code, ported from pi-commandcode-provider (MIT)." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "访问第三方网络地址(如 api.commandcode.ai、commandcode.ai)", "file": "src/adapter.ts", "line": 100 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/index.ts", "line": 70 }, { "explanation": "访问第三方网络地址(如 api.commandcode.ai)", "file": "src/client/locales.ts", "line": 111 }, { "explanation": "访问第三方网络地址(如 a.com、api.commandcode.ai、example.com、new.example.com)", "file": "tests/settings.test.ts", "line": 169 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "370f614e1ca4f5a236111b3eb3a05967b7aa6514", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "cocofhu/anime-find", "name": "anime-find", "author": "cocofhu", "description": "DeepSeek Harness 搜番插件:对话内多源搜索番剧,卡片展示 Bangumi 评分与详情,支持复制磁力。", "repo_url": "https://github.com/cocofhu/anime-find", "homepage": "https://github.com/cocofhu/anime-find#readme", "stars": 163, "forks": 31, "open_issues": 2, "watchers": 11, "pushed_at": "2026-08-27T11:54:39Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "anime", "anime-search", "bangumi", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "magnet", "mikan", "plugin", "torrent", "typescript" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 搜番插件。在对话中搜索番剧,以可点击卡片展示结果,并在详情面板中查看字幕组、磁力链接和种子文件。" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "监听键盘输入事件", "file": "src/client.js", "line": 653, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/streaming.ts", "line": 188, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 anibt.net、api.animes.garden、bgm.tv、dm1.xfdm.pro)", "file": "src/client.js", "line": 208 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dm1.xfdm.pro)", "file": "src/config-store.ts", "line": 40 }, { "explanation": "访问第三方网络地址(如 dm1.xfdm.pro)", "file": "src/config-store.ts", "line": 18 }, { "explanation": "访问第三方网络地址(如 anibt.net、api.animes.garden、mikanani.me)", "file": "src/host.ts", "line": 41 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 anibt.example、anibt.net、api.animes.garden、garden.example)", "file": "src/tests/config-store.test.ts", "line": 150 }, { "explanation": "访问第三方网络地址(如 anibt.example、anibt.net、api.animes.garden、garden.example)", "file": "src/tests/config-store.test.ts", "line": 24 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 anibt.net、api.animes.garden、media.example.test、mikanani.me)", "file": "src/tests/host-settings.test.ts", "line": 157 }, { "explanation": "访问第三方网络地址(如 anibt.net、api.animes.garden、media.example.test、mikanani.me)", "file": "src/tests/host-settings.test.ts", "line": 22 }, { "explanation": "访问第三方网络地址(如 cdn.example、mikanani.me)", "file": "src/tests/search-text.test.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 anibt.net、api.animes.garden、cdn.example.test、cdn.media.example.test)", "file": "src/tests/streaming.test.ts", "line": 18 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/update-check.ts", "line": 11 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c3f69a51c04f37e1ddd9ea46a739561e4bdef6ae", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "wxkingstar/SpecFusion", "name": "SpecFusion", "author": "wxkingstar", "description": "在 DeepSeek Harness / Claude Code / Cursor / Codex / Gemini CLI 里直接搜索 20 个中国开放平台的 65,600+ 篇 API 文档;零配置,支持 Skill 与 DSH 原生插件。", "repo_url": "https://github.com/wxkingstar/SpecFusion", "homepage": "https://specfusion.kingstar.xin/", "stars": 57, "forks": 15, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-21T05:38:28Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agents", "alipay", "api-documentation", "chinese-api", "claude-code", "cursor", "deepseek-harness", "dingtalk", "douyin", "dsh-plugin", "feishu", "gemini-cli", "jd", "pinduoduo", "shein", "taobao", "wechat", "wecom", "xiaohongshu", "youzan" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "🌐 官网:specfusion.kingstar.xin" }, "risk_level": "moderate", "risk_notes": [ "依赖 fastify@5.2.1 存在已知漏洞(GHSA-444r-cwp2-x5xf, GHSA-jx2c-rxcm-jvmq, GHSA-mg2h-6x62-wpwc) @ ", "依赖 axios@1.7.7 存在已知漏洞(GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw, GHSA-3p68-rc4w-qgx5) @ ", "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68) @ " ], "risk_evidence": [ { "explanation": "存在编码转义字符串(疑似混淆)", "file": "api/src/services/tokenizer.ts", "line": 89 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "scrapers/src/utils/tokenizer.ts", "line": 57 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/ego-bridge.mjs", "line": 83, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/pdd-refresh.mjs", "line": 55, "confidence": 1 }, { "explanation": "依赖 fastify@5.2.1 存在已知漏洞(GHSA-444r-cwp2-x5xf, GHSA-jx2c-rxcm-jvmq, GHSA-mg2h-6x62-wpwc)", "file": "" }, { "explanation": "依赖 axios@1.7.7 存在已知漏洞(GHSA-35jp-ww65-95wh, GHSA-3g43-6gmg-66jw, GHSA-3p68-rc4w-qgx5)", "file": "" }, { "explanation": "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "api/src/services/tokenizer.ts", "line": 28 }, { "explanation": "访问第三方网络地址(如 ideservice.alipay.com、opendocs.alipay.com)", "file": "scrapers/src/sources/alipay.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 dashscope.aliyuncs.com、help.aliyun.com)", "file": "scrapers/src/sources/bailian.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 open.italent.cn)", "file": "scrapers/src/sources/beisen.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 open.dewu.com)", "file": "scrapers/src/sources/dewu.ts", "line": 13 }, { "explanation": "访问第三方网络地址(如 oapi.dingtalk.com、open.dingtalk.com)", "file": "scrapers/src/sources/dingtalk.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 op.jinritemai.com)", "file": "scrapers/src/sources/douyin.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 applink.feishu.cn、open.feishu.cn)", "file": "scrapers/src/sources/feishu.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 open.jd.com)", "file": "scrapers/src/sources/jd.ts", "line": 14 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 gw-api.pinduoduo.com、open-api.pinduoduo.com、open.pinduoduo.com)", "file": "scrapers/src/sources/pinduoduo.ts", "line": 348 }, { "explanation": "访问第三方网络地址(如 gw-api.pinduoduo.com、open-api.pinduoduo.com、open.pinduoduo.com)", "file": "scrapers/src/sources/pinduoduo.ts", "line": 12 }, { "explanation": "访问第三方网络地址(如 open.sheincorp.com)", "file": "scrapers/src/sources/shein.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 open.taobao.com)", "file": "scrapers/src/sources/taobao.ts", "line": 9 }, { "explanation": "访问第三方网络地址(如 volcengine.com)", "file": "scrapers/src/sources/volcengine-docs.ts", "line": 9 }, { "explanation": "访问第三方网络地址(如 api.volcengine.com)", "file": "scrapers/src/sources/volcengine.ts", "line": 9 }, { "explanation": "访问第三方网络地址(如 weapp.eteams.cn)", "file": "scrapers/src/sources/weaver.ts", "line": 9 }, { "explanation": "访问第三方网络地址(如 api.weixin.qq.com、developers.weixin.qq.com)", "file": "scrapers/src/sources/wechat-miniprogram.ts", "line": 9 }, { "explanation": "访问第三方网络地址(如 pay.weixin.qq.com)", "file": "scrapers/src/sources/wechat-pay.ts", "line": 11 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 developer.work.weixin.qq.com)", "file": "scrapers/src/sources/wecom.ts", "line": 382 }, { "explanation": "访问第三方网络地址(如 developer.work.weixin.qq.com)", "file": "scrapers/src/sources/wecom.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 open.xiaohongshu.com)", "file": "scrapers/src/sources/xiaohongshu.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 doc.youzanyun.com)", "file": "scrapers/src/sources/youzan.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 open.pinduoduo.com)", "file": "scripts/pdd-refresh.mjs", "line": 25 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f1780beb5dcda37a8ff5130ecf0e11b744830e78", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "kanghelyu/dsh-deepseek-flow", "name": "dsh-deepseek-flow", "author": "kanghelyu", "description": "", "repo_url": "https://github.com/kanghelyu/dsh-deepseek-flow", "homepage": "https://deepseekflow.kanghelyu.org/", "stars": 55, "forks": 4, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-19T15:49:27Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "ai-workflow", "dark-mode", "deepseek-harness", "developer-tools", "dsh-plugin", "flow-editor", "markdown", "visual-workflow", "visualization", "workflow", "workflow-builder", "workflow-management" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "- Markdown 是唯一事实来源——一份总控 WORKFLOW.md,每个步骤拥有独立的 STEP.md 工作区。", "en": "- Markdown as the source of truth — one master WORKFLOW.md, plus one STEP.md workspace for each step." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 3333, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 95 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 126 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 957 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 959 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 961 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 963 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 966 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 967 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 968 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 970 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 972 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 973 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/standalone-ui-qa.mjs", "line": 174, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/entry.js", "line": 1947, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 980 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "87a4e8d43102c22f0e1f2b0cbd9af120de611310", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Q00/ouroboros", "name": "ouroboros", "author": "Q00", "description": "Agent OS: the agent gets smarter on its own. We just hold the line: the grading command and expected result never make it into the success contract we hand it. Interview-gated, staged evaluation, budgeted evolution loop. MCP server, 13 runtimes: Claude Code, Codex CLI, Gemini CLI, OpenCode, Copilot, Kiro and more.", "repo_url": "https://github.com/Q00/ouroboros", "homepage": "https://ouroboros.page/", "stars": 5715, "forks": 570, "open_issues": 65, "watchers": 14, "pushed_at": "2026-08-28T06:28:56Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent-os", "agentic-ai", "ai-agent", "ai-coding-agent", "claude-code", "cli", "codex", "coding-agent", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "github-copilot", "llm-evaluation", "llm-orchestration", "loop-engineering", "mcp", "opencode" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "和任何操作系统一样,Ouroboros 分成三层:一层稳定的、提供原语的 OS 层,一层承载领域工作流的应用层,还有一个人真正坐在前面的 shell。三个仓库,一个技术栈:", "en": "Like any OS, Ouroboros is split into a stable OS layer of primitives, an application layer of domain workflows, and a shell that humans actually sit in front of. Three repos, one stack:" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "645a2f04adc1a8b3ab961cb8856bec06ff3b8325", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "agentrq/agentrq", "name": "agentrq", "author": "agentrq", "description": "AgentRQ: Human-in-loop realtime conversational task manager for AI Agents. Self-hosted! Control your own agents from wherever you want Mobile, Web, Desktop. Designed to work well with your own Claude subscriptions and any harness.", "repo_url": "https://github.com/agentrq/agentrq", "homepage": "https://agentrq.com", "stars": 1092, "forks": 78, "open_issues": 14, "watchers": 1, "pushed_at": "2026-08-26T03:31:11Z", "archived": false, "language": "Go", "license": "Apache-2.0", "topics": [ "acp-client", "acp-gateway", "agentic-ai", "agentic-workflow", "agents", "claude-code", "deepseek-harness", "deepseek-harness-plugin", "dsh-plugin", "hermes-agent", "mcp", "mcp-server", "openclaw", "opencode", "supervisor", "task", "task-manager", "task-scheduler", "todo" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> 本文是面向中文开发者的导读,帮助快速理解 AgentRQ 的定位、架构和本地运行方式。", "en": "AgentRQ is a modern, high-performance platform designed for seamless collaboration between human operators and AI agents. It leverages the Model Context Protocol (MCP) to allow AI models (like Claude) to interact directly with your workspace's task management" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#1", "依赖 dompurify@3.4.10 存在已知漏洞(GHSA-55q2-fjhq-7xh7, GHSA-c2j3-45gr-mqc4, GHSA-cmwh-pvxp-8882) @ ", "依赖 postcss@8.5.12 存在已知漏洞(GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849) @ ", "依赖 @modelcontextprotocol/sdk@1.12.0 存在已知漏洞(GHSA-345p-7cg4-v4c7, GHSA-8r9q-7v3j-jr4g, GHSA-w48q-cv73-mx4w) @ " ], "risk_evidence": [ { "explanation": "依赖 dompurify@3.4.10 存在已知漏洞(GHSA-55q2-fjhq-7xh7, GHSA-c2j3-45gr-mqc4, GHSA-cmwh-pvxp-8882)", "file": "" }, { "explanation": "依赖 postcss@8.5.12 存在已知漏洞(GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849)", "file": "" }, { "explanation": "依赖 @modelcontextprotocol/sdk@1.12.0 存在已知漏洞(GHSA-345p-7cg4-v4c7, GHSA-8r9q-7v3j-jr4g, GHSA-w48q-cv73-mx4w)", "file": "" }, { "explanation": "访问第三方网络地址(如 workspace.mcp.example)", "file": "plugins/deepseek-harness/test/sessions.test.ts", "line": 8 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8779a273e0b9175671152a4b55692b9e728ff87d", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "GanyuanRan/Aegis", "name": "Aegis", "author": "GanyuanRan", "description": "Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across long tasks.", "repo_url": "https://github.com/GanyuanRan/Aegis", "homepage": "https://github.com/GanyuanRan/Aegis", "stars": 1137, "forks": 51, "open_issues": 1, "watchers": 5, "pushed_at": "2026-08-27T02:35:00Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent-skills", "ai-agents", "ai-coding", "architecture-driven-development", "awsome-coding-plugin", "baseline-first", "claude-code", "codex", "coding-agents", "dive", "dsh-plugin", "evidence-driven", "first-principles", "opencode", "software-architecture", "spec-driven-development", "spec-kit" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "Aegis Method Pack 让 AI 编程 agent 变得可信:少返工、更安全、说“完成”前先给证据。", "en": "English is now the default GitHub README:" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "extensions/dsh/bootstrap.js", "line": 26 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "fea84dd545385ebdbe1c7ceab0d2afb8fe9d4600", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "syncable-dev/memtrace-public", "name": "memtrace-public", "author": "syncable-dev", "description": "Structural memory for AI coding agents. Bi-temporal graph, MCP-native, zero LLM calls. Cursor · Claude Code · Codex · DeepSeek Harness · Hermes · VS Code · Windsurf.", "repo_url": "https://github.com/syncable-dev/memtrace-public", "homepage": "https://memtrace.io", "stars": 466, "forks": 41, "open_issues": 20, "watchers": 4, "pushed_at": "2026-08-20T12:12:36Z", "archived": false, "language": "Python", "license": "NOASSERTION", "topics": [ "agent-memory", "ai-agents", "bi-temporal-graph", "claude-code", "code-intelligence", "code-search", "coding-agents", "cursor", "deepseek-harness", "dsh", "dsh-plugin", "knowledge-graph", "local-first", "mcp", "mcp-server", "rust", "semantic-search", "structural-memory", "temporal-analysis", "tree-sitter" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "en": "Memtrace runs as a DeepSeek Harness plugin. Install Harness first (npm install -g @deepseek-ai/dsh — that is the dsh command), then add Memtrace:" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "27da0253307024aa1db134d548b101bf177c4508", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "xmanrui/dsh-im", "name": "dsh-im", "author": "xmanrui", "description": "通过扫码或机器人凭据把IM机器人接入DeepSeek Harness(支持飞书、微信、钉钉、企业微信、QQ、Slack、Telegram、Discord和WhatsApp)。 Connect IM bots to DeepSeek Harness via QR code or credentials (9 channels).", "repo_url": "https://github.com/xmanrui/dsh-im", "homepage": "https://github.com/xmanrui/dsh-im", "stars": 924, "forks": 95, "open_issues": 16, "watchers": 1, "pushed_at": "2026-08-28T02:53:39Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "ai-agents", "chatbot", "cordis", "deepseek", "deepseek-harness", "dingtalk-bot", "discord-bot", "dsh", "dsh-plugin", "feishu-bot", "im-bot", "slack-bot", "telegram-bot", "wechat-bot", "whatsapp-bot" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "通过扫码、App Manifest 或已有机器人凭据把 IM 机器人接入 DeepSeek Harness,并让本机 Harness 主动连接公网 AI Office。一个插件、一个设置入口,统一管理九种 IM 渠道和 AI Office Connector。每个 IM 渠道都支持接入多个机器人,各机器人的连接状态、工作区和会话绑定彼此独立。", "en": "Connect IM bots to DeepSeek Harness by scanning a QR code, using an App Manifest, or entering existing bot credentials, and let the local Harness connect outward to a public AI Office. One plugin and one settings entry manage nine multi-bot IM channels and" }, "risk_level": "high", "risk_notes": [ "读取凭据类环境变量并发送到网络,可能泄露密钥 @ test/channels/feishu/feishu-proxy.test.mjs" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 1423, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 198 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 200 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 202 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 204 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 205 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 206 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 207 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 210 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 211 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 212 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 213 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "src/channels/shared/harness-approval.mjs", "line": 21 }, { "explanation": "存在 Base64 解码行为", "file": "src/channels/weixin/weixin-api.mjs", "line": 43, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/dingtalk/dingtalk-bridge.test.mjs", "line": 160, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/feishu/bridge.test.mjs", "line": 11, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/feishu/message-utils.test.mjs", "line": 13, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/qq/bridge.test.mjs", "line": 102, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/wecom/bridge.test.mjs", "line": 11, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/channels/weixin/weixin-bridge.test.mjs", "line": 133, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/image-bridge.test.mjs", "line": 6, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "test/image-prompt.test.mjs", "line": 15, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 api.slack.com、office.example.com、w3.org)", "file": "lib/client.js", "line": 1185 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugin-src/client/build.mjs", "line": 10 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "plugin-src/client/channels/dingtalk/index.js", "line": 36 }, { "explanation": "访问第三方网络地址(如 office.example.com)", "file": "plugin-src/client/channels/office/index.js", "line": 116 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.dingtalk.com、oapi.dingtalk.com)", "file": "src/channels/dingtalk/dingtalk-api.mjs", "line": 253 }, { "explanation": "访问第三方网络地址(如 api.dingtalk.com、oapi.dingtalk.com)", "file": "src/channels/dingtalk/dingtalk-api.mjs", "line": 5 }, { "explanation": "访问第三方网络地址(如 api.dingtalk.com)", "file": "src/channels/dingtalk/dingtalk-runtime.mjs", "line": 98 }, { "explanation": "访问第三方网络地址(如 open.feishu.cn、open.larksuite.com)", "file": "src/channels/feishu/feishu-app.mjs", "line": 2 }, { "explanation": "访问第三方网络地址(如 api.slack.com)", "file": "src/channels/slack/manifest.mjs", "line": 32 }, { "explanation": "访问第三方网络地址(如 slack.com)", "file": "src/channels/slack/slack-api.mjs", "line": 3 }, { "explanation": "访问第三方网络地址(如 api.telegram.org)", "file": "src/channels/telegram/telegram-api.mjs", "line": 3 }, { "explanation": "访问第三方网络地址(如 ilinkai.weixin.qq.com、novac2c.cdn.weixin.qq.com)", "file": "src/channels/weixin/weixin-api.mjs", "line": 5 }, { "explanation": "访问第三方网络地址(如 login.dingtalk.com)", "file": "test/channels/dingtalk/client-api.test.mjs", "line": 67 }, { "explanation": "访问第三方网络地址(如 dingtalk.com、download.example.test、download.oss-cn-hangzhou.aliyuncs.com、h5.dingtalk.com)", "file": "test/channels/dingtalk/dingtalk-api.test.mjs", "line": 37 }, { "explanation": "访问第三方网络地址(如 oapi.dingtalk.com、oapi.dingtalk.com.attacker.example)", "file": "test/channels/dingtalk/dingtalk-bridge.test.mjs", "line": 38 }, { "explanation": "访问第三方网络地址(如 oapi.dingtalk.com)", "file": "test/channels/dingtalk/dingtalk-controller.test.mjs", "line": 110 }, { "explanation": "访问第三方网络地址(如 harness.example)", "file": "test/channels/dingtalk/harness-client.test.mjs", "line": 70 }, { "explanation": "访问第三方网络地址(如 open-dev.dingtalk.com)", "file": "test/channels/dingtalk/rpc.test.mjs", "line": 16 }, { "explanation": "访问第三方网络地址(如 cdn.discordapp.com、example.com)", "file": "test/channels/discord/discord.test.mjs", "line": 227 }, { "explanation": "访问第三方网络地址(如 example.com、open.feishu.cn)", "file": "test/channels/feishu/bridge.test.mjs", "line": 557 }, { "explanation": "访问第三方网络地址(如 accounts.feishu.cn、open.feishu.cn)", "file": "test/channels/feishu/client-api.test.mjs", "line": 125 }, { "explanation": "访问第三方网络地址(如 open.feishu.cn)", "file": "test/channels/feishu/connection-test-client.test.mjs", "line": 187 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "test/channels/feishu/feishu-proxy.test.mjs" }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "test/channels/feishu/message-utils.test.mjs", "line": 72 }, { "explanation": "访问第三方网络地址(如 accounts.feishu.cn)", "file": "test/channels/feishu/multi-bot-controller.test.mjs", "line": 162 }, { "explanation": "访问第三方网络地址(如 accounts.feishu.cn、evil.example、open.feishu.cn、proxy.test)", "file": "test/channels/feishu/plugin-host.test.mjs", "line": 260 }, { "explanation": "访问第三方网络地址(如 open.feishu.cn、open.larksuite.com、user)", "file": "test/channels/feishu/repair-manager.test.mjs", "line": 46 }, { "explanation": "访问第三方网络地址(如 office.example.com、public.example)", "file": "test/channels/office/office.test.mjs", "line": 76 }, { "explanation": "访问第三方网络地址(如 attacker.example、multimedia.nt.qq.com.cn)", "file": "test/channels/qq/bridge.test.mjs", "line": 89 }, { "explanation": "访问第三方网络地址(如 q.qq.com)", "file": "test/channels/qq/controller-and-rpc.test.mjs", "line": 25 }, { "explanation": "访问第三方网络地址(如 example.com、files-origin.slack.com、files.slack.com、slack.com)", "file": "test/channels/slack/slack.test.mjs", "line": 148 }, { "explanation": "访问第三方网络地址(如 wecom.example)", "file": "test/channels/wecom/bridge.test.mjs", "line": 300 }, { "explanation": "访问第三方网络地址(如 work.weixin.qq.com)", "file": "test/channels/wecom/controller-and-rpc.test.mjs", "line": 18 }, { "explanation": "访问第三方网络地址(如 liteapp.weixin.qq.com)", "file": "test/channels/weixin/plugin-host.test.mjs", "line": 29 }, { "explanation": "访问第三方网络地址(如 attacker.example、attacker.test、ilinkai.weixin.qq.com、liteapp.weixin.qq.com)", "file": "test/channels/weixin/weixin-api.test.mjs", "line": 62 }, { "explanation": "访问第三方网络地址(如 ilinkai.weixin.qq.com)", "file": "test/channels/weixin/weixin-bridge.test.mjs", "line": 77 }, { "explanation": "访问第三方网络地址(如 ilinkai.weixin.qq.com、liteapp.weixin.qq.com)", "file": "test/channels/weixin/weixin-controller.test.mjs", "line": 97 }, { "explanation": "访问第三方网络地址(如 mmg.whatsapp.net)", "file": "test/channels/whatsapp/whatsapp.test.mjs", "line": 226 }, { "explanation": "访问第三方网络地址(如 cdn.attacker.example、files.example、files.example.test、files.slack.com)", "file": "test/image-prompt.test.mjs", "line": 151 }, { "explanation": "访问第三方网络地址(如 private.example.invalid)", "file": "test/model-command.test.mjs", "line": 145 }, { "explanation": "访问第三方网络地址(如 badge.example)", "file": "test/random-badge-worker.test.mjs", "line": 35 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f7d2fe70472bed8c0e66aaad47631ab1fb137f2f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "toby-bridges/api-relay-audit", "name": "api-relay-audit", "author": "toby-bridges", "description": "Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.", "repo_url": "https://github.com/toby-bridges/api-relay-audit", "homepage": "https://toby-bridges.github.io/api-relay-audit/", "stars": 812, "forks": 78, "open_issues": 23, "watchers": 1, "pushed_at": "2026-08-27T16:43:59Z", "archived": false, "language": "Python", "license": "AGPL-3.0", "topics": [ "ai-agents", "ai-audit", "ai-security", "anthropic", "api-gateway", "claude", "dsh-plugin", "llm-audit", "llm-proxy", "llm-security", "model-substitution", "openai-api", "prompt-injection", "python", "security-audit", "security-scanner", "supply-chain-security", "tool-call-rewriting", "web3-security", "web3-wallet" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "Local security audit for AI API relays and LLM proxies." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 explicit.example、override.example、relay.example、relay.example.com)", "file": "dsh/test/plugin.test.js", "line": 57 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "00ce80208ea1178ac39116bf0843517a748e4dce", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "mrpulor-gh/nuphus-mcp", "name": "nuphus-mcp", "author": "mrpulor-gh", "description": "Desktop automation MCP server — computer use for any AI agent: control screen, windows, mouse/keyboard, and Chrome via Model Context Protocol (stdio)", "repo_url": "https://github.com/mrpulor-gh/nuphus-mcp", "homepage": "https://github.com/mrpulor-gh/nuphus-mcp", "stars": 267, "forks": 33, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-21T18:33:01Z", "archived": false, "language": "Rust", "license": "MIT", "topics": [ "ai-agent", "browser-automation", "chrome-automation", "computer-use", "computer-vision", "desktop-automation", "dsh-plugin", "mcp", "mcp-server", "model-context-protocol", "ocr", "rust" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "桌面自动化 MCP Server —— 为任意 AI 智能体提供\"计算机使用\"能力。看屏幕、控制窗口/键鼠、驱动 Chrome,经 Model Context Protocol(stdio)接入。", "en": "Desktop automation MCP server — computer use for any AI agent. See the screen, control windows/mouse/keyboard, and drive Chrome over the Model Context Protocol (stdio). Desktop & browser automation need no API key; OCR runs locally; vision plugs into your own" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9817ef74619235e710932e8d9d7a5ad68abb6891", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "d-dev0101/open-sea-skin", "name": "open-sea-skin", "author": "d-dev0101", "description": "WebGPU ocean skin for DeepSeek Harness — DSH plugin, Harness-only Chrome/Edge extension, static installer, and native integration.", "repo_url": "https://github.com/d-dev0101/open-sea-skin", "homepage": "https://d-dev0101.github.io/open-sea-skin/", "stars": 192, "forks": 4, "open_issues": 4, "watchers": 1, "pushed_at": "2026-08-24T13:59:05Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "chrome-extension", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "ocean-skin", "theme", "threejs", "webgpu" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 加上实时 WebGPU 海洋皮肤。保留五组 Gerstner 波与 TSL 海面视觉,增加半透明玻璃界面,并提供只作用于 Harness 的浏览器扩展、无需编译 的 dist 安装脚本、可一行安装的 DSH 插件,以及真正接入 Harness", "en": "A self-contained WebGPU ocean skin for DeepSeek Harness. It keeps the original five-wave Gerstner/TSL look, adds a translucent Harness theme, and is available as a one-line DSH plugin, Harness-only Chrome/Edge extension, one-command static" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "harness-plugin/src/client/OpenSeaQuickControls.tsx", "line": 55, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/capture-gallery.mjs", "line": 73, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "extension/vendor/addons/controls/OrbitControls.js", "line": 1, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 x)", "file": "harness-plugin/src/index.ts", "line": 56 }, { "explanation": "访问第三方网络地址(如 dsh.local)", "file": "plugin/index.js", "line": 39 }, { "explanation": "访问第三方网络地址(如 d-dev0101.github.io)", "file": "package.json", "line": 9 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/browser-acceptance.mjs", "line": 18 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 fixture)", "file": "scripts/browser-support.mjs", "line": 31 }, { "explanation": "访问第三方网络地址(如 fixture)", "file": "scripts/browser-support.mjs", "line": 63 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "extension/vendor/three.core.js", "line": 5 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "2437d80a96de4124c54fbe89872fa7090103f025", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "zh667/TokenLedger", "name": "TokenLedger", "author": "zh667", "description": "Relay-site attributed token usage for DeepSeek Harness — zero config, no credentials", "repo_url": "https://github.com/zh667/TokenLedger", "homepage": "https://www.npmjs.com/package/dsh-tokenledger", "stars": 177, "forks": 13, "open_issues": 3, "watchers": 2, "pushed_at": "2026-08-28T04:33:32Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "billing", "deepseek-harness", "dsh-plugin", "newapi", "sub2api", "token-usage" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "把 DeepSeek Harness 的 Token 用量算清楚,并归属到实际服务这次请求的中转站——不用配置,不用凭据。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 relay.example.com)", "file": "src/plugin.js", "line": 113 }, { "explanation": "访问第三方网络地址(如 api.relay-one.example、api.relay-two.example)", "file": "test/plugin.test.js", "line": 263 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "87b3d1806ac4d204a9195fc04ae8af6d6ebdd3ee", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "toolclub/dsh-agent-team-gui", "name": "dsh-agent-team-gui", "author": "toolclub", "description": "Persistent multi-model workflow teams for DeepSeek Harness — dynamic lead planning, bounded DAGs, per-agent model/tools, Run Center and Token insights.", "repo_url": "https://github.com/toolclub/dsh-agent-team-gui", "homepage": "https://github.com/toolclub/dsh-agent-team-gui#readme", "stars": 151, "forks": 2, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-24T06:30:56Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent", "agent-orchestration", "ai-agents", "dag", "deepseek-harness", "deepseek-harness-plugin", "dsh", "dsh-plugin", "dsh-plugins", "multi-agent", "multi-model", "orchestration", "react", "token-usage", "typescript", "workflow-engine" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 提供持久、可复用的多模型 Agent 小队。", "en": "Persistent, reusable multi-model Agent teams for DeepSeek Harness." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/quality/browser-smoke.mjs", "line": 600, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/quality/browser-smoke.mjs", "line": 614, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/quality/capture-readme.mjs", "line": 36, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/quality/capture-readme.mjs", "line": 45, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/quality/capture-readme.mjs", "line": 213, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/ComposerControl.tsx", "line": 129, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/SettingsPage.tsx", "line": 485, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/quality/browser-smoke.mjs", "line": 597 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "3b56aa4dbe20cc128d710928d20c80404ec7fff6", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "shanliuling/dsh-image-gen", "name": "dsh-image-gen", "author": "shanliuling", "description": "Generate images directly in DeepSeek Harness chats", "repo_url": "https://github.com/shanliuling/dsh-image-gen", "homepage": "https://github.com/shanliuling/dsh-image-gen#readme", "stars": 255, "forks": 16, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-27T09:47:35Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agent", "cordis", "deepseek", "deepseek-harness", "dsh-plugin", "gemini", "image-generation", "openai", "plugin", "seedream" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "让 DeepSeek Harness 像 ChatGPT 一样在对话中直接生成图片,支持画廊汇总,全屏预览、快捷复制与一键下载。", "en": "Bring ChatGPT-like image generation to DeepSeek Harness — supporting in-chat generation, gallery overview, fullscreen preview, quick copy, and one-click download." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "监听键盘输入事件", "file": "src/client/gallery-view.tsx", "line": 143, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/index.tsx", "line": 416, "confidence": 1 } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "57b0fdc4bf05ecaef9edc8e6d40bf286d074ca57", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "howmp/dsh-pentest", "name": "dsh-pentest", "author": "howmp", "description": "面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs", "repo_url": "https://github.com/howmp/dsh-pentest", "homepage": "https://github.com/howmp/dsh-pentest", "stars": 299, "forks": 37, "open_issues": 0, "watchers": 2, "pushed_at": "2026-08-24T04:12:22Z", "archived": false, "language": "JavaScript", "license": "unknown", "topics": [ "deepseek-harness", "dsh-plugin", "dsh-plugins", "pentest" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 的渗透测试模式:一条探索链路——goal → intent → fact → 派生 intent → finding—— 决策 agent(根 agent)把探索/执行委派给子 agent、把每个节点与边写进持久记录,并记录资产 (根域名 / 子域名 / IP / 服务 / App / 端点)及其父子关系。每个漏洞 finding 必须带可复现步骤。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "lib/pentest.js", "line": 1308, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/pentest.js", "line": 2666, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/pentest.js", "line": 2723, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 9 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 11 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 12 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 13 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 14 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/pentest.js", "line": 15 }, { "explanation": "存在 Base64 解码行为", "file": "packages/dsh-pentest/lib/index.js", "line": 1308, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/dsh-pentest/lib/index.js", "line": 2666, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/dsh-pentest/lib/index.js", "line": 2723, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 9 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 11 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 12 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 13 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 14 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "packages/dsh-pentest/lib/index.js", "line": 15 }, { "explanation": "访问第三方网络地址(如 json-schema.org)", "file": "lib/pentest.js", "line": 11700 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "src/dsh-pentest/tests/tools.spec.ts", "line": 41 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "6ec87675cc88b64547bb530274696e5df3b802cc", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "MeteorNOX/DeepSeek-Balance-Whale-Widget", "name": "DeepSeek-Balance-Whale-Widget", "author": "MeteorNOX", "description": "DeepSeek Harness(DSH)一只住在 DSH 界面右下角的小鲸鱼娘,帮你盯着DeepSeek账户余额。QQ弹弹,支持拖拽吸附、左吸附翻转、数字滚动动画,随界面自动启用,建议直接喊来你的dsh安装", "repo_url": "https://github.com/MeteorNOX/DeepSeek-Balance-Whale-Widget", "homepage": "https://github.com/MeteorNOX/DeepSeek-Balance-Whale-Widget", "stars": 1199, "forks": 46, "open_issues": 18, "watchers": 1, "pushed_at": "2026-08-24T17:14:19Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "cordis", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "dsh-plugins", "floating-widget", "plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "DeepSeek Harness(DSH)Web 界面右下角的常驻余额挂件:小鲸鱼气泡图 + DeepSeek API 余额 + 今日已用 + 每轮对话消耗统计,每次打开界面自动启用。本项目是标准 DSH 插件包,可通过 dsh plugin 安装/卸载。" }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/index.js", "line": 791 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 w3.org)", "file": "lib/index.js", "line": 12 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/index.js", "line": 58 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "732367798728e1e86e0cf1c4046e4f1b6e031d2c", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "amruthpillai/reactive-resume", "name": "reactive-resume", "author": "amruthpillai", "description": "A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!", "repo_url": "https://github.com/amruthpillai/reactive-resume", "homepage": "https://rxresu.me", "stars": 41854, "forks": 4671, "open_issues": 114, "watchers": 126, "pushed_at": "2026-08-27T16:24:43Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-skills", "ai", "dsh-plugin", "hacktoberfest", "javascript", "mcp-server", "react", "resume-builder", "self-hosted", "typescript" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 Cordis/DSH 落地标记(cordis.patch.yml/.dsh-plugin/dsh.client 等)", "description_i18n": { "en": "Reactive Resume stays free, open-source, and independent because companies choose to support the work behind it. Thank you to every sponsor who helps fund hosting, maintenance, and continued development for the community." }, "risk_level": "moderate", "risk_notes": [ "依赖 @orpc/server 与知名包 semver 名称高度相似(编辑距离 1),存在仿冒风险 @ package.json#1", "依赖 @codemirror/commands 与知名包 commander 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json#2", "依赖 @orpc/server 与知名包 semver 名称高度相似(编辑距离 1),存在仿冒风险 @ package.json#4", "依赖 @better-auth/oauth-provider@1.6.29 存在已知漏洞(GHSA-p2fr-6hmx-4528) @ " ], "risk_evidence": [ { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "apps/web/src/features/applications/components/insights-view.tsx", "line": 136 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "apps/web/src/features/applications/components/insights-view.tsx", "line": 210 }, { "explanation": "存在 Base64 解码行为", "file": "packages/api/src/features/ai/service.ts", "line": 429, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "packages/mcp/src/tool-meta.ts", "line": 59, "confidence": 1 }, { "explanation": "依赖 @better-auth/oauth-provider@1.6.29 存在已知漏洞(GHSA-p2fr-6hmx-4528)", "file": "" }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "apps/server/src/http/public-resume-pdf.test.ts", "line": 23 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "apps/server/src/index.ts", "line": 21 }, { "explanation": "访问第三方网络地址(如 docs.rxresu.me、rxresu.me)", "file": "apps/server/src/openapi/generator.test.ts", "line": 29 }, { "explanation": "访问第三方网络地址(如 example.com、rxresu.me、server.internal)", "file": "apps/server/src/static/web.test.ts", "line": 5 }, { "explanation": "访问第三方网络地址(如 schema.org)", "file": "apps/server/src/static/web.ts", "line": 104 }, { "explanation": "访问第三方网络地址(如 .)", "file": "apps/web/src/components/input/rich-input.tsx", "line": 325 }, { "explanation": "访问第三方网络地址(如 opencollective.com)", "file": "apps/web/src/components/ui/donation-toast.test.tsx", "line": 134 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "apps/web/src/features/applications/components/insights-view.tsx", "line": 205 }, { "explanation": "访问第三方网络地址(如 docs.rxresu.me)", "file": "apps/web/src/features/resume/stylesheet/editor.test.tsx", "line": 88 }, { "explanation": "访问第三方网络地址(如 api.openai.com)", "file": "apps/web/src/features/settings/integrations/components/ai-section.test.tsx", "line": 114 }, { "explanation": "访问第三方网络地址(如 gateway.example.com)", "file": "apps/web/src/features/settings/integrations/components/ai-section.tsx", "line": 578 }, { "explanation": "访问第三方网络地址(如 rxresu.me、schema.org)", "file": "apps/web/src/libs/seo.ts", "line": 1 }, { "explanation": "访问第三方网络地址(如 rxresu.me)", "file": "apps/web/src/routes/__root.tsx", "line": 54 }, { "explanation": "访问第三方网络地址(如 amruthpillai.com)", "file": "package.json", "line": 10 }, { "explanation": "访问第三方网络地址(如 api.openai.com、openai-compatible.example.com)", "file": "packages/api/src/features/agent/tools.test.ts", "line": 50 }, { "explanation": "访问第三方网络地址(如 example.test)", "file": "packages/api/src/features/ai/service.test.ts", "line": 54 }, { "explanation": "访问第三方网络地址(如 example.com、rxresu.me)", "file": "packages/mcp/src/mcp-server-card.test.ts", "line": 16 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "3221afda9ddfb03d6cce87927b0ce47338b4cfa8", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "awesome-dsh-plugin/awesome-dsh-plugin", "name": "awesome-dsh-plugin", "author": "awesome-dsh-plugin", "description": "A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表", "repo_url": "https://github.com/awesome-dsh-plugin/awesome-dsh-plugin", "homepage": "https://awesome-dsh-plugin.com", "stars": 13271, "forks": 2235, "open_issues": 363, "watchers": 33, "pushed_at": "2026-08-28T06:45:53Z", "archived": false, "language": "Python", "license": "CC0-1.0", "topics": [ "awesome", "awesome-list", "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "> DeepSeek Harness(dsh)插件精选列表。", "en": "> A curated list of plugins for DeepSeek Harness (dsh)." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "5909d7aad5a48e1eb3dc5d47d03cd705945d6706", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "0xsline/awesome-deepseek-harness", "name": "awesome-deepseek-harness", "author": "0xsline", "description": "DeepSeek Harness (DSH) ecosystem: curated plugins, tools, and infrastructure from dsh-external/hub and the public dsh-plugin topic.", "repo_url": "https://github.com/0xsline/awesome-deepseek-harness", "homepage": "https://deepseekdocs.com/", "stars": 925, "forks": 335, "open_issues": 6, "watchers": 7, "pushed_at": "2026-08-27T22:30:50Z", "archived": false, "language": "Python", "license": "CC0-1.0", "topics": [ "agent", "ai", "ai-agents", "ai-tools", "awesome", "awesome-list", "coding-assistant", "curated-list", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "dsh-plugins", "harness", "llm", "mcp", "plugins" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "安装     贡献指南     DeepSeek Docs    ", "en": "Install     Contribution guide     DeepSeek Docs    " }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "1ba172f4dc00c382914c411c52e94ff2bf29f2e1", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "sandbaseai/sandbase-harness", "name": "sandbase-harness", "author": "sandbaseai", "description": "Local-first AI agent runtime with sandboxed sessions, MCP tools, memory, credentials, audit/replay, and a built-in console. Run OpenAI, Anthropic, MiniMax, DeepSeek V4, and OpenAI-compatible models on your infrastructure.", "repo_url": "https://github.com/sandbaseai/sandbase-harness", "homepage": "https://github.com/sandbaseai/sandbase-harness/releases/latest", "stars": 635, "forks": 60, "open_issues": 3, "watchers": 22, "pushed_at": "2026-08-27T19:16:35Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "agent-framework", "agent-observability", "agent-plugins", "agent-runtime", "agent-sandbox", "ai-agents", "ai-infrastructure", "deepseek", "deepseek-harness", "deepseek-v4", "docker", "dsh", "dsh-plugin", "local-first", "mcp-server", "model-context-protocol", "openai-compatible", "sandbox", "self-hosted", "typescript" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "一个本地优先、可自托管的 AI Agent Runtime。它把持久化会话、沙箱工具、 Memory、凭证、审计日志、事件回放和可视化 Console 放在同一个运行时边界中, 并提供原生 DeepSeek Harness stdio MCP 插件。", "en": "A local-first runtime for AI agents. Sessions, sandboxed tools, memory, credentials, audit trails, and a built-in Console — all running on your machine or in your own infrastructure." }, "risk_level": "high", "risk_notes": [ "依赖 @hono/node-server@1.13.0 存在已知漏洞(GHSA-92pp-h63x-v22m, GHSA-frvp-7c67-39w9, GHSA-wc8c-qw6v-h7f6) @ ", "依赖 ai@4.0.0 存在已知漏洞(GHSA-rwvc-j5jr-mgvh) @ ", "依赖 hono@4.6.0 存在已知漏洞(GHSA-2234-fmw7-43wr, GHSA-26pp-8wgv-hjvm, GHSA-2gcr-mfcq-wcc3) @ ", "依赖 nanoid@5.0.0 存在已知漏洞(GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-mwcw-c2x4-8c55) @ ", "依赖 yaml@2.5.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ ", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ tests/unit/settings.test.ts" ], "risk_evidence": [ { "explanation": "依赖 @hono/node-server@1.13.0 存在已知漏洞(GHSA-92pp-h63x-v22m, GHSA-frvp-7c67-39w9, GHSA-wc8c-qw6v-h7f6)", "file": "" }, { "explanation": "依赖 ai@4.0.0 存在已知漏洞(GHSA-rwvc-j5jr-mgvh)", "file": "" }, { "explanation": "依赖 hono@4.6.0 存在已知漏洞(GHSA-2234-fmw7-43wr, GHSA-26pp-8wgv-hjvm, GHSA-2gcr-mfcq-wcc3)", "file": "" }, { "explanation": "依赖 nanoid@5.0.0 存在已知漏洞(GHSA-28wg-ghj8-5hjv, GHSA-2v37-7h3g-55p8, GHSA-mwcw-c2x4-8c55)", "file": "" }, { "explanation": "依赖 yaml@2.5.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "访问第三方网络地址(如 api.anthropic.com、api.minimax.io、api.openai.com)", "file": "apps/console/src/components/pages/settings/RuntimeSettingsEditorState.ts", "line": 88 }, { "explanation": "访问第三方网络地址(如 api.example.com、api.minimax.io)", "file": "apps/console/src/components/pages/settings/SettingsGeneral.tsx", "line": 98 }, { "explanation": "访问第三方网络地址(如 api.minimax.io、api.minimaxi.com、platform.minimax.io、platform.minimaxi.com)", "file": "src/core/model/minimax.ts", "line": 23 }, { "explanation": "访问第三方网络地址(如 s3.amazonaws.com)", "file": "src/core/settings/adapters.ts", "line": 75 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/core/settings/schema.ts", "line": 231 }, { "explanation": "访问第三方网络地址(如 mcp.example.com)", "file": "tests/integration/api.test.ts", "line": 232 }, { "explanation": "访问第三方网络地址(如 example.invalid)", "file": "tests/integration/console-api-e2e.test.ts", "line": 174 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "tests/unit/console-pages.test.ts", "line": 241 }, { "explanation": "访问第三方网络地址(如 agent-plugins.org)", "file": "tests/unit/mcp-distribution.test.ts", "line": 57 }, { "explanation": "访问第三方网络地址(如 api.minimax.io、api.openai.com、s3.amazonaws.com)", "file": "tests/unit/runtime-settings-forms.test.tsx", "line": 62 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "tests/unit/settings.test.ts" }, { "explanation": "访问第三方网络地址(如 mem0.example.test、models.example.test、worker.example.test)", "file": "tests/unit/settings.test.ts", "line": 163 }, { "explanation": "访问第三方网络地址(如 api.minimax.io、api.minimaxi.com)", "file": "tests/unit/v1-local-first-spec.test.ts", "line": 100 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "65ce225d01f56b5584d833af6b1afcc119dfd323", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "EthanYoQ/AI-Novel-Writer", "name": "AI-Novel-Writer", "author": "EthanYoQ", "description": "本地优先 AI 小说创作工作台,提供 Windows/macOS 桌面版与 DeepSeek Harness 插件开发预览,支持角色、大纲、章节蓝图、审稿修稿和本地模型。", "repo_url": "https://github.com/EthanYoQ/AI-Novel-Writer", "homepage": "https://github.com/EthanYoQ/AI-Novel-Writer", "stars": 475, "forks": 67, "open_issues": 11, "watchers": 2, "pushed_at": "2026-08-23T23:22:24Z", "archived": false, "language": "TypeScript", "license": "GPL-3.0", "topics": [ "ai-writing", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugins", "electron", "fiction-writing", "gemini", "local-first", "novel-writing", "ollama", "react", "typescript", "web-novel" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "中文 README 现为仓库默认入口:README.md。英文说明请见 README_en.md。", "en": "In addition to the Windows and macOS desktop editions, the plugin directory contains the @ethanyoq/dsh-ai-novel-writer 0.1.0 developer preview. It brings project settings, characters, story blueprints, chapter blueprints, and chapter drafts into DeepSeek" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "89682ef6b91683cedda24181ff172e5cd74e7f38", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "alibaba/anolisa", "name": "anolisa", "author": "alibaba", "description": "ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.", "repo_url": "https://github.com/alibaba/anolisa", "homepage": "https://agentic-os.sh/", "stars": 548, "forks": 102, "open_issues": 164, "watchers": 8, "pushed_at": "2026-08-28T06:41:45Z", "archived": false, "language": "Rust", "license": "Apache-2.0", "topics": [ "agent-infrastructure", "agent-memory", "agent-runtime", "agent-security", "agentic-ai", "agentic-os", "ai-agents", "context-engineering", "developer-tools", "dsh-plugin", "linux", "observability", "runtime-security", "rust", "sandbox", "skill", "token-optimization" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "Agent 入口 上下文效率 运行与安全", "en": "Agent entry Context efficiency Runtime & security" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#4", "依赖 openclaw@2026.4.14 存在已知漏洞(GHSA-24vr-rprv-67rf, GHSA-275c-xpvc-jgfw, GHSA-2hfg-4fh4-qp7f) @ " ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/agentsight/dashboard/src/i18n.tsx", "line": 2200, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "src/agentsight/dashboard/tests/run-api-client-regression.cjs", "line": 11, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "src/agentsight/dashboard/tests/run-api-client-regression.cjs", "line": 39, "confidence": 1 }, { "explanation": "依赖 openclaw@2026.4.14 存在已知漏洞(GHSA-24vr-rprv-67rf, GHSA-275c-xpvc-jgfw, GHSA-2hfg-4fh4-qp7f)", "file": "" }, { "explanation": "访问第三方网络地址(如 pypi.org)", "file": "src/agent-sec-core/Makefile", "line": 267 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/agent-sec-core/openclaw-plugin/src/utils.ts", "line": 12 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.com)", "file": "src/agent-sec-core/openclaw-plugin/tests/unit/observability-test.ts", "line": 180 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "src/agent-sec-core/openclaw-plugin/tests/unit/observability-test.ts", "line": 120 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/agentsight/dashboard/src/pages/AgentHealthPage.tsx", "line": 839 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8ba8709a98a57a658b0538469341c59080d3b744", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Lum1104/dsh-browser", "name": "dsh-browser", "author": "Lum1104", "description": "dsh plugin: Chrome sidebar extension that lets DeepSeek Harness operate your browser directly, no vision capabilities required. 一款 Chrome 侧边栏扩展程序,可让 DeepSeek Harness 直接操控您的浏览器,无需视觉能力。", "repo_url": "https://github.com/Lum1104/dsh-browser", "homepage": "https://github.com/Lum1104/dsh-browser", "stars": 491, "forks": 28, "open_issues": 1, "watchers": 2, "pushed_at": "2026-08-27T07:24:40Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "browser-automation", "chrome-extension", "coding-agent", "cordis", "deepseek", "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "把 DeepSeek Harness 连接到你正在使用的 Chrome 或 Firefox 标签页。模型可以读取页面内容、点击控件、填写表单、滚动与导航,同时保留登录态、会话和 Cookie。侧边栏提供对话界面。", "en": "Connect DeepSeek Harness to the Chrome or Firefox tab you are already using. The model can read page content, click controls, fill forms, scroll, and navigate while preserving your login state, session, and cookies. A side panel or sidebar provides the" }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "硬编码敏感凭据(疑似硬编码密钥)", "file": "benchmark/lib/extension-browser.mjs", "line": 64 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "benchmark/lib/chromium.mjs", "line": 20 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "eefd503da96097b41826943f49231f761e448e70", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "linhay/harmony-next.skills", "name": "harmony-next.skills", "author": "linhay", "description": "🚀 Expert guidance for HarmonyOS NEXT (API 12+) development. Covers IDE operations, performance tuning, architecture (HAP/HAR/HSP), and automation testing.", "repo_url": "https://github.com/linhay/harmony-next.skills", "homepage": "https://github.com/linhay/harmony-next.skills", "stars": 341, "forks": 25, "open_issues": 0, "watchers": 2, "pushed_at": "2026-08-18T08:05:29Z", "archived": false, "language": "Python", "license": "unknown", "topics": [ "arkts", "automation-testing", "deveco-studio", "dsh-plugin", "harmonyos", "harmonyos-next", "openharmony", "performance-tuning" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "给 Gemini CLI、Claude Code、Codex 等 AI 编程助手使用的 HarmonyOS NEXT 离线参考技能库。", "en": "An offline HarmonyOS NEXT reference skill library for AI coding assistants such as Gemini CLI, Claude Code, and Codex." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "880420ccaede758845daa3e86154c4e02e6f2249", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "ZJU-REAL/Polaris", "name": "Polaris", "author": "ZJU-REAL", "description": "Toward Autonomous Scientific Discovery", "repo_url": "https://github.com/ZJU-REAL/Polaris", "homepage": "https://zju-real.github.io/Polaris/", "stars": 213, "forks": 30, "open_issues": 24, "watchers": 1, "pushed_at": "2026-08-27T04:54:10Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "ai-agents", "ai-scientist", "auto-research", "dsh-plugin", "polaris-agent" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "一段 2 分钟的平台导览:六阶段流水线、Voyage 智能体内核、一次真实的实验运行,以及 PolarisBuddy。", "en": "A 2-minute tour of the platform: the six-stage pipeline, the Voyage agent core, a real experiment run, and PolarisBuddy." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json", "依赖 @codemirror/commands 与知名包 commander 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json#2" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f97a1b92aa78871542219bf829e8768ae6c8ec09", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "ZSeven-W/dsh-openpencil", "name": "dsh-openpencil", "author": "ZSeven-W", "description": "The DeepSeek Harness plugin for OpenPencil — preview, inspect, and edit real .op documents inside a conversation.", "repo_url": "https://github.com/ZSeven-W/dsh-openpencil", "homepage": "https://op.zseven.tech", "stars": 154, "forks": 6, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-26T15:33:14Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "design", "dsh", "dsh-plugin", "openpencil", "ppt", "ui", "ui-design" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH OpenPencil 将 DeepSeek Harness 与 OpenPencil 连接起来,让智能体(Agent)驱动一个真实、可编辑、可交互的设计画布,而不是返回一张生成的图片。", "en": "DSH OpenPencil connects DeepSeek Harness with OpenPencil so an Agent drives a real, editable, interactive design canvas instead of returning a generated image." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e3eb3bfdb5262db0659c3c6e567fe209199c3eb2", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "drewnekota/cetus", "name": "cetus", "author": "drewnekota", "description": "One macOS app for Claude Code, Codex, and every agent runtime you use — scheduled runs, global hotkey launcher, per-run git worktrees, one review board.", "repo_url": "https://github.com/drewnekota/cetus", "homepage": "https://github.com/drewnekota/cetus", "stars": 138, "forks": 11, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-27T03:27:48Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agent", "automation", "claude-code", "codex", "computer-use", "deepseek-harness", "desktop-agent", "dsh", "dsh-plugin", "local-first", "macos", "rust", "tauri" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/dsh-host-apiproxy", "risk_level": "moderate", "risk_notes": [ "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json#4", "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json#5", "依赖 next@16.2.6 存在已知漏洞(GHSA-4633-3j49-mh5q, GHSA-4c39-4ccg-62r3, GHSA-68g3-v927-f742) @ ", "依赖 xlsx@0.18.5 存在已知漏洞(GHSA-4r6h-8v6p-xvw6, GHSA-5pgg-2g8v-p4x9) @ " ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/components/chat/artifact-view.tsx", "line": 503, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/components/chat/artifact-view.tsx", "line": 767, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/components/chat/chat-pane.tsx", "line": 800, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/components/chat/chat-pane.tsx", "line": 936, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/components/chat/chat-pane.tsx", "line": 1467, "confidence": 1 }, { "explanation": "依赖 next@16.2.6 存在已知漏洞(GHSA-4633-3j49-mh5q, GHSA-4c39-4ccg-62r3, GHSA-68g3-v927-f742)", "file": "" }, { "explanation": "依赖 xlsx@0.18.5 存在已知漏洞(GHSA-4r6h-8v6p-xvw6, GHSA-5pgg-2g8v-p4x9)", "file": "" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "29fc65c9669109e8bed62ec33354bbc692aaed73", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "taxueseek/argo", "name": "argo", "author": "taxueseek", "description": "专门为 agent 打造的 agent 搜索工具,具备多语言搜索能力,覆盖中文/英文/学术/代码/购物/金融/新闻/百科。", "repo_url": "https://github.com/taxueseek/argo", "homepage": "https://github.com/taxueseek/argo", "stars": 111, "forks": 9, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-27T14:02:12Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "dsh-ecosystem", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> 简单来说:前三种方案解决「人找信息」,Argo 解决「Agent 及搜索核查于一身,具备一条龙的搜索服务」。差别不在界面,在交付物,给人看的叫总结页或链接清单,给 Agent 的应是能排序、能复核、不撑爆上下文的优质内容,更可靠的搜索信息。", "en": "Argo is multilingual search infrastructure for AI agents." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "bin/argo.js", "line": 11 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "49f8a80302b17bae970851979a57e79ad7bae3e0", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "kelai141/dsh-mobile-apk", "name": "dsh-mobile-apk", "author": "kelai141", "description": "dsh 安卓壳 APK——WebView UI + 内嵌 Termux 运行时快照(解压即跑)、SAF 目录桥、保活服务、看门狗、运行时在线更新。", "repo_url": "https://github.com/kelai141/dsh-mobile-apk", "homepage": "https://github.com/kelai141/dsh-mobile-apk", "stars": 258, "forks": 25, "open_issues": 9, "watchers": 1, "pushed_at": "2026-08-28T05:56:10Z", "archived": false, "language": "Kotlin", "license": "MIT", "topics": [ "android", "dsh-plugin", "kotlin", "termux", "webview" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码 app/src/main/assets/patched/attachment-local-index.js import/引用 DSH 或 Cordis 模块", "description_i18n": { "zh": "> dsh-mobile 生态 · dsh-shell-termux(shell)· dsh-client-ui-responsive(移动 UI)· dsh-host-web-compat(浏览器兼容)· dsh-mobile(协调仓库,private)", "en": "> dsh-mobile 生态 · dsh-shell-termux(shell)· dsh-client-ui-responsive(移动 UI)· dsh-host-web-compat(浏览器兼容)" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "app/src/main/assets/patched/session-persistence-jsonl-index.js", "line": 91 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "app/src/main/assets/patched/session-persistence-jsonl-index.js", "line": 112 } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f7ed7e9cb69fcd0002f16e2507c3edc267c74825", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Fishquito7/dsh-skill-mcp-panel", "name": "dsh-skill-mcp-panel", "author": "Fishquito7", "description": "DSH Web UI plugin: skill and MCP management(Web界面的skill/MCP管理工具)", "repo_url": "https://github.com/Fishquito7/dsh-skill-mcp-panel", "homepage": "https://github.com/Fishquito7/dsh-skill-mcp-panel", "stars": 107, "forks": 11, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-18T05:43:14Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek", "dsh", "dsh-plugin", "mcp", "plugin", "skills" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH 插件,在 Web 设置页同时提供「技能」与「MCP」两个管理面板,并随包提供统一终端命令 dsh-panel(skill / mcp 两个子命令族)。", "en": "A DSH plugin for managing skills right from the web UI and terminal" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json", "依赖 @modelcontextprotocol/sdk@1.12.0 存在已知漏洞(GHSA-345p-7cg4-v4c7, GHSA-8r9q-7v3j-jr4g, GHSA-w48q-cv73-mx4w) @ " ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "lib/client.js", "line": 61 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "lib/client.js", "line": 62 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "lib/client.js", "line": 1169 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 780, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/client.ts", "line": 62 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/client.ts", "line": 63 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/client.ts", "line": 1173 }, { "explanation": "存在 Base64 解码行为", "file": "src/index.ts", "line": 802, "confidence": 1 }, { "explanation": "依赖 @modelcontextprotocol/sdk@1.12.0 存在已知漏洞(GHSA-345p-7cg4-v4c7, GHSA-8r9q-7v3j-jr4g, GHSA-w48q-cv73-mx4w)", "file": "" }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/client.js", "line": 63 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 309 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "5fa5d87c68ad34337e073f82dc50767ed690eb27", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "volcengine/OpenViking", "name": "OpenViking", "author": "volcengine", "description": "Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.", "repo_url": "https://github.com/volcengine/OpenViking", "homepage": "https://openviking.ai/", "stars": 33981, "forks": 2578, "open_issues": 539, "watchers": 93, "pushed_at": "2026-08-28T06:27:36Z", "archived": false, "language": "Python", "license": "AGPL-3.0", "topics": [ "agent-memory", "agent-plugins", "agentic-rag", "context-database", "dsh-plugin", "self-evolving" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "👋 加入我们的社区", "en": "👋 Join our Community" }, "risk_level": "moderate", "risk_notes": [ "依赖 @whiskeysockets/baileys@7.0.0-rc.9 存在已知漏洞(GHSA-qvv5-jq5g-4cgg) @ ", "依赖 ws@8.17.1 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p) @ " ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "examples/codex-memory-plugin/scripts/marketplace.test.mjs", "line": 170, "confidence": 1 }, { "explanation": "依赖 @whiskeysockets/baileys@7.0.0-rc.9 存在已知漏洞(GHSA-qvv5-jq5g-4cgg)", "file": "" }, { "explanation": "依赖 ws@8.17.1 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p)", "file": "" }, { "explanation": "访问第三方网络地址(如 agent-plugins.org)", "file": "agent-plugins/plugin.test.mjs", "line": 6 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "agent-plugins/servers/shared/mcp-proxy-config.mjs", "line": 35 }, { "explanation": "访问第三方网络地址(如 openviking.ai)", "file": "docs/.vitepress/config.ts", "line": 8 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 compressor.example)", "file": "examples/codex-memory-plugin/scripts/auto-recall.test.mjs", "line": 84 }, { "explanation": "访问第三方网络地址(如 compressor.example)", "file": "examples/codex-memory-plugin/scripts/auto-recall.test.mjs", "line": 76 }, { "explanation": "访问第三方网络地址(如 ov.example.com)", "file": "examples/dsh-memory-plugin/mcp.test.mjs", "line": 11 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.vikingdb.cn-beijing.volces.com、example.com、third-party.example)", "file": "examples/memory-plugin-shared/install-agent-hooks.test.mjs", "line": 21 }, { "explanation": "访问第三方网络地址(如 api.vikingdb.cn-beijing.volces.com、example.com、third-party.example)", "file": "examples/memory-plugin-shared/install-agent-hooks.test.mjs", "line": 35 }, { "explanation": "访问第三方网络地址(如 x、y)", "file": "examples/memory-plugin-shared/mcp-proxy-config.test.mjs", "line": 17 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "6e944cc3e14872ec7e7a80edec9265397f367894", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "anywhere-labs/deepseek-harness-desktop", "name": "deepseek-harness-desktop", "author": "anywhere-labs", "description": "为 DeepSeek Harness (DSH) 插件生态打造的现代化桌面端解决方案。万物皆「插件」,桌面本身也是「插件」。", "repo_url": "https://github.com/anywhere-labs/deepseek-harness-desktop", "homepage": "https://dshdesktop.cn", "stars": 21324, "forks": 1036, "open_issues": 253, "watchers": 50, "pushed_at": "2026-08-28T04:30:09Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "cordis", "cordis-plugin", "deepseek", "deepseek-harness", "desktop", "dsh", "dsh-plugin", "dsh-plugin-desktop" ], "category": "plugin", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "description_i18n": { "zh": "这是旧链接的兼容入口。当前中文产品 README 是 README.md,完整文档索引在 docs/README.md。", "en": "Current release installers support Windows x64 and macOS Universal. No extra environment is needed — download, install, and start using it with one click." }, "risk_level": "high", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#3", "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c) @ ", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ dsh-plugin-desktop/scripts/release-preflight.ts" ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "dsh-community-fabric/scripts/verify-docs.mjs", "line": 133, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "dsh-community-market/scripts/verify-docs.mjs", "line": 97, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "dsh-community-market/src/client/MarketOverlay.tsx", "line": 28, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "dsh-community-market/src/install/service.ts", "line": 208, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "dsh-plugin-desktop/scripts/release-preflight.ts", "line": 56, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "dsh-plugin-desktop/src/native-ui/recovery/App.tsx", "line": 275, "confidence": 1 }, { "explanation": "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c)", "file": "" }, { "explanation": "访问第三方网络地址(如 catalog.example、json-schema.org、plugins.example.org、user)", "file": "dsh-community-market/scripts/verify-docs.mjs", "line": 126 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com)", "file": "dsh-community-market/src/adapters/dsh-1024store.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 api.dshfind.com)", "file": "dsh-community-market/src/adapters/dshfind.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、dshfind.com)", "file": "dsh-community-market/src/catalog/service.ts", "line": 36 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "dsh-community-market/src/client/locales.ts", "line": 135 }, { "explanation": "访问第三方网络地址(如 plugins.example.org)", "file": "dsh-community-market/tests/client-api.spec.ts", "line": 254 }, { "explanation": "访问第三方网络地址(如 api.deepseek1024.com、plugins.example.org)", "file": "dsh-community-market/tests/client-overlay.spec.tsx", "line": 114 }, { "explanation": "访问第三方网络地址(如 other.example、plugins.example.org)", "file": "dsh-community-market/tests/contracts.spec.ts", "line": 149 }, { "explanation": "访问第三方网络地址(如 api.dshfind.com、attacker.example)", "file": "dsh-community-market/tests/dshfind-adapter.spec.ts", "line": 29 }, { "explanation": "访问第三方网络地址(如 attacker.example、plugins.example.org)", "file": "dsh-community-market/tests/host-routes.spec.ts", "line": 93 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、gitlab.example、user)", "file": "dsh-community-market/tests/install-target-adapter.spec.ts", "line": 24 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、evil.example)", "file": "dsh-community-market/tests/market-install.spec.ts", "line": 27 }, { "explanation": "访问第三方网络地址(如 attacker.example、catalog.example、deepseek1024.com、deepseek1024.com.attacker.example)", "file": "dsh-community-market/tests/market-runtime.spec.ts", "line": 61 }, { "explanation": "访问第三方网络地址(如 catalog.example、fixture-home.example、safe.example、second.example)", "file": "dsh-community-market/tests/market-settings-tab.spec.tsx", "line": 70 }, { "explanation": "访问第三方网络地址(如 github.com.attacker.example、tracker.example、user)", "file": "dsh-community-market/tests/media-service.spec.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 cdn.plugins.example.org、plugins.example.org)", "file": "dsh-community-market/tests/standard-http.spec.ts", "line": 22 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "dsh-plugin-desktop/scripts/package-mac.ts", "line": 67 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "dsh-plugin-desktop/scripts/release-preflight.ts" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 electronjs.org)", "file": "dsh-plugin-desktop/scripts/verify-cli-runtime.mjs", "line": 29 }, { "explanation": "访问第三方网络地址(如 electronjs.org)", "file": "dsh-plugin-desktop/scripts/verify-cli-runtime.mjs", "line": 125 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "6201080cfaa2f9b0864333e9da695cde71d3f1e1", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "tt-a1i/archify", "name": "archify", "author": "tt-a1i", "description": "Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.", "repo_url": "https://github.com/tt-a1i/archify", "homepage": "https://tt-a1i.github.io/archify/", "stars": 24585, "forks": 1572, "open_issues": 46, "watchers": 99, "pushed_at": "2026-08-28T06:02:22Z", "archived": false, "language": "HTML", "license": "MIT", "topics": [ "agent-skills", "architecture-as-code", "architecture-diagram", "claude-skill", "code-visualization", "codex", "coding-agents", "data-flow-diagram", "deepseek-harness", "developer-tools", "diagram-as-code", "diagrams", "diagrams-as-code", "dsh-plugin", "mermaid-alternative", "opencode", "sequence-diagram", "software-architecture", "system-design", "text-to-diagram" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "在对话里,把代码仓库或系统描述变成漂亮、可靠、可交互的系统地图。", "en": "Turn a codebase or system description into a polished, interactive system map — directly in chat." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "archify/bin/visual-check.mjs", "line": 453, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "archify/delta/architecture-delta.mjs", "line": 1088, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "archify/delta/architecture-delta.mjs", "line": 1101, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "archify/delta/architecture-delta.mjs", "line": 1127, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "archify/renderers/shared/generated-brand-marks.mjs", "line": 162 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "archify/renderers/shared/generated-brand-marks.mjs", "line": 253 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "archify/renderers/shared/generated-brand-marks.mjs", "line": 491 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "archify/renderers/shared/generated-brand-marks.mjs", "line": 1674 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "archify/renderers/shared/generated-validators.mjs", "line": 13 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "archify/renderers/shared/utils.mjs", "line": 179 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/automatic-port-spread.test.mjs", "line": 18, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "archify/test/brand-marks.test.mjs", "line": 238, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "archify/test/brand-marks.test.mjs", "line": 278, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "archify/test/brand-marks.test.mjs", "line": 310, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/desktop-reader-browser.test.mjs", "line": 22, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/intent-trace.test.mjs", "line": 23, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/layout-rules.test.mjs", "line": 43, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/layout-rules.test.mjs", "line": 58, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/real-repository-proof.test.mjs", "line": 66, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/real-repository-proof.test.mjs", "line": 72, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/render-output-checks.test.mjs", "line": 18, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/route-share-card.test.mjs", "line": 24, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/semantic-passport.test.mjs", "line": 23, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/semantic-radar.test.mjs", "line": 26, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/semantic-radar.test.mjs", "line": 218, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/semantic-radar.test.mjs", "line": 246, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/v1-compatibility.test.mjs", "line": 18, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/v1-compatibility.test.mjs", "line": 33, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/v1-compatibility.test.mjs", "line": 47, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/viewer-chrome-layout.test.mjs", "line": 26, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/viewer-chrome-layout.test.mjs", "line": 173, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "archify/test/viewer-chrome-layout.test.mjs", "line": 227, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "archify/bin/archify.mjs", "line": 54 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "archify/delta/architecture-delta.mjs", "line": 933 }, { "explanation": "访问第三方网络地址(如 about.gitlab.com、about.meta.com、about.x.com、airtable.com)", "file": "archify/renderers/shared/generated-brand-marks.mjs", "line": 18 }, { "explanation": "访问第三方网络地址(如 github、json-schema.org)", "file": "archify/renderers/shared/generated-validators.mjs", "line": 2 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 brand.example.invalid、user、w3.org)", "file": "archify/test/brand-marks.test.mjs", "line": 44 }, { "explanation": "访问第三方网络地址(如 brand.example.invalid、user、w3.org)", "file": "archify/test/brand-marks.test.mjs", "line": 214 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 w3.org)", "file": "archify/test/viewer-chrome-layout.test.mjs", "line": 14 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "95e8a3a9d50136bc34e1093edbca7d4a52e974aa", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "EverMind-AI/EverOS", "name": "EverOS", "author": "EverMind-AI", "description": "One portable memory layer for every AI agent: local-first, Markdown-native, user-owned, and self-evolving across apps, tools, and workflows.", "repo_url": "https://github.com/EverMind-AI/EverOS", "homepage": "https://evermind.ai/everos", "stars": 12498, "forks": 905, "open_issues": 76, "watchers": 109, "pushed_at": "2026-08-28T06:45:52Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "agent-memory", "agentic-ai", "ai", "chats", "clawdbot", "clawdbot-skill", "deepseek-harness", "dsh", "dsh-plugin", "llm", "long-term-memory", "mcp", "memory", "memory-management", "python3", "rag", "skills" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "EverOS 是面向 agents 和 makers 的 Python library 与 local-first memory runtime。它从 day one 开始就提供一层可携带的记忆层,让记忆穿过 coding assistants、apps、devices 和 workflows。它会把 conversations、files 和", "en": "EverOS is a Python library and local-first memory runtime for agents and makers. It gives one portable memory layer across coding assistants, apps, devices, and workflows from day one. It stores conversations, files, and agent" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#1", "依赖 express@4.18.2 存在已知漏洞(GHSA-qw6h-vgh9-j6wx, GHSA-rv95-896h-c2vc) @ ", "读取本地环境配置文件(dotenv .env) @ use-cases/claude-code-plugin/hooks/scripts/session-context.js" ], "risk_evidence": [ { "explanation": "依赖 express@4.18.2 存在已知漏洞(GHSA-qw6h-vgh9-j6wx, GHSA-rv95-896h-c2vc)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "examples/dsh/src/identity.ts", "line": 63 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "use-cases/claude-code-plugin/hooks/scripts/session-context.js" }, { "explanation": "访问第三方网络地址(如 api.evermind.ai)", "file": "use-cases/claude-code-plugin/hooks/scripts/utils/config.js", "line": 30 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d07cddc403049464aa0cd48bb3b8233d68e41af4", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "MemTensor/MemOS", "name": "MemOS", "author": "MemTensor", "description": "Self-evolving memory OS for LLM & AI Agents: ultra-persistent memory, hybrid-retrieval, and cross-task skill reuse, with 35.24% token savings and DeepSeek Harness support.", "repo_url": "https://github.com/MemTensor/MemOS", "homepage": "https://memos.openmem.net", "stars": 11059, "forks": 1009, "open_issues": 55, "watchers": 48, "pushed_at": "2026-08-28T06:41:28Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "agent", "agentic-ai", "ai", "ai-agents", "chatgpt", "claude", "deepseek-harness", "dsh-plugin", "hermes", "llm", "long-term-memory", "mcp", "memory", "memory-management", "openclaw", "rag", "self-evolving", "self-hosted", "skills", "token-savings" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "MemOS 是一个面向 LLM 与 AI Agent 的记忆操作系统,统一了长期记忆的存/取/管,内置 KB、多模态、工具记忆 与 企业级 优化,实现上下文感知与个性化的交互。", "en": "MemOS is a Memory Operating System for LLMs and AI agents that unifies store / retrieve / manage for long-term memory, enabling context-aware and personalized interactions with KB, multi-modal, tool memory, and enterprise-grade optimizations built in." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2", "依赖 preact 与知名包 react 名称高度相似(编辑距离 1),存在仿冒风险 @ package.json#2", "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#3", "依赖 @accomplish/shared 与知名包 sharp 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json#3", "依赖 uuid@10.0.0 存在已知漏洞(GHSA-w5hq-g745-h8pq) @ ", "依赖 yaml@2.6.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ ", "依赖 @modelcontextprotocol/sdk@1.0.0 存在已知漏洞(GHSA-w48q-cv73-mx4w) @ " ], "risk_evidence": [ { "explanation": "依赖 uuid@10.0.0 存在已知漏洞(GHSA-w5hq-g745-h8pq)", "file": "" }, { "explanation": "依赖 yaml@2.6.0 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "依赖 @modelcontextprotocol/sdk@1.0.0 存在已知漏洞(GHSA-w48q-cv73-mx4w)", "file": "" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "be68e2fb5370866bd5e2b188bb3d22bd13b49e09", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "crafter-station/petdex", "name": "petdex", "author": "crafter-station", "description": "A public gallery of animated pets for Codex, Claude Code, DeepSeek Harness, Hermes, OpenCode, Gemini CLI, and more.", "repo_url": "https://github.com/crafter-station/petdex", "homepage": "https://petdex.dev", "stars": 3985, "forks": 190, "open_issues": 26, "watchers": 10, "pushed_at": "2026-08-26T04:16:02Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "claude-code", "clerk", "cli", "codex", "developer-tools", "drizzle-orm", "dsh-plugin", "mascot", "neon", "nextjs", "pixel-art", "postgres", "react", "sprites", "tailwindcss", "vercel" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "Petdex is three things working together:" }, "risk_level": "high", "risk_notes": [ "依赖 postcss@8.5.13 存在已知漏洞(GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849) @ ", "依赖 sharp@0.34.5 存在已知漏洞(GHSA-f88m-g3jw-g9cj) @ ", "读取本地环境配置文件(dotenv .env) @ package.json", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/publish-pet-sticker-artifacts.ts", "访问第三方网络地址(如 petdex.dev、schema.org) @ src/app/[locale]/pets/[slug]/page.tsx:41", "访问第三方网络地址(如 petdex.dev、schema.org、x.com) @ src/app/[locale]/u/[handle]/page.tsx:38", "访问第三方网络地址(如 petdex.local) @ src/app/api/pets/[slug]/sticker/route.test.ts:30" ], "risk_evidence": [ { "explanation": "依赖 postcss@8.5.13 存在已知漏洞(GHSA-fxqj-rqcc-2cmp, GHSA-r28c-9q8g-f849)", "file": "" }, { "explanation": "依赖 sharp@0.34.5 存在已知漏洞(GHSA-f88m-g3jw-g9cj)", "file": "" }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "package.json" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/apply-sticker-exports.ts", "line": 8 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/publish-pet-sticker-artifacts.ts" }, { "explanation": "访问第三方网络地址(如 api.cloudflare.com、petdex.dev)", "file": "scripts/publish-pet-sticker-artifacts.ts", "line": 716 }, { "explanation": "访问第三方网络地址(如 petdex.dev、schema.org)", "file": "src/app/[locale]/pets/[slug]/page.tsx", "line": 41 }, { "explanation": "访问第三方网络地址(如 petdex.dev、schema.org、x.com)", "file": "src/app/[locale]/u/[handle]/page.tsx", "line": 38 }, { "explanation": "访问第三方网络地址(如 petdex.local)", "file": "src/app/api/pets/[slug]/sticker/route.test.ts", "line": 30 }, { "explanation": "访问第三方网络地址(如 pub-94495283df974cfea5e98d6a9e3fa462.r2.dev、w3.org)", "file": "src/lib/mock/db.ts", "line": 36 }, { "explanation": "访问第三方网络地址(如 petdex.dev)", "file": "src/lib/pet-public-artifact-keys.test.ts", "line": 45 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 admin.petdex.dev、petdex.dev)", "file": "src/proxy.ts", "line": 35 }, { "explanation": "访问第三方网络地址(如 admin.petdex.dev、petdex.dev)", "file": "src/proxy.ts", "line": 38 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c7fbe8a9c9c45900e98dacfaad4f41627e2c760a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "chuspeeism/dashi-taskboard", "name": "dashi-taskboard", "author": "chuspeeism", "description": "", "repo_url": "https://github.com/chuspeeism/dashi-taskboard", "homepage": "https://github.com/chuspeeism/dashi-taskboard", "stars": 2714, "forks": 378, "open_issues": 26, "watchers": 13, "pushed_at": "2026-08-28T04:39:39Z", "archived": false, "language": "JavaScript", "license": "Apache-2.0", "topics": [ "claude-code", "cli", "codex", "codex-app", "codex-desktop", "codex-plugin", "dsh", "dsh-plugin", "skills" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "一个本地优先的议题面板,可在浏览器中运行,也可通过独立 CDP 启动器或其注入脚本嵌入 Codex。同一套 HTTP API 为 React UI 和随附 Codex Skill 使用的 taskctl CLI 提供支持。", "en": "A local-first issue board that runs in a browser and can be embedded in Codex through the standalone CDP launcher or its injection script. The same HTTP API powers the React UI and the taskctl CLI used by the bundled Codex Skill." }, "risk_level": "high", "risk_notes": [ "依赖 js-yaml@4.1.1 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68) @ ", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/codex-injector.mjs", "读取本地环境配置文件(dotenv .env) @ test/injector.test.mjs" ], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "cloud/src/index.mjs", "line": 355, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/codex-injector.mjs", "line": 1926, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "server/app.mjs", "line": 915, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/App.tsx", "line": 1562, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/App.tsx", "line": 1579, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/App.tsx", "line": 2074, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "web/src/components/AiChat.tsx", "line": 315, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/AiChat.tsx", "line": 1758, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "web/src/components/AiChat.tsx", "line": 318 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "web/src/components/AiChat.tsx", "line": 333 }, { "explanation": "存在 Base64 解码行为", "file": "web/src/components/InlineMediaComposer.tsx", "line": 236, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "web/src/components/InlineMediaComposer.tsx", "line": 286, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "web/src/components/InlineMediaComposer.tsx", "line": 226 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/LabelPicker.tsx", "line": 75, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/ProjectAutomationMenu.tsx", "line": 139, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/TaskConversationMenu.tsx", "line": 80, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/TaskDetail.tsx", "line": 534, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/TaskDetail.tsx", "line": 548, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/TaskFilterMenu.tsx", "line": 240, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "web/src/components/TaskPropertyPicker.tsx", "line": 145, "confidence": 1 }, { "explanation": "依赖 js-yaml@4.1.1 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "cli/taskctl.mjs", "line": 220 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/codex-injector.mjs" }, { "explanation": "访问第三方网络地址(如 taskboard.local)", "file": "test/board-interactions.test.mjs", "line": 101 }, { "explanation": "访问第三方网络地址(如 legacy.example.test、tasks.example.test)", "file": "test/cloud-companion.test.mjs", "line": 63 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 taskboard.example.test)", "file": "test/cloud-migration.test.mjs", "line": 1142 }, { "explanation": "访问第三方网络地址(如 taskboard.example.test)", "file": "test/cloud-migration.test.mjs", "line": 1177 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "test/injector.test.mjs" }, { "explanation": "访问第三方网络地址(如 evil.example、example.com)", "file": "test/server.test.mjs", "line": 28 }, { "explanation": "访问第三方网络地址(如 developers.openai.com)", "file": "web/src/components/AiChat.tsx", "line": 3281 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "a869a2e26a2cdd9167c98e69955209c0d1d4a0ca", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "GCWing/BitFun", "name": "BitFun", "author": "GCWing", "description": "BitFun combines a high-performance agent runtime written in Rust with a polished desktop application. It pairs the depth of a Code Agent with open, general-purpose capabilities for work beyond software development.", "repo_url": "https://github.com/GCWing/BitFun", "homepage": "https://github.com/GCWing/BitFun", "stars": 1828, "forks": 202, "open_issues": 141, "watchers": 7, "pushed_at": "2026-08-28T06:34:14Z", "archived": false, "language": "Rust", "license": "MIT", "topics": [ "agent-teams", "agentic", "agentic-os", "agentic-runtime", "ai-coding", "ai-ide", "ai-sdk", "bitfun", "computer-use-agent", "cowork", "dsh-plugin", "openclaw", "vibe-coding" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/dsh-agent-spine-demo", "description_i18n": { "zh": "能写代码、能做文档、能操控桌面,并提供小应用、Rust Runtime 和可自部署的多设备互控服务器。", "en": "Writes code, produces documents, and drives the desktop — with Mini Apps, a Rust runtime, and a self-hostable device-sync server." }, "risk_level": "high", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "依赖 pnpm@10.32.1 存在已知漏洞(GHSA-3qhv-2rgh-x77r, GHSA-4gxm-v5v7-fqc4, GHSA-54hh-g5mx-jqcp) @ ", "依赖 simple-git@3.27.0 存在已知漏洞(GHSA-hffm-xvc3-vprc, GHSA-jcxm-m3jx-f287, GHSA-r275-fr43-pm7q) @ ", "读取本地环境配置文件(dotenv .env) @ packages/dsh-acp/scripts/smoke.mjs", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ src/apps/extension-host/test/gateway.test.ts", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ src/apps/miniapp-market-server/Dockerfile" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "package.json", "line": 146 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/cargo-target-gc.mjs", "line": 301, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/cargo-target-gc.mjs", "line": 308, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-build-prereqs.mjs", "line": 140, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-build-prereqs.mjs", "line": 146, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/check-github-config.test.mjs", "line": 626, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/apps/extension-host/src/streams.ts", "line": 148, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/apps/extension-host/test/gateway.test.ts", "line": 356, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/apps/extension-host/test/rpc.test.ts", "line": 223, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/apps/extension-host/test/rpc.test.ts", "line": 224, "confidence": 1 }, { "explanation": "依赖 pnpm@10.32.1 存在已知漏洞(GHSA-3qhv-2rgh-x77r, GHSA-4gxm-v5v7-fqc4, GHSA-54hh-g5mx-jqcp)", "file": "" }, { "explanation": "依赖 simple-git@3.27.0 存在已知漏洞(GHSA-hffm-xvc3-vprc, GHSA-jcxm-m3jx-f287, GHSA-r275-fr43-pm7q)", "file": "" }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "packages/dsh-acp/scripts/smoke.mjs" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/cargo-target-gc.mjs", "line": 404 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 openbitfun.com)", "file": "scripts/check-github-config.test.mjs", "line": 43 }, { "explanation": "访问第三方网络地址(如 openbitfun.com)", "file": "scripts/check-github-config.test.mjs", "line": 672 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "scripts/core-boundaries/self-test.mjs", "line": 3354 }, { "explanation": "访问第三方网络地址(如 json.schemastore.org)", "file": "src/apps/extension-host/package.json", "line": 2 }, { "explanation": "访问第三方网络地址(如 json-schema.org、opencode.ai)", "file": "src/apps/extension-host/script/generate-protocol.ts", "line": 24 }, { "explanation": "访问第三方网络地址(如 workspace.example.test)", "file": "src/apps/extension-host/test/fixtures/gateway/injected.ts", "line": 22 }, { "explanation": "访问第三方网络地址(如 auth.example、workspace.example)", "file": "src/apps/extension-host/test/fixtures/runtime/full.js", "line": 30 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "src/apps/extension-host/test/gateway.test.ts" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.example、auth.example、workspace.example)", "file": "src/apps/extension-host/test/host.test.ts", "line": 644 }, { "explanation": "访问第三方网络地址(如 api.example、auth.example、workspace.example)", "file": "src/apps/extension-host/test/host.test.ts", "line": 308 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.com)", "file": "src/apps/extension-host/test/loader.test.ts", "line": 423 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "src/apps/extension-host/test/loader.test.ts", "line": 282 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "src/apps/miniapp-market-server/Dockerfile" } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "41f4af303910b45f488bc78944ce91c452a273ee", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Tencent/BrowserSkill", "name": "BrowserSkill", "author": "Tencent", "description": "Let AI agents use your real, logged-in browser without interrupting your work. CLI + extension for browser automation across any shell-capable AI agent.", "repo_url": "https://github.com/Tencent/BrowserSkill", "homepage": "https://github.com/Tencent/BrowserSkill", "stars": 1427, "forks": 112, "open_issues": 39, "watchers": 7, "pushed_at": "2026-08-28T06:31:30Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent", "browser-use", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "让 AI Agent 操作你的浏览器,而不打断你的工作。", "en": "Let AI agents use your browser without interrupting your work." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2" ], "risk_evidence": [ { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/__tests__/observation.test.ts", "line": 108, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/__tests__/observation.test.ts", "line": 126, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/__tests__/observation.test.ts", "line": 143, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/dispatcher.ts", "line": 329, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "apps/extension/src/tools/observation.ts", "line": 109, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/observation.ts", "line": 170, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/observation.ts", "line": 276, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/extension/src/tools/observation.ts", "line": 318, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "packages/dsh-plugin-browserskill/scripts/build-client-css.mjs", "line": 45, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "packages/dsh-plugin-browserskill/src/client/ScreenshotToolView.tsx", "line": 80, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "packages/dsh-plugin-browserskill/src/image.ts", "line": 41, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "packages/dsh-plugin-browserskill/src/tools.ts", "line": 832, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 app.test、example.com、example.test、left.test)", "file": "apps/extension/src/browser-driver/__tests__/chromium-cdp.test.ts", "line": 47 }, { "explanation": "访问第三方网络地址(如 app.test、left.test、nested.test、right.test)", "file": "apps/extension/src/browser-driver/__tests__/frame-graph.test.ts", "line": 10 }, { "explanation": "访问第三方网络地址(如 a.example、example.com)", "file": "apps/extension/src/lib/__tests__/trace-reducer.test.ts", "line": 25 }, { "explanation": "访问第三方网络地址(如 a.example、app.example、b.example、chrome.google.com)", "file": "apps/extension/src/tools/__tests__/borrow-confirmation.test.ts", "line": 72 }, { "explanation": "访问第三方网络地址(如 example.test)", "file": "apps/extension/src/tools/__tests__/dispatcher.test.ts", "line": 377 }, { "explanation": "访问第三方网络地址(如 app.example)", "file": "apps/extension/src/tools/__tests__/human-loop.test.ts", "line": 236 }, { "explanation": "访问第三方网络地址(如 app.example.test、docs.example.org、example.com、passport.jd.com)", "file": "apps/extension/src/tools/__tests__/observation.test.ts", "line": 918 }, { "explanation": "访问第三方网络地址(如 developer.chrome.com)", "file": "apps/extension/src/tools/borrow-confirmation.ts", "line": 272 }, { "explanation": "访问第三方网络地址(如 passport.jd.com)", "file": "apps/extension/src/tools/vom/__tests__/capture.test.ts", "line": 838 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "apps/extension/wxt.config.ts", "line": 74 }, { "explanation": "访问第三方网络地址(如 x)", "file": "packages/dsh-plugin-browserskill/src/observation-http.ts", "line": 178 }, { "explanation": "访问第三方网络地址(如 evil.example、example.com、x)", "file": "packages/dsh-plugin-browserskill/tests/observation.test.ts", "line": 165 }, { "explanation": "访问第三方网络地址(如 a.test、b.test、example.com、x)", "file": "packages/dsh-plugin-browserskill/tests/tools.test.ts", "line": 177 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "2719e76438ea0c4a4227493731267269dca82e0f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "mem9-ai/mem9", "name": "mem9", "author": "mem9-ai", "description": "Unlimited memory for OpenClaw", "repo_url": "https://github.com/mem9-ai/mem9", "homepage": "https://github.com/mem9-ai/mem9", "stars": 1202, "forks": 123, "open_issues": 91, "watchers": 5, "pushed_at": "2026-08-25T07:46:23Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "本文档集解释 MEM9 当前实现中的四条核心链路:Recall、Facts 抽取、Reconcile 和记忆持久化。它们共同组成“把一次对话变成可长期检索的记忆,再在未来召回”的闭环。", "en": "1. Choose your mem9 endpoint." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#4", "依赖 openclaw@2026.1.26 存在已知漏洞(GHSA-24vr-rprv-67rf, GHSA-25gx-x37c-7pph, GHSA-25pw-4h6w-qwvm) @ " ], "risk_evidence": [ { "explanation": "依赖 openclaw@2026.1.26 存在已知漏洞(GHSA-24vr-rprv-67rf, GHSA-25gx-x37c-7pph, GHSA-25pw-4h6w-qwvm)", "file": "" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "37a7c88592237aee971220ac03041a027cd95c0a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Anil-matcha/awesome-dsh-plugin", "name": "awesome-dsh-plugin", "author": "Anil-matcha", "description": "A curated list of plugins for DeepSeek Harness (dsh) - DeepSeek Harness plugin ecosystem", "repo_url": "https://github.com/Anil-matcha/awesome-dsh-plugin", "homepage": "https://github.com/Anil-matcha/awesome-dsh-plugin", "stars": 988, "forks": 255, "open_issues": 16, "watchers": 16, "pushed_at": "2026-08-25T06:52:19Z", "archived": false, "language": "unknown", "license": "unknown", "topics": [ "agent-harness", "ai-agent", "ai-agents", "autonomous-agent", "awesome", "awesome-list", "cli", "coding-agent", "cordis", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-plugin", "llm", "llm-agent", "open-source", "plugin-ecosystem", "plugins", "web-ui" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "en": "> A curated guide to DeepSeek Harness (dsh) — DeepSeek's open-source, everything-is-a-plugin coding agent — and the best community plugins built on it." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "bfca2fedec2ee085bb5084567c3a2ef043fce3d0", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "mindscale-noah/MindMemOS", "name": "MindMemOS", "author": "mindscale-noah", "description": "", "repo_url": "https://github.com/mindscale-noah/MindMemOS", "homepage": "https://mindmemos.cn", "stars": 958, "forks": 92, "open_issues": 1, "watchers": 13, "pushed_at": "2026-08-27T08:51:04Z", "archived": false, "language": "Python", "license": "unknown", "topics": [ "agent", "agent-memory", "agent-skills", "agentic", "dsh-plugin", "dsh-plugins", "openclaw", "openclaw-agent", "openclaw-plugin", "rag", "skills" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "description_i18n": { "zh": "- 2026-08-18:我们发布了 DeepSeek Harness 插件,让 DeepSeek Harness(dsh)Agent 自动召回并写入 MindMemOS 记忆。", "en": "- 2026-08-18: We released the DeepSeek Harness Plugin, letting DeepSeek Harness (dsh) agents automatically recall and write MindMemOS memories." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c1befcb73646b54f7a96724ea5463edb21c03ee0", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "tong-io/tongflow", "name": "tongflow", "author": "tong-io", "description": "TongFlow — Multimodal GenAI Studio", "repo_url": "https://github.com/tong-io/tongflow", "homepage": "https://app.tongflow.com", "stars": 958, "forks": 129, "open_issues": 7, "watchers": 99, "pushed_at": "2026-08-28T05:25:13Z", "archived": false, "language": "TypeScript", "license": "AGPL-3.0", "topics": [ "3d", "agent", "ai", "ai-tools", "aigc", "canvas", "deepseek-harness", "document", "dsh-plugin", "genai", "generative-ai", "image", "link", "multimodal", "studio", "tongflow", "video", "voice", "workflow" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "| 工作流截图 | 输出结果 | | :--: | :--: | | 基本 — 输入文本(添加),生成图像(转换),再融合成一张(组合)。 | |", "en": "| Workflow | Result | | :--: | :--: | | Basic — Type text (Add), generate images (Transform), then blend them into one (Compose). | |" }, "risk_level": "moderate", "risk_notes": [ "依赖 drizzle-orm@0.44.5 存在已知漏洞(GHSA-gpj5-g38j-94v9) @ ", "依赖 nanoid@5.1.6 存在已知漏洞(GHSA-28wg-ghj8-5hjv) @ ", "依赖 next@15.5.19 存在已知漏洞(GHSA-4633-3j49-mh5q, GHSA-4c39-4ccg-62r3, GHSA-68g3-v927-f742) @ ", "依赖 next-intl@4.6.1 存在已知漏洞(GHSA-4c35-wcg5-mm9h, GHSA-8f24-v5vv-gm5j) @ ", "依赖 uuid@13.0.0 存在已知漏洞(GHSA-w5hq-g745-h8pq) @ ", "读取本地环境配置文件(dotenv .env) @ packages/dsh-tongflow/src/api.ts" ], "risk_evidence": [ { "explanation": "依赖 drizzle-orm@0.44.5 存在已知漏洞(GHSA-gpj5-g38j-94v9)", "file": "" }, { "explanation": "依赖 nanoid@5.1.6 存在已知漏洞(GHSA-28wg-ghj8-5hjv)", "file": "" }, { "explanation": "依赖 next@15.5.19 存在已知漏洞(GHSA-4633-3j49-mh5q, GHSA-4c39-4ccg-62r3, GHSA-68g3-v927-f742)", "file": "" }, { "explanation": "依赖 next-intl@4.6.1 存在已知漏洞(GHSA-4c35-wcg5-mm9h, GHSA-8f24-v5vv-gm5j)", "file": "" }, { "explanation": "依赖 uuid@13.0.0 存在已知漏洞(GHSA-w5hq-g745-h8pq)", "file": "" }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "packages/dsh-tongflow/src/api.ts" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/dsh-tongflow/src/project/paths.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 example.invalid)", "file": "packages/dsh-tongflow/test/engine.test.ts", "line": 127 }, { "explanation": "访问第三方网络地址(如 x)", "file": "packages/dsh-tongflow/test/project-model.test.ts", "line": 117 }, { "explanation": "访问第三方网络地址(如 api.example.com、x)", "file": "packages/tongflow/src/core/registry/model-catalog.test.ts", "line": 6 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "55786d4cdbfaf0401ca35dc655369e5e832e8abc", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Anionex/dsh-vision-toolkit", "name": "dsh-vision-toolkit", "author": "Anionex", "description": "[dsh]为纯文本模型设计更强大的视觉工具箱:安装免费使用、粘贴图片直接识别、多张图片问答、截图到前端UI 还原等|DeepSeek Harness-native integration for agent-vision-toolkit: image Q&A, long-screenshot OCR, UI restoration, grounding, pixel diff, Artifacts, and Web UI.", "repo_url": "https://github.com/Anionex/dsh-vision-toolkit", "homepage": "https://agent-vision.anionex.me", "stars": 836, "forks": 37, "open_issues": 10, "watchers": 2, "pushed_at": "2026-08-27T19:09:47Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-skills", "agent-vision-toolkit", "computer-vision", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "gui-automation", "ocr", "plugin", "python", "screenshot-testing", "text-only-llm", "typescript", "ui-restoration", "vision-language-model", "vision-tools" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "更强大的视觉工具箱——给 DeepSeek Harness 里的纯文本模型装上眼睛:图片问答、长图 OCR、前端 UI 还原、GUI 视觉任务,一套视觉工具箱和一个 Skill。", "en": "A more powerful vision toolkit—give text-only models in DeepSeek Harness eyes: image Q&A, long-screenshot OCR, UI restoration, and GUI visual tasks in one toolkit and Skill." }, "risk_level": "high", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ lib/upstream.js", "读取本地环境配置文件(dotenv .env) @ tests/runtime.spec.ts" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/runtime.js", "line": 1430, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/tools.js", "line": 543, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/types/runtime.d.ts", "line": 403, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "src/runtime.ts", "line": 1951, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "src/tools.ts", "line": 586, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "tests/runtime.spec.ts", "line": 655, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "tests/runtime.spec.ts", "line": 666, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "tests/runtime.spec.ts", "line": 689, "confidence": 1 }, { "explanation": "使用系统/子进程执行外部命令", "file": "tests/vision-prompt-guard.spec.ts", "line": 58, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/moondream-openai-proxy/worker-configuration.d.ts", "line": 310, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/moondream-openai-proxy/worker-configuration.d.ts", "line": 410, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "workers/moondream-openai-proxy/worker-configuration.d.ts", "line": 12377 }, { "explanation": "访问第三方网络地址(如 vision.anionex.me)", "file": "lib/client.js", "line": 87 }, { "explanation": "访问第三方网络地址(如 dsh.internal)", "file": "lib/paste-images.js", "line": 196 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/paths.js", "line": 28 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dsh-vision-python-bootstrap-1317715800.cos.ap-guangzhou.myqcloud.com、mirrors.cloud.tencent.com)", "file": "lib/runtime-install.js", "line": 517 }, { "explanation": "访问第三方网络地址(如 dsh-vision-python-bootstrap-1317715800.cos.ap-guangzhou.myqcloud.com、mirrors.cloud.tencent.com)", "file": "lib/runtime-install.js", "line": 26 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 w3.org)", "file": "lib/runtime.js", "line": 316 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/runtime.js", "line": 21 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "lib/upstream.js" }, { "explanation": "访问第三方网络地址(如 agent-vision.anionex.me、ifdian.net)", "file": "package.json", "line": 22 }, { "explanation": "访问第三方网络地址(如 dsh-vision-python-bootstrap-1317715800.cos.ap-guangzhou.myqcloud.com)", "file": "scripts/python-bootstrap-mirror.mjs", "line": 20 }, { "explanation": "访问第三方网络地址(如 api.inferera.com、changed.example、custom.example、vision.anionex.me)", "file": "tests/client.spec.ts", "line": 84 }, { "explanation": "访问第三方网络地址(如 agent-vision.anionex.me、example.com)", "file": "tests/config.spec.ts", "line": 17 }, { "explanation": "访问第三方网络地址(如 vision.example)", "file": "tests/image-compress.spec.ts", "line": 57 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "tests/paths.spec.ts", "line": 216 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 alice、single-secret)", "file": "tests/plugin-update.spec.ts", "line": 201 }, { "explanation": "访问第三方网络地址(如 alice、single-secret)", "file": "tests/plugin-update.spec.ts", "line": 393 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dsh-vision-python-bootstrap-1317715800.cos.ap-guangzhou.myqcloud.com)", "file": "tests/runtime-install.spec.ts", "line": 61 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "tests/runtime.spec.ts" }, { "explanation": "访问第三方网络地址(如 agent-vision.anionex.me、example.com、vision.anionex.me、vision.example)", "file": "tests/runtime.spec.ts", "line": 67 }, { "explanation": "访问第三方网络地址(如 attacker.example、vision.example)", "file": "tests/web.spec.ts", "line": 153 }, { "explanation": "访问第三方网络地址(如 agent-vision.anionex.me、apache.org、developer.mozilla.org、developers.cloudflare.com)", "file": "workers/moondream-openai-proxy/worker-configuration.d.ts", "line": 7 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "5a33bf6e9ff38f2d05d32fd6ee41479b8340ac5c", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "superdesigndev/treg", "name": "treg", "author": "superdesigndev", "description": "OpenRouter for agent tools. Join community here: https://discord.gg/6mQYYfFMAn", "repo_url": "https://github.com/superdesigndev/treg", "homepage": "https://treg.to", "stars": 669, "forks": 59, "open_issues": 22, "watchers": 2, "pushed_at": "2026-08-28T06:35:55Z", "archived": false, "language": "Python", "license": "NOASSERTION", "topics": [ "agents", "api-keys", "cli", "credentials", "developer-tools", "dsh-plugin", "mcp", "proxy", "python", "registry", "secrets" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "OpenRouter, but for agent tools instead of models. Point an agent at one base URL with one token and it can do the job: 2,850 catalogued endpoints across ~57 providers — SEO and backlinks, social and trends, people and company enrichment, ads, scraping —" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 treg.to)", "file": "package.json", "line": 27 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "603540f653994080d4f507a9a3564e1017c28eef", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Nagi-ovo/dsh-ads", "name": "dsh-ads", "author": "Nagi-ovo", "description": "把 DSH 变成 2005 年门户网站|Parody ads, fake games, and popups for the DSH Web UI", "repo_url": "https://github.com/Nagi-ovo/dsh-ads", "homepage": "https://github.com/Nagi-ovo/dsh-ads", "stars": 578, "forks": 4, "open_issues": 11, "watchers": 0, "pushed_at": "2026-08-27T21:32:38Z", "archived": false, "language": "TypeScript", "license": "BSD-3-Clause", "topics": [ "deepseek-harness", "dsh-plugin", "trolling", "web-ui" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "把 DeepSeek Harness 变成 2005 年门户网站。连 inference 都逃不过广告。", "en": "Turn DeepSeek Harness into a 2005 web portal. Not even inference escapes the ads." }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ lib/index.js" ], "risk_evidence": [ { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "lib/index.js" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-assets.mjs", "line": 117, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-catalog.mjs", "line": 18, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-contrib.mjs", "line": 46, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-english-artwork.mjs", "line": 84, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-english-artwork.mjs", "line": 89, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/build-english-artwork.mjs", "line": 265, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/GamePoster.tsx", "line": 155, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/InferenceRewardGate.tsx", "line": 278, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/Lightbox.tsx", "line": 97, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "scripts/build-english-artwork.mjs", "line": 84 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "3a2ba704bc383099c686d3288ff6e0d61fc391e5", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "xiaods/k8e", "name": "k8e", "author": "xiaods", "description": "k8e.sh - OpenSource Agentic AI Sandbox Matrix ", "repo_url": "https://github.com/xiaods/k8e", "homepage": "https://k8e.sh", "stars": 480, "forks": 33, "open_issues": 1, "watchers": 9, "pushed_at": "2026-08-25T14:52:02Z", "archived": false, "language": "Go", "license": "Apache-2.0", "topics": [ "agentic-ai", "dsh-plugin", "k8s", "kubernetes", "sandbox-playground" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "| # | Section | |---|---------| | 1 | 🤖 What is K8E? |" }, "risk_level": "high", "risk_notes": [ "依赖 @grpc/grpc-js@1.12.0 存在已知漏洞(GHSA-5375-pq7m-f5r2, GHSA-99f4-grh7-6pcq) @ ", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ plugins/deepseek-harness/scripts/release.mjs" ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "plugins/deepseek-harness/scripts/release.mjs", "line": 131, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "plugins/deepseek-harness/scripts/release.mjs", "line": 164, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "plugins/deepseek-harness/scripts/release.mjs", "line": 193, "confidence": 1 }, { "explanation": "依赖 @grpc/grpc-js@1.12.0 存在已知漏洞(GHSA-5375-pq7m-f5r2, GHSA-99f4-grh7-6pcq)", "file": "" }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "plugins/deepseek-harness/packages/dsh-k8e-sandbox-client-ui/src/client/prefs.ts", "line": 9 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugins/deepseek-harness/packages/dsh-k8e-sandbox-client/src/grpc.ts", "line": 192 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "plugins/deepseek-harness/scripts/release.mjs" }, { "explanation": "访问第三方网络地址(如 gw)", "file": "plugins/deepseek-harness/tests/tool.test.mjs", "line": 37 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e76c6210fb5cdecc9fd7e2705ce14b15755c44fc", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "FSMargoo/dsh-at-file", "name": "dsh-at-file", "author": "FSMargoo", "description": "Codex-style @file mentions for DeepSeek Harness: search workspace files in the composer and attach their path to prompts.", "repo_url": "https://github.com/FSMargoo/dsh-at-file", "homepage": "https://github.com/FSMargoo/dsh-at-file", "stars": 489, "forks": 19, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-22T16:48:38Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness Web 界面的工作区路径引用插件。在输入框输入 @,可以搜索当前工作区并插入文件或目录路径。", "en": "Workspace path references for the DeepSeek Harness web interface. Type @ in the composer to search the current workspace and insert a file or directory path." }, "risk_level": "moderate", "risk_notes": [ "读取本地环境配置文件(dotenv .env) @ lib/client.js" ], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "lib/index.js", "line": 304, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 101, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 113, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/index.js", "line": 2459, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5630 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5631 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5632 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5633 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5639 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5640 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5641 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/index.js", "line": 5642 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 1284, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 2642, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 2699, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 16107, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4455 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4456 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4457 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4458 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4464 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4465 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4466 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 4467 }, { "explanation": "访问第三方网络地址(如 json-schema.org)", "file": "lib/index.js", "line": 12851 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "lib/client.js" } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c57849b27e378cf6b41d082b17c8a8750cee370f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "fufankeji/deepseek-harness-studio", "name": "deepseek-harness-studio", "author": "fufankeji", "description": "DeepSeek Harness 零代码桌面端|一键启动,支持 Windows 与 macOS;内置插件发现、热点插件推送、一键安装与管理、AI 智能推荐和视觉增强。", "repo_url": "https://github.com/fufankeji/deepseek-harness-studio", "homepage": "https://www.beyondata.com/", "stars": 548, "forks": 54, "open_issues": 0, "watchers": 4, "pushed_at": "2026-08-27T08:21:17Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agent", "deepseek", "deepseek-harness", "deepseek-harness-studio", "desktop-app", "developer-tools", "dsh", "dsh-plugin", "electron", "macos", "plugin-manager", "windows" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/dsh-tool-session-query", "description_i18n": { "zh": "与 DeepSeek Harness 一同维护的原生源码和公开包。landlock-run/ workspace 负责 harness 使用的 Landlock 自限后执行启动器,包括其架构、由三个包组成的 npm 包家族、平台支持、开发工作流和发布流程。", "en": "> Status key: ✅ Available; 🗓️ Planned. The desktop development workspace, public Plugin Center, and Chinese DeepSeek controls are available today. Planned capabilities will be updated only after the corresponding workflow is runnable." }, "risk_level": "high", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj) @ ", "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c) @ ", "读取本地环境配置文件(dotenv .env) @ apps/cli/tests/built-bin.e2e.ts", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ apps/desktop/scripts/release-mac.ts", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ apps/web/tests/scaffold.ts" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/desktop/src/main.ts", "line": 227, "confidence": 1 }, { "explanation": "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj)", "file": "" }, { "explanation": "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c)", "file": "" }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "apps/cli/tests/built-bin.e2e.ts" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "apps/cli/tests/built-bin.e2e.ts", "line": 23 }, { "explanation": "访问第三方网络地址(如 ml2022.oss-cn-hangzhou.aliyuncs.com)", "file": "apps/desktop/package.json", "line": 75 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "apps/desktop/scripts/release-mac.ts" }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "apps/web/tests/scaffold.ts" }, { "explanation": "访问第三方网络地址(如 dsh.internal)", "file": "packages/client/connection/src/client/rpc.ts", "line": 11 }, { "explanation": "访问第三方网络地址(如 x)", "file": "packages/client/modules/src/index.ts", "line": 536 }, { "explanation": "访问第三方网络地址(如 docs.ollama.com、docs.sglang.ai、docs.vllm.ai、help.aliyun.com)", "file": "packages/client/ui-desktop-customization/src/client/vision-enhancement-controller.ts", "line": 70 }, { "explanation": "访问第三方网络地址(如 example.test、help.aliyun.com、openrouter.ai)", "file": "packages/client/ui-desktop-customization/tests/vision.client.spec.tsx", "line": 26 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "cc6a9d37f8d0de554dfaff8168cf32d27d74e66a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "yogsoth-ai/de-anthropocentric-research-engine", "name": "de-anthropocentric-research-engine", "author": "yogsoth-ai", "description": "900+ pure-markdown skills for autonomous AI research, organized as 9 freely-composable packages over a 4-layer hierarchy (Campaign → Strategy → Tactic → SOP). Non-linear orchestration with backtracking, 6 MCP integrations. The AI is the researcher — you set the direction.", "repo_url": "https://github.com/yogsoth-ai/de-anthropocentric-research-engine", "homepage": "https://github.com/yogsoth-ai/de-anthropocentric-research-engine", "stars": 394, "forks": 30, "open_issues": 3, "watchers": 28, "pushed_at": "2026-08-25T16:10:30Z", "archived": false, "language": "HTML", "license": "Apache-2.0", "topics": [ "academic-research", "agent-native-research-artifact", "ai-scientist", "auto-research", "autonomous-research", "autoresearch", "claude-code", "codex", "deep-research", "dsh-plugin", "literature-review", "mcp", "research-agent", "research-orchestration", "scientific-discovery", "semantic-scholar", "skill" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "description_i18n": { "en": "The complete research orchestration system for AI-native science." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cli/test/cli.test.js", "line": 10, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "dsh-plugin/src/mcp.js", "line": 46 }, { "explanation": "访问第三方网络地址(如 api.alphaxiv.org、api.keenable.ai)", "file": "dsh-plugin/src/servers.js", "line": 31 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "970c22052a924d4e051e0e1631a5f7f651b5e60a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "text2future/flowix", "name": "flowix", "author": "text2future", "description": "Notes for you, Memory for your agents. / 内置 Deepseek harness Agent / 适用 办公 & 写作 & Coding", "repo_url": "https://github.com/text2future/flowix", "homepage": "https://www.flowix-memo.com/", "stars": 376, "forks": 44, "open_issues": 25, "watchers": 1, "pushed_at": "2026-08-27T17:28:35Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-memory", "claude-code", "codex-cli", "desktop", "dsh", "dsh-plugin", "dsh-plugin-desktop", "hermes-agent", "markdown-editor", "memory-system", "note-taking", "open-code" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "用 Markdown 记录内容,把需要的上下文交给 Agent,再将结果写回同一篇笔记,方便检查、修改和下次继续使用。", "en": "Write in Markdown, point an agent to the context it needs, and save the result back to the same note — ready to review, edit, and reuse next time." }, "risk_level": "moderate", "risk_notes": [ "依赖 mermaid@11.15.0 存在已知漏洞(GHSA-2v8p-3f2j-5mp7, GHSA-3rrr-jr9j-h3q3, GHSA-6x64-9x62-f2gx) @ ", "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj) @ ", "读取本地环境配置文件(dotenv .env) @ app/flowix-dsh-host/vendor/deepseek-harness/packages/boot/app-boot/src/index.ts" ], "risk_evidence": [ { "explanation": "依赖 mermaid@11.15.0 存在已知漏洞(GHSA-2v8p-3f2j-5mp7, GHSA-3rrr-jr9j-h3q3, GHSA-6x64-9x62-f2gx)", "file": "" }, { "explanation": "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "app/flowix-dsh-host/src/main.ts", "line": 23 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "app/flowix-dsh-host/vendor/deepseek-harness/packages/boot/app-boot/src/index.ts" }, { "explanation": "访问第三方网络地址(如 x)", "file": "app/flowix-dsh-host/vendor/deepseek-harness/packages/client/modules/src/index.ts", "line": 428 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "29fc3660cfc8cbf5bfa0623e8df52fb55eb08099", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "lencx/Minke", "name": "Minke", "author": "lencx", "description": "🐳 DeepSeek Harness Desktop", "repo_url": "https://github.com/lencx/Minke", "homepage": "https://github.com/lencx/Minke", "stars": 569, "forks": 62, "open_issues": 4, "watchers": 4, "pushed_at": "2026-08-26T11:12:47Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "agent", "deekseek", "desktop", "dsh", "dsh-plugin", "harness" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "- 不只是对话窗口 — 彼此独立的右侧和底部 Tabs,将文件管理器、终端、浏览器、插件和 Session 详情放在当前对话旁边。插件区支持从 GitHub 发现插件,以及安装、状态检查、修复与卸载。文件管理器支持目录浏览、语法高亮预览、编辑与 Diff;终端则连接运行 Minke 的电脑上的真实 PTY。", "en": "- More than a chat window — Independent right and bottom Tabs keep Files, Terminal, Browser, Plugins, and Session details beside the active conversation. The Plugins workspace supports GitHub discovery, installation, status checks, repair, and removal. Files" }, "risk_level": "high", "risk_notes": [ "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ packages/harness-overlay/src/client/remote/locales.ts", "读取本地环境配置文件(dotenv .env) @ tests/cross-platform-packaging.test.mjs" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "packages/harness-overlay/src/client/pwa/view.tsx", "line": 65, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "packages/harness-overlay/src/client/shortcuts/runtime.ts", "line": 112, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "packages/harness-overlay/src/client/shortcuts/shortcut-recording.ts", "line": 18, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "tests/harness-contract.test.mjs", "line": 23, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "tests/shortcut-recording.test.mjs", "line": 54, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "tests/shortcut-recording.test.mjs", "line": 76, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/tabs.test.mjs", "line": 468, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "desktop/main/data-home.ts", "line": 123 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "packages/harness-overlay/src/client/remote/locales.ts" }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "packages/harness-overlay/src/client/tabs/HeaderActions.ts", "line": 96 }, { "explanation": "访问第三方网络地址(如 google.com)", "file": "packages/harness-overlay/src/client/tabs/web/controller.ts", "line": 25 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "tests/cross-platform-packaging.test.mjs" }, { "explanation": "访问第三方网络地址(如 models.example.test)", "file": "tests/model-runtime.test.mjs", "line": 75 }, { "explanation": "访问第三方网络地址(如 token)", "file": "tests/plugin-catalog.test.mjs", "line": 85 }, { "explanation": "访问第三方网络地址(如 lencx-ma、lencx-macbook-pro.tail9example.ts.net、m-0123456789abcdef.example.com、minke-team.cloudflareaccess.com)", "file": "tests/remote.test.mjs", "line": 230 }, { "explanation": "访问第三方网络地址(如 cdn.example.com、example.com、github.githubassets.com、google.com)", "file": "tests/tabs.test.mjs", "line": 476 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "3c796298803d1f937da5808ee6df84d91a41e239", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "op7418/pilot-harness", "name": "pilot-harness", "author": "op7418", "description": "Pilot Harness — a CodePilot-inspired desktop client and plugin suite for DeepSeek Harness on macOS, Windows, and Linux.", "repo_url": "https://github.com/op7418/pilot-harness", "homepage": "https://github.com/op7418/pilot-harness", "stars": 261, "forks": 18, "open_issues": 19, "watchers": 1, "pushed_at": "2026-08-20T12:42:53Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agent", "codepilot", "deepseek", "deepseek-harness", "desktop-app", "dsh", "dsh-plugin", "electron", "linux", "macos", "typescript", "windows" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/dsh-tool-session-query", "description_i18n": { "zh": "DeepSeek Harness 的“一切皆插件”架构很强大,但默认体验围绕通过 CLI 启动的 Web UI 设计。Pilot Harness 保留这套运行时模型,同时补上一个日常桌面产品应有的部分:", "en": "DeepSeek Harness has a powerful “everything is a plugin” architecture, but its default experience is designed around a CLI-launched Web UI. Pilot Harness keeps that runtime model and adds the parts expected from a daily desktop product:" }, "risk_level": "high", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj) @ ", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ apps/desktop/scripts/native-macos-sign.cjs", "读取本地环境配置文件(dotenv .env) @ packages/boot/app-boot/tests/app-boot.spec.ts" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/desktop/src/main.ts", "line": 204, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "apps/desktop/tests/desktop-picker.e2e.mjs", "line": 43, "confidence": 1 }, { "explanation": "依赖 js-yaml@4.2.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "apps/desktop/scripts/after-sign.cjs", "line": 56 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "apps/desktop/scripts/native-macos-sign.cjs" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 timestamp.example.test)", "file": "apps/desktop/tests/packaging-config.test.ts", "line": 19 }, { "explanation": "访问第三方网络地址(如 timestamp.example.test)", "file": "apps/desktop/tests/packaging-config.test.ts", "line": 188 }, { "explanation": "访问第三方网络地址(如 example.com、user)", "file": "apps/desktop/tests/server-url.test.ts", "line": 6 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "packages/boot/app-boot/tests/app-boot.spec.ts" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 attacker.example)", "file": "packages/boot/app-boot/tests/app-boot.spec.ts", "line": 41 }, { "explanation": "访问第三方网络地址(如 attacker.example)", "file": "packages/boot/app-boot/tests/app-boot.spec.ts", "line": 134 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d1fa9c15fc00c05ea6931aafd724554ca34d5a6d", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Dominic789654/awesome-deepseek-harness", "name": "awesome-deepseek-harness", "author": "Dominic789654", "description": "A curated list of plugins, skills, MCP servers, patch/profile layers, orchestrators & UIs for DeepSeek Harness (DSH). Visualization · PPT · Coding · Agents · Loops (auto-research) and more. #dsh", "repo_url": "https://github.com/Dominic789654/awesome-deepseek-harness", "homepage": "https://github.com/Dominic789654/awesome-deepseek-harness", "stars": 204, "forks": 130, "open_issues": 5, "watchers": 0, "pushed_at": "2026-08-28T06:38:15Z", "archived": false, "language": "TypeScript", "license": "NOASSERTION", "topics": [ "agent", "agent-framework", "ai-agent", "ai-agents", "awesome", "awesome-list", "coding-agent", "deepseek", "deepseek-ai", "deepseek-harness", "deepseek-harness-plugin", "deepseek-harness-plugins", "dsh", "dsh-patch", "dsh-plugin", "dsh-plugins", "llm", "llm-agent", "mcp", "plugins" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> 面向 DeepSeek Harness(DSH) 的 插件 / Skill / MCP / Patch(Profile)层 / 编排器 / 聚合器 / UI 精选清单 —— DeepSeek 官方 agent 运行框架,核心理念 Model + Harness = Agent。", "en": "> A curated list of plugins, skills, MCP servers, patch/profile layers, orchestrators, aggregators & UIs for DeepSeek Harness (DSH) — DeepSeek's official agent runtime built around the idea Model + Harness = Agent." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d659ef08cc212caa3ccfcb3816c145aa77334f73", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "oil-oil/dsh-oil-creator", "name": "dsh-oil-creator", "author": "oil-oil", "description": "AI-assisted local creator workbench for DeepSeek Harness", "repo_url": "https://github.com/oil-oil/dsh-oil-creator", "homepage": "https://github.com/oil-oil/dsh-oil-creator", "stars": 159, "forks": 30, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-20T00:40:08Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "creator", "deepseek-harness", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "插件不建立封闭的内容数据库。正文和产物仍是普通文件,任何编辑器和 AI 文件工具都能读取:" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-release.mjs", "line": 49, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-release.mjs", "line": 57, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-release.mjs", "line": 188, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/client/assets/oilIcon.ts", "line": 1 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 bilibili.com、channels.weixin.qq.com、creator.douyin.com、creator.xiaohongshu.com)", "file": "scripts/collect-publish.mjs", "line": 15 }, { "explanation": "访问第三方网络地址(如 bilibili.com、channels.weixin.qq.com、creator.douyin.com、creator.xiaohongshu.com)", "file": "scripts/collect-publish.mjs", "line": 7 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 bailian.console.aliyun.com、lite.ego.app、zenmux.ai)", "file": "src/capabilities.ts", "line": 133 }, { "explanation": "访问第三方网络地址(如 bailian.console.aliyun.com、lite.ego.app、zenmux.ai)", "file": "src/capabilities.ts", "line": 196 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/platformIcons.ts", "line": 8 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "03f8d09ce9a298578ba850c0fc5dc3ff44b568ec", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "orziz/odai", "name": "odai", "author": "orziz", "description": "AI agent 通用任务治理框架:对齐目标与事实,规划和调度能力,守住授权与风险边界,治理任务执行到真实验收与交付。Governance framework for evidence-driven planning, orchestration, and verified delivery.", "repo_url": "https://github.com/orziz/odai", "homepage": "https://github.com/orziz/odai", "stars": 103, "forks": 16, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-28T06:01:01Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "agent-skills", "agentic-workflow", "ai-agent", "ai-agents", "ai-governance", "claude-code", "codex", "dsh", "dsh-plugin", "dsh-plugins", "github-copilot", "odai" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "odai 是面向 AI agent 的治理内核驱动的通用任务执行框架。", "en": "odai is a governance-powered general task-execution framework for AI agents." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 postpack 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 postpack 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 postpack 脚本会在安装/发布时自动执行 @ package.json#3", "依赖 yaml@2.8.1 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ " ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/verify-dsh-coexistence.mjs", "line": 53, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/verify-dsh-coexistence.mjs", "line": 116, "confidence": 1 }, { "explanation": "依赖 yaml@2.8.1 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/verify-dsh-coexistence.mjs", "line": 27 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c6cfc780f1bc2a67aff04506a1dd7db0841f7b29", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh_workflow", "name": "dsh_workflow", "author": "omdsh-dev", "description": "把Claude Code的UltraCode模式带给DSH,把 DSH 的一次性多 Agent 调度,升级为可生成、可保存、可治理、可观察、可恢复的 Workflow 层", "repo_url": "https://github.com/omdsh-dev/dsh_workflow", "homepage": "https://github.com/omdsh-dev/dsh_workflow", "stars": 108, "forks": 4, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-13T23:53:40Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent-orchestration", "deepseek-harness", "dsh", "dsh-plugin", "dshtopic", "multi-agent", "workflow" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "DSH 已经有很强的 Harness 基础设施:模型路由、子 Agent provider、工具权限、审批、Session 日志、后台 jobs 与 UI 事件。但仅有这些“执行原语”,团队仍需在每次会话里重新描述如何拆解、并发、验证和汇总。", "en": "@dsh-external/workflow turns DeepSeek Harness's one-off multi-agent execution into a reusable, governed, observable, and resumable workflow layer. It independently implements the complete workflow capability model demonstrated by KodaX while integrating with" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/check-compatibility.mjs", "line": 7, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/service.js", "line": 302 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "44b83c182aa02d1be8a0803e8446cb495f93cd8f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "cocode-agency/cocode", "name": "cocode", "author": "cocode-agency", "description": "Best ready-to-run DeepSeek Harness distribution: DSH desktop GUI, terminal TUI, and harness integration.", "repo_url": "https://github.com/cocode-agency/cocode", "homepage": "https://cocode.agency", "stars": 161, "forks": 37, "open_issues": 2, "watchers": 2, "pushed_at": "2026-08-27T18:41:22Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "agent", "byok", "cocode", "coding-agent", "deepseek", "deepseek-harness", "desktop-app", "dsh", "dsh-plugin", "free", "tui", "vibe-coding" ], "category": "distribution", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "description_i18n": { "zh": "开箱即用的 DeepSeek Harness 发行版。", "en": "A ready-to-run DeepSeek Harness distribution." }, "risk_level": "high", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ cocode-gui/electron-builder.config.ts", "读取本地环境配置文件(dotenv .env) @ cocode-gui/tests/scripts/workspace-dependencies.test.ts" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/build-runtime.mjs", "line": 13, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/build-runtime.mjs", "line": 25, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/build-runtime.mjs", "line": 30, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/build-supervisor.mjs", "line": 88, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/icons/generate-macos-icons.mjs", "line": 236, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/icons/generate-macos-icons.mjs", "line": 301, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/icons/generate-macos-icons.mjs", "line": 321, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/lib/workspace-dependencies.mjs", "line": 17, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/release/build-mac-pkg.mjs", "line": 150, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/release/release-hooks.ts", "line": 618, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/release/release-hooks.ts", "line": 778, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/release/release-hooks.ts", "line": 886, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/scripts/release/windows-sign-service.cjs", "line": 267, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "cocode-gui/scripts/release/windows-sign-service.cjs", "line": 276, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "cocode-gui/src/main/contexts/account/presentation/ipc/register-account-ipc.ts", "line": 100 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "cocode-gui/src/main/shared/logging/error-serializer.ts", "line": 43 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "cocode-gui/tests/release/icon-pipeline.test.ts", "line": 82, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "cocode-host-supervisor/packages/host-supervisor/src/host-jsonrpc-plugin/gateway.ts", "line": 1607, "confidence": 1 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "cocode-gui/electron-builder.config.ts" }, { "explanation": "访问第三方网络地址(如 workbench.local)", "file": "cocode-gui/packages/cocode/cocode-workbench/src/host-api.ts", "line": 248 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "cocode-gui/packages/cocode/cocode-workbench/src/word-document.ts", "line": 26 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 w3.org)", "file": "cocode-gui/scripts/icons/generate-macos-icons.mjs", "line": 312 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "cocode-gui/scripts/icons/generate-macos-icons.mjs", "line": 328 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 timestamp.digicert.com)", "file": "cocode-gui/scripts/release/release-config.ts", "line": 100 }, { "explanation": "访问第三方网络地址(如 timestamp.digicert.com)", "file": "cocode-gui/scripts/release/release-config.ts", "line": 319 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 cocode.agency)", "file": "cocode-gui/src/main/contexts/account/infrastructure/agency-client.ts", "line": 107 }, { "explanation": "访问第三方网络地址(如 cocode.agency)", "file": "cocode-gui/src/main/contexts/account/infrastructure/agency-client.ts", "line": 90 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 cocode.agency、example.com)", "file": "cocode-gui/tests/main/account/account-primitives.test.ts", "line": 171 }, { "explanation": "访问第三方网络地址(如 cocode.agency、example.com)", "file": "cocode-gui/tests/main/account/account-primitives.test.ts", "line": 36 }, { "explanation": "访问第三方网络地址(如 cocode.agency、old.cocode.agency、other.example)", "file": "cocode-gui/tests/main/account/account-service.test.ts", "line": 59 }, { "explanation": "访问第三方网络地址(如 example.test)", "file": "cocode-gui/tests/main/logging/logging-core.test.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 gitlab.com)", "file": "cocode-gui/tests/main/shell/application-update-config.test.ts", "line": 129 }, { "explanation": "访问第三方网络地址(如 cocode.example.test、signing.example.test、timestamp.digicert.com、timestamp.example.test)", "file": "cocode-gui/tests/release/release-config.test.ts", "line": 144 }, { "explanation": "访问第三方网络地址(如 cocode.example.test)", "file": "cocode-gui/tests/release/windows-sign-service.test.ts", "line": 184 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "cocode-gui/tests/scripts/workspace-dependencies.test.ts" }, { "explanation": "访问第三方网络地址(如 vitejs.dev)", "file": "cocode-gui/vite.main.config.ts", "line": 5 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 renderer.local、vitejs.dev)", "file": "cocode-gui/vite.renderer.config.ts", "line": 18 }, { "explanation": "访问第三方网络地址(如 renderer.local、vitejs.dev)", "file": "cocode-gui/vite.renderer.config.ts", "line": 20 }, { "explanation": "访问第三方网络地址(如 secret)", "file": "cocode-tui/test/connection/client.test.ts", "line": 371 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "1228b841709c4539f8e05f10ad60f2fce56d53c4", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "labring/sealos-skills", "name": "sealos-skills", "author": "labring", "description": "AI agent skills for Sealos — deploy any project, provision databases, object storage & more with one command. Works with Claude Code, Gemini CLI, Codex.", "repo_url": "https://github.com/labring/sealos-skills", "homepage": "https://sealos.io/sealos-skills", "stars": 77, "forks": 18, "open_issues": 6, "watchers": 1, "pushed_at": "2026-08-14T06:36:11Z", "archived": false, "language": "Python", "license": "unknown", "topics": [ "agent-skills", "ai-agent", "claude-code", "cloud-native", "codex", "deployment", "docker", "dsh-plugin", "gemini-cli", "kubernetes", "sealos" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "通过 AI 智能体将项目部署到 Sealos Cloud。", "en": "Deploy projects to Sealos Cloud from your AI agent." }, "risk_level": "moderate", "risk_notes": [ "依赖 yaml@2.4.2 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ ", "读取本地环境配置文件(dotenv .env) @ skills/sealos-database/scripts/analyze-project-database.mjs" ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/test-sealos-deploy-template-fast-path.mjs", "line": 60, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/test-sealos-deploy-template-fast-path.mjs", "line": 73, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-canvas/scripts/generate-canvas.mjs", "line": 191, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-canvas/scripts/generate-canvas.mjs", "line": 207, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-canvas/scripts/generate-canvas.mjs", "line": 232, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/build-push.mjs", "line": 77, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/build-push.mjs", "line": 99, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/build-push.mjs", "line": 217, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/detect-image.mjs", "line": 457, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/detect-template.mjs", "line": 107, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/ensure-image-pull-secret.mjs", "line": 7, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/gh-auth-utils.mjs", "line": 15, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/gh-auth-utils.mjs", "line": 146, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/gh-auth-utils.mjs", "line": 164, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/gh-refresh-scopes.mjs", "line": 62, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/gh-refresh-scopes.mjs", "line": 86, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "skills/sealos-deploy/scripts/sealos-auth.mjs", "line": 259, "confidence": 1 }, { "explanation": "依赖 yaml@2.4.2 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 demo.example.com)", "file": "scripts/test_canvas_contract.mjs", "line": 74 }, { "explanation": "访问第三方网络地址(如 demo.example.com)", "file": "scripts/test_canvas_contract.mjs", "line": 20 }, { "explanation": "访问第三方网络地址(如 demo-app-abc123.gzg.sealos.run)", "file": "scripts/test_deploy_pipeline_contract.mjs", "line": 30 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "skills/sealos-canvas/scripts/generate-canvas.mjs", "line": 35 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "skills/sealos-database/scripts/analyze-project-database.mjs" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 template.)", "file": "skills/sealos-deploy/scripts/deploy-template.mjs", "line": 28 }, { "explanation": "访问第三方网络地址(如 template.)", "file": "skills/sealos-deploy/scripts/deploy-template.mjs", "line": 17 }, { "explanation": "访问第三方网络地址(如 ghcr.io、hub.docker.com)", "file": "skills/sealos-deploy/scripts/detect-image.mjs", "line": 72 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f6876f7df876eac3617ddc15f95f43dcb8c33e31", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "Tencent/WeKnora", "name": "WeKnora", "author": "Tencent", "description": "Open-source LLM knowledge platform: turn raw documents into a queryable RAG, an autonomous reasoning agent, and a self-maintaining Wiki.", "repo_url": "https://github.com/Tencent/WeKnora", "homepage": "https://weknora.weixin.qq.com", "stars": 20814, "forks": 2994, "open_issues": 577, "watchers": 99, "pushed_at": "2026-08-28T06:27:34Z", "archived": false, "language": "Go", "license": "NOASSERTION", "topics": [ "agent", "agentic", "ai", "chatbot", "dsh-plugin", "embeddings", "evaluation", "generative-ai", "golang", "knowledge-base", "llm", "multi-tenant", "ollama", "openai", "question-answering", "rag", "reranking", "semantic-search", "vector-search", "wiki" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "This package provides a client library for interacting with WeKnora services, supporting all HTTP-based interface calls, making it easier for other modules to integrate with WeKnora services without having to write HTTP request code directly." }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ frontend/src/api/embed/index.ts", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#3", "依赖 axios@1.16.0 存在已知漏洞(GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548) @ ", "依赖 dompurify@3.4.11 存在已知漏洞(GHSA-55q2-fjhq-7xh7, GHSA-c2j3-45gr-mqc4) @ ", "依赖 mermaid@11.15.0 存在已知漏洞(GHSA-2v8p-3f2j-5mp7, GHSA-3rrr-jr9j-h3q3, GHSA-6x64-9x62-f2gx) @ ", "依赖 xlsx@0.20.2 存在已知漏洞(GHSA-4r6h-8v6p-xvw6, GHSA-5pgg-2g8v-p4x9) @ " ], "risk_evidence": [ { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "frontend/src/api/embed/index.ts" }, { "explanation": "依赖 axios@1.16.0 存在已知漏洞(GHSA-42h9-826w-cgv3, GHSA-7q8q-rj6j-mhjq, GHSA-f4gw-2p7v-4548)", "file": "" }, { "explanation": "依赖 dompurify@3.4.11 存在已知漏洞(GHSA-55q2-fjhq-7xh7, GHSA-c2j3-45gr-mqc4)", "file": "" }, { "explanation": "依赖 mermaid@11.15.0 存在已知漏洞(GHSA-2v8p-3f2j-5mp7, GHSA-3rrr-jr9j-h3q3, GHSA-6x64-9x62-f2gx)", "file": "" }, { "explanation": "依赖 xlsx@0.20.2 存在已知漏洞(GHSA-4r6h-8v6p-xvw6, GHSA-5pgg-2g8v-p4x9)", "file": "" }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "frontend/public/tdesign-icons/0.4.1/fonts/index.js", "line": 3 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "frontend/src/api/embed/index.ts", "line": 62 }, { "explanation": "访问第三方网络地址(如 your-backend.example.com、your-site.example.com)", "file": "frontend/src/api/embed/index.ts", "line": 628 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "412dcc41c662c9b45698959e0c3c37db5b8dc9d3", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "omdsh-dev/DSH-better-sidebar", "name": "DSH-better-sidebar", "author": "omdsh-dev", "description": "开放的侧边栏底座,支持三方拓展注册新侧边栏页面。内置文件渲染编辑/终端/侧边对话/Git/子代理页面 | Open sidebar foundation, supports third-party extensions to register new sidebar pages. Built-in file rendering/editing, terminal, side chat, Git, and sub-agent pages.", "repo_url": "https://github.com/omdsh-dev/DSH-better-sidebar", "homepage": "https://github.com/omdsh-dev/DSH-better-sidebar", "stars": 3039, "forks": 254, "open_issues": 138, "watchers": 6, "pushed_at": "2026-08-27T20:21:00Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek", "deepseek-harness", "dsh", "dsh-better-sidebar", "dsh-plugin", "sidebar" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "一个服务化的侧边栏框架,一套开箱即用的完整工作台", "en": "A service-oriented sidebar framework, and a complete workbench out of the box" }, "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "依赖 @codemirror/commands 与知名包 commander 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json", "依赖 ws@8.18.0 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p) @ " ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "依赖 @codemirror/commands 与知名包 commander 名称高度相似(编辑距离 2),存在仿冒风险", "file": "package.json" }, { "explanation": "监听键盘输入事件", "file": "src/client/UploadOverlay.tsx", "line": 33, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/mermaid.tsx", "line": 160, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "tests/chunk-artifact.spec.ts", "line": 31, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "tests/e2e/mount.e2e.ts", "line": 414, "confidence": 1 }, { "explanation": "依赖 ws@8.18.0 存在已知漏洞(GHSA-58qx-3vcg-4xpx, GHSA-96hv-2xvq-fx4p)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/agent-pty.ts", "line": 227 }, { "explanation": "访问第三方网络地址(如 dsh.internal)", "file": "src/bundle-route.ts", "line": 84 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/icons.tsx", "line": 16 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/client/state.ts", "line": 4 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.com)", "file": "tests/e2e/mount.e2e.ts", "line": 34 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "tests/e2e/mount.e2e.ts", "line": 85 }, { "explanation": "访问第三方网络地址(如 h)", "file": "tests/html-route.spec.ts", "line": 152 }, { "explanation": "访问第三方网络地址(如 example.com、w3.org)", "file": "tests/mermaid-markdown.spec.tsx", "line": 21 }, { "explanation": "访问第三方网络地址(如 evil.test、example.com、w3.org)", "file": "tests/mermaid-sanitize.spec.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 a.example、b.example、example.com)", "file": "tests/service.spec.ts", "line": 241 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 arxiv.org、example.com、site.example)", "file": "tests/smoke.spec.ts", "line": 225 }, { "explanation": "访问第三方网络地址(如 arxiv.org、example.com、site.example)", "file": "tests/smoke.spec.ts", "line": 663 }, { "explanation": "访问第三方网络地址(如 example.com、other.com、x)", "file": "tests/state.spec.ts", "line": 308 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b7aab48deb17b7dd92094c84441783fccaf51561", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "ysr666/dsh-vision-router", "name": "dsh-vision-router", "author": "ysr666", "description": "Eyes for text-only DeepSeek Harness agents: built-in free vision chain (no key) + pixel-level vision tools (Q&A, grounding, crop, pixel diff, colors, OCR, SVG trace, cutout, screenshots). One-command install, no Python, image turns work like ordinary tool-calling turns.", "repo_url": "https://github.com/ysr666/dsh-vision-router", "homepage": "https://github.com/ysr666/dsh-vision-router", "stars": 1009, "forks": 44, "open_issues": 1, "watchers": 2, "pushed_at": "2026-08-28T06:47:21Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "multimodal", "vision" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "使用屏幕/画面采集能力", "file": "lib/adversarial-hardening.js", "line": 401, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/adversarial-hardening.js", "line": 402, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client-presentation-boundary.js", "line": 133, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/local-vision-stabilizer.js", "line": 105, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/local-vision-stabilizer.js", "line": 109, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "lib/local-vision-stabilizer.js", "line": 144, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "lib/vision-backend-smoke-test.js", "line": 267, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "lib/vision-backend-smoke-test.js", "line": 14 }, { "explanation": "使用屏幕/画面采集能力", "file": "tests/qa-screenshot-runtime.test.js", "line": 35, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/adversarial-hardening.js", "line": 338 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/vision-tool-runtime-boundary.js", "line": 2 }, { "explanation": "访问第三方网络地址(如 alice、secret.invalid)", "file": "tests/doctor-runtime.test.js", "line": 71 }, { "explanation": "访问第三方网络地址(如 gateway.example)", "file": "tests/pi-ai-bridge-wire-compat.test.js", "line": 12 }, { "explanation": "访问第三方网络地址(如 a.example、b.example)", "file": "tests/qa-endpoint-route-alias.test.js", "line": 12 }, { "explanation": "访问第三方网络地址(如 a.example、b.example、c.example)", "file": "tests/qa-reliability-tail.test.js", "line": 112 }, { "explanation": "访问第三方网络地址(如 example.invalid、fallback.invalid)", "file": "tests/vision-backend-smoke-test.test.js", "line": 114 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9e9a938e53a70715a23c7b9650b652506e537419", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "vibeinging/deepseek-harness-desktop-app", "name": "deepseek-harness-desktop-app", "author": "vibeinging", "description": "DeepSeek Harness Desktop App: a local AI desktop workspace for DSH Sessions, projects, files, web research, plugins, and Office artifacts.", "repo_url": "https://github.com/vibeinging/deepseek-harness-desktop-app", "homepage": "https://github.com/vibeinging/deepseek-harness-desktop-app", "stars": 632, "forks": 35, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-27T03:37:01Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "agentic-workflows", "ai-agent", "ai-workbench", "data-analysis", "deepseek-harness", "desktop-app", "dsh", "dsh-plugin", "electron", "local-first", "mcp", "model-context-protocol", "office-automation", "react", "typescript" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "这个私有 Profile Bundle 在不导入、不修改 DSH 源码检出目录的前提下扩展官方 DSH Web Profile。它把 project_list、conversation_list、四个 DeepSeek Harness Desktop App Canvas/Site 工具、三个 Office 产物工具和 ui_render 注册到 Agent 作用域的 DSH 工具目录。它的 product.json 还向应用自有的 agent.workbench.tool", "en": "DeepSeek Harness Desktop App is a local AI work desktop built on DeepSeek Harness (DSH). It brings DSH Sessions, Agents, Tools, Skills, MCP, and Profile Bundles together with projects, files, web pages, Git Worktrees, Canvas, Sites, and Office artifacts in" }, "risk_level": "high", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#1" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在 Base64 解码行为", "file": "electron/main.js", "line": 681, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "electron/main.js", "line": 1419, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "electron/main.js", "line": 1559, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "electron/main.js", "line": 1490, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "server/src/app/models/index.js", "line": 122 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "electron/main.js", "line": 123 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "electron/main.js", "line": 36 }, { "explanation": "访问第三方网络地址(如 gateway.example)", "file": "renderer/src/views/models/index.tsx", "line": 298 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "a7cfa02b2937730fd3e3d75b97524550afa957f7", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "hashgraph-online/hol-guard", "name": "hol-guard", "author": "hashgraph-online", "description": "Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.", "repo_url": "https://github.com/hashgraph-online/hol-guard", "homepage": "https://hol.org/guard", "stars": 490, "forks": 17, "open_issues": 34, "watchers": 1, "pushed_at": "2026-08-28T04:07:04Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "agent-security", "ai-agent-security", "ai-agents", "ai-antivirus", "ai-security", "claude-code", "codex", "cursor", "devsecops", "dsh-plugin", "gemini-cli", "mcp", "mcp-security", "openclaw", "opencode", "prompt-injection", "runtime-security", "secrets-detection", "security", "supply-chain-security" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "en": "| | Stop risky AI actions before they compromise your machine. HOL Guard is a local-first security layer for AI agents, tools, plugins, skills, MCP servers, and package installs. Install HOL Guard Read the documentation PyPI Package (hol-guard) Report an" }, "risk_level": "high", "risk_notes": [ "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ dashboard/src/guard-api.test.ts" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "dashboard/src/app.tsx", "line": 313, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "dashboard/src/review-decision-card.tsx", "line": 353, "confidence": 1 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "dashboard/src/guard-api.test.ts" }, { "explanation": "访问第三方网络地址(如 attacker.example、example.com、example.test)", "file": "dashboard/src/guard-api.test.ts", "line": 106 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "dashboard/src/guard-api.ts", "line": 283 }, { "explanation": "访问第三方网络地址(如 hol.org)", "file": "dashboard/src/guard-api.ts", "line": 434 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "fae7e96f29a805d2347c056d2e2f99b75fbd6a12", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Ikalus1988/MisakaNet", "name": "MisakaNet", "author": "Ikalus1988", "description": "📚 A zero-dependency, git-backed micro-lesson library for AI Agents to asynchronously share and search verified debugging experience. Python stdlib only. | https://misakanet.org", "repo_url": "https://github.com/Ikalus1988/MisakaNet", "homepage": "https://misakanet.org", "stars": 430, "forks": 160, "open_issues": 34, "watchers": 27, "pushed_at": "2026-08-28T06:51:20Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "ai-agent", "ai-infra", "claude", "deepseek-harness", "devops", "dsh-plugin", "failure-analysis", "failure-memory", "git-based", "knowledge-sharing", "lesson-database", "mcp", "mcp-server", "multi-agent", "open-source", "python" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "> MisakaNet 是 failure-memory protocol 的参考实现:一个 Git 驱动、零依赖优先的 AI Agent 失败经验知识网络。", "en": "> Git-backed failure-memory for AI coding agents." }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "workers/register-proxy-sw.js", "line": 206, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/register-proxy-sw.js", "line": 223, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/register-proxy-sw.js", "line": 609, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/register-proxy.js", "line": 212, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "workers/register-proxy.js", "line": 461, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/fatal-guard/bin/fatal-guard.js", "line": 115 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "workers/register-proxy-sw.js", "line": 1595 }, { "explanation": "访问第三方网络地址(如 claude.ai、copilot.microsoft.com、cursor.sh、glama.ai)", "file": "workers/register-proxy-sw.js", "line": 7 }, { "explanation": "访问第三方网络地址(如 dash.cloudflare.com、ikalus1988.github.io)", "file": "workers/register-proxy.js", "line": 2 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "6df5d5aed3dd3bc30dd864800bdaed862c5f2115", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "vlln/whale-girl", "name": "whale-girl", "author": "vlln", "description": "DSH Web GUI 桌面宠物插件(QQ 宠物形态):右下角悬浮、可拖拽/投喂/玩耍的积累型伙伴。", "repo_url": "https://github.com/vlln/whale-girl", "homepage": "https://github.com/vlln/whale-girl", "stars": 293, "forks": 17, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-27T08:49:20Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "dsh-repository-plugin", "pet" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "官方 bundle 插件 格式(仓库根 package.json 的 dsh.bundle + dsh.client)。经官方 profile 管理:", "en": "Official bundle plugin (dsh.bundle + dsh.client in root package.json), managed via the official profile:" }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 1086, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 1099, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 209 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 214 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 216 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 225 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "lib/client.js", "line": 243 }, { "explanation": "监听键盘输入事件", "file": "lib/client/index.mjs", "line": 1122, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client/index.mjs", "line": 1135, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "desktop/lib/src/config.mjs", "line": 38 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/client.js", "line": 673 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dsh.internal)", "file": "lib/index.mjs", "line": 41 }, { "explanation": "访问第三方网络地址(如 dsh.internal)", "file": "lib/index.mjs", "line": 537 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e22e1fd918746e610f7bfb1713cef1e57a56f37c", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "csyangwen/dsh-memory-evolve", "name": "dsh-memory-evolve", "author": "csyangwen", "description": "为 DeepSeek Harness 带来「跨会话长期记忆 + 后台自我进化」能力的纯插件实现:五轨记忆 · git 分支感知 · 回合内自我审查 · 技能自我进化与技能管理器 · 四轨待办 · COI 调度 · 会话广播 · 会话搜索 · 提示词管理器 · 临时信息便签——零核心修改、零运行时依赖,随装随用、卸载即净。", "repo_url": "https://github.com/csyangwen/dsh-memory-evolve", "homepage": "https://github.com/csyangwen/dsh-memory-evolve", "stars": 251, "forks": 22, "open_issues": 4, "watchers": 0, "pushed_at": "2026-08-24T13:42:39Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> 一句话:让 DSH 里的 AI 拥有跨会话的长期记忆、帮你管理待办与技能、还能拉起一群 AI 会话和外部 AI 代理协同干活——越用越懂你,换会话不丢上下文。", "en": "> In one sentence: Give the AI inside DSH long-term cross-session memory, help you manage todos and skills, and let you orchestrate a team of AI sessions and external AI agents working together — the more you use it, the more it understands you, and switching" }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "tests/update.test.js", "line": 42, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/coi/scheduler.js", "line": 350 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/client/notification-bell.tsx", "line": 23 }, { "explanation": "访问第三方网络地址(如 ...)", "file": "src/client/notification-bell.tsx", "line": 309 }, { "explanation": "访问第三方网络地址(如 evil.example)", "file": "tests/update.test.js", "line": 683 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "a08fff7f5c0228bf7a9dbf21d917579ccc08a5a8", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "weijiafu14/pi2dsh", "name": "pi2dsh", "author": "weijiafu14", "description": "Bridge the Pi and DeepSeek Harness ecosystems: one Pi Host ABI runs unmodified Pi extensions as native DSH plugins. 打通 Pi 与 DSH 生态。", "repo_url": "https://github.com/weijiafu14/pi2dsh", "homepage": "https://github.com/weijiafu14/pi2dsh", "stars": 170, "forks": 32, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-28T00:22:57Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "ai-agents", "compatibility-layer", "deepseek-harness", "dsh", "dsh-plugin", "migration", "pi", "pi-agent", "plugin-migration" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "让 Pi 生态的插件原样跑在 DeepSeek Harness 上。", "en": "Run the Pi ecosystem's plugins on DeepSeek Harness, unmodified." }, "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "依赖 yaml@2.8.1 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ ", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/verify-examples-e2e.mjs", "读取本地环境配置文件(dotenv .env) @ scripts/verify-tui-singlepath-e2e.mjs" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/verify-tui-singlepath-e2e.mjs", "line": 55, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/runtime.ts", "line": 386, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/tui-surfaces.ts", "line": 117 }, { "explanation": "存在 Base64 解码行为", "file": "tests/compat-shims.spec.ts", "line": 248, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "tests/compat-shims.spec.ts", "line": 265, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "tests/compat-shims.spec.ts", "line": 270, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "tests/dsh-runtime.spec.ts", "line": 383, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "tests/provider-adapter.spec.ts", "line": 319, "confidence": 1 }, { "explanation": "依赖 yaml@2.8.1 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/verify-examples-e2e.mjs" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/verify-tui-mcp-tool-e2e.mjs", "line": 39 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "scripts/verify-tui-singlepath-e2e.mjs" }, { "explanation": "访问第三方网络地址(如 api.anthropic.com、api.githubcopilot.com、api.moonshot.ai、chatgpt.com)", "file": "src/compat/pi-ai.ts", "line": 238 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/compat/pi-coding-agent.ts", "line": 14 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.invalid、gw.fixture.test、responses.fixture.test)", "file": "tests/dsh-runtime.spec.ts", "line": 702 }, { "explanation": "访问第三方网络地址(如 example.invalid、gw.fixture.test、responses.fixture.test)", "file": "tests/dsh-runtime.spec.ts", "line": 975 }, { "explanation": "访问第三方网络地址(如 first.example、gw.example、second.example)", "file": "tests/engine.spec.ts", "line": 375 }, { "explanation": "访问第三方网络地址(如 dynamic.example、gw.example)", "file": "tests/provider-adapter.spec.ts", "line": 90 }, { "explanation": "访问第三方网络地址(如 builtin.example、gw.example、one.example、two.example)", "file": "tests/provider-ledger.spec.ts", "line": 14 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "22b46a62d2742c79f41efe9152c88c1208b64f92", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "imsai-sh/awesome-deepseek-harness-plugins", "name": "awesome-deepseek-harness-plugins", "author": "imsai-sh", "description": "DeepSeek Harness plugin store, marketplace and hub — 3,100+ dsh plugins with search, rankings, install commands and a free public API. DeepSeek Harness 插件市场 / 插件商店:自动收集与格式校验,免费搜索 API。deepseek1024.com", "repo_url": "https://github.com/imsai-sh/awesome-deepseek-harness-plugins", "homepage": "https://deepseek1024.com/", "stars": 197, "forks": 138, "open_issues": 13, "watchers": 1, "pushed_at": "2026-08-28T05:47:47Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "awesome-list", "catalog", "deepseek", "deepseek-harness", "deepseek-harness-plugins", "deepseek1024", "dsh", "dsh-1024store", "dsh-bundle", "dsh-plugin", "dsh-plugin-market", "dsh-plugin-verify", "dsh-plugins", "dsh-skill", "marketplace", "plugin-directory", "plugin-hub", "plugin-store", "plugins", "registry" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "dsh1024 是 DeepSeek Harness 的 DSH 1024Store 包。一个 npm 包提供两个入口:" }, "risk_level": "high", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ packages/dsh1024/test/cli.test.js", "读取本地环境配置文件(dotenv .env) @ scripts/build-readme.mjs", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/review-plugin-submission.mjs" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "apps/web/src/components/SplitInstallButton.tsx", "line": 103, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "apps/web/worker-configuration.d.ts", "line": 312, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "apps/web/worker-configuration.d.ts", "line": 412, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "apps/web/worker-configuration.d.ts", "line": 12379 }, { "explanation": "存在 Base64 解码行为", "file": "apps/web/worker/lib/github-discovery.ts", "line": 316, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "packages/dsh1024/client/client.js", "line": 462, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "scripts/review-plugin-submission.mjs", "line": 405, "confidence": 1 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 deepseek1024.com、imsai.cc)", "file": "apps/web/scripts/visual-check.mjs", "line": 3 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、imsai.cc)", "file": "apps/web/scripts/visual-check.mjs", "line": 3 }, { "explanation": "访问第三方网络地址(如 example.com、images.example.com)", "file": "apps/web/src/lib/readme.test.tsx", "line": 14 }, { "explanation": "访问第三方网络地址(如 readme.invalid)", "file": "apps/web/src/lib/readme.ts", "line": 13 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "apps/web/src/lib/useLiveStats.ts", "line": 17 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com)", "file": "apps/web/tests/api-contract.test.ts", "line": 138 }, { "explanation": "访问第三方网络地址(如 cli.example、deepseek1024.com、example.com、registry-consumer.example)", "file": "apps/web/tests/app.test.ts", "line": 67 }, { "explanation": "访问第三方网络地址(如 api.npmjs.org)", "file": "apps/web/tests/npm-downloads.test.ts", "line": 20 }, { "explanation": "访问第三方网络地址(如 x.tgz)", "file": "apps/web/tests/npm-refresh-task.test.ts", "line": 75 }, { "explanation": "访问第三方网络地址(如 deepseek1024、deepseek1024.com)", "file": "apps/web/tests/seo.test.ts", "line": 60 }, { "explanation": "访问第三方网络地址(如 apache.org、developer.mozilla.org、developers.cloudflare.com、docs.oasis-open.org)", "file": "apps/web/worker-configuration.d.ts", "line": 40 }, { "explanation": "访问第三方网络地址(如 api.deepseek1024.com、deepseek1024.com、schema.org)", "file": "apps/web/worker/seo-templates.ts", "line": 15 }, { "explanation": "访问第三方网络地址(如 api.deepseek1024.com、sitemaps.org)", "file": "apps/web/worker/seo.ts", "line": 475 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/dsh1024/lib/routes.js", "line": 19 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 deepseek1024.com)", "file": "packages/dsh1024/src/shared/telemetry.ts", "line": 266 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "packages/dsh1024/test/cli.test.js" }, { "explanation": "访问第三方网络地址(如 example.com、gitlab.com、legacy.invalid、modern.invalid)", "file": "packages/dsh1024/test/cli.test.js", "line": 106 }, { "explanation": "访问第三方网络地址(如 example.com、store.example)", "file": "packages/dsh1024/tests/registry.test.mjs", "line": 24 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、evil.example、harness.local、public.example)", "file": "packages/dsh1024/tests/routes.test.mjs", "line": 15 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、fallback.example)", "file": "packages/dsh1024/tests/update.test.mjs", "line": 15 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "scripts/build-readme.mjs" }, { "explanation": "访问第三方网络地址(如 api.deepseek1024.com、deepseek1024.com)", "file": "scripts/build-readme.mjs", "line": 11 }, { "explanation": "访问第三方网络地址(如 example.test)", "file": "scripts/build-readme.test.mjs", "line": 33 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/review-plugin-submission.mjs" } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "31935ce6c25faf41f8d5383632fc884237af9488", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Han-1413141/dsh-cost-meter", "name": "dsh-cost-meter", "author": "Han-1413141", "description": "DeepSeek Harness session cost meter plugin: session/daily cost, budget, history, OpenCode Go quota, official & custom-provider balance, Codex-like token heatmap, peak/off-peak pricing with pre-switch popup & system-notification alerts, official price sync, 90+ model pricing catalog, Coding Plan quota queries (7 vendors), bilingual zh/en UI", "repo_url": "https://github.com/Han-1413141/dsh-cost-meter", "homepage": "https://github.com/Han-1413141/dsh-cost-meter", "stars": 211, "forks": 15, "open_issues": 1, "watchers": 1, "pushed_at": "2026-08-27T13:10:45Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "cost-tracking", "deepseek", "deepseek-api", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugins", "harness", "llm", "plugins", "token-usage" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 会话费用统计插件(界面中英双语)", "en": "Session cost tracking plugin for the DeepSeek Harness web GUI (bilingual UI)" }, "risk_level": "high", "risk_notes": [ "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ lib/coding-plans.js" ], "risk_evidence": [ { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/client.js", "line": 2756 }, { "explanation": "访问第三方网络地址(如 example.com、w3.org)", "file": "lib/client.js", "line": 1705 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "lib/coding-plans.js" }, { "explanation": "访问第三方网络地址(如 api.anthropic.com、api.commandcode.ai、api.moonshot.cn、api.siliconflow.cn)", "file": "lib/coding-plans.js", "line": 111 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/custom-balance.js", "line": 76 }, { "explanation": "访问第三方网络地址(如 opencode.ai)", "file": "lib/index.js", "line": 360 }, { "explanation": "访问第三方网络地址(如 ai.google.dev、alibabacloud.com、docs.x.ai、opencode.ai)", "file": "lib/pricing.js", "line": 28 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 a、example.test)", "file": "test/verify.mjs", "line": 261 }, { "explanation": "访问第三方网络地址(如 a、example.test)", "file": "test/verify.mjs", "line": 80 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "a4f653b37ba3a31b7f4a50af3ad52dbe31efdcdf", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "liangmianya/dsh-synapse", "name": "dsh-synapse", "author": "liangmianya", "description": "A visual, non-linear conversation workspace plugin for DeepSeek Harness ; A canvas-based session explorer and branching workspace for DeepSeek Harness.", "repo_url": "https://github.com/liangmianya/dsh-synapse", "homepage": "https://github.com/liangmianya/dsh-synapse", "stars": 243, "forks": 30, "open_issues": 16, "watchers": 0, "pushed_at": "2026-08-26T13:12:24Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugin-market", "dsh-plugins", "plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "dsh-synapse 是一个独立的 DeepSeek Harness Web 插件。它不替代 DSH 的模型、工具、会话或权限逻辑,而是在原生对话界面上增加一个可视化工作台,将同一工作区内的会话、追问和分支呈现为可浏览的对话地图。" }, "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "app.js", "line": 8 }, { "explanation": "访问第三方网络地址(如 dsh.local)", "file": "index.js", "line": 769 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "a323f76b0c47ffad59194d8ac7efacb3aa6bdfba", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "Tabbit-Browser/dsh-tabbit", "name": "dsh-tabbit", "author": "Tabbit-Browser", "description": "Tabbit Browser plugins for Deepseek Harness", "repo_url": "https://github.com/Tabbit-Browser/dsh-tabbit", "homepage": "https://www.tabbit.ai", "stars": 95, "forks": 10, "open_issues": 10, "watchers": 0, "pushed_at": "2026-08-22T16:01:13Z", "archived": false, "language": "JavaScript", "license": "unknown", "topics": [ "awesome-dsh-plugin", "browser-automation", "browser-use", "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugin-desktop", "dsh-plugin-market", "dsh-plugin-verify", "dsh-plugins", "playwright", "tabbit" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "这是一个为 DeepSeek Harness(DSH)打造的插件。安装后,DSH 中的 Agent 获得控制 Tabbit 浏览器的能力:通过 tabbit-cli——Tabbit 浏览器自带的、任务隔离的 Playwright CLI——操作真实网页、复用真实登录态,完成网页自动化、信息提取、QA 与基准测试等任务。", "en": "A plugin for DeepSeek Harness (DSH) that gives the agent control over your Tabbit Browser: real pages, real login state, and real interactions, driven through tabbit-cli — the task-isolated Playwright CLI owned by the browser itself. Use it for web" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "update-check.js", "line": 56 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "7b69a066973d4198d70d91368c7a5643ed7a57ce", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "omdsh-dev/dsh-annotation", "name": "dsh-annotation", "author": "omdsh-dev", "description": "DSH Web 选中批注插件:选文字→批注→回车随消息发送;气泡隐藏批注块(零闪烁);回复按 Annotation N 逐条对照(可悬浮芯片)。官方 bundle,零核心改动", "repo_url": "https://github.com/omdsh-dev/dsh-annotation", "homepage": "https://omdsh-dev.github.io/dsh-annotation/", "stars": 101, "forks": 6, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-27T17:55:35Z", "archived": false, "language": "HTML", "license": "MIT", "topics": [ "dsh", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH Web 选中批注插件:选文字 → 批注 → 回车随消息发给模型,回复按批注编号逐条对照", "en": "Selection-annotation plugin for DSH Web: select text → annotate → press Enter to send it along with your message; the model replies to each annotation by number." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json", "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "依赖 cordis 与知名包 ioredis 名称高度相似(编辑距离 2),存在仿冒风险", "file": "package.json" } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "599cd1e68c320da2def27574a57a4e5e786d757b", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "shengsheng90/DSH-taskboard", "name": "DSH-taskboard", "author": "shengsheng90", "description": "Native local Taskboard plugin for DeepSeek Harness. SQLite-backed projects, Agent claim/review, and a native Web UI — no iframe, no second chat runtime.", "repo_url": "https://github.com/shengsheng90/DSH-taskboard", "homepage": "https://www.npmjs.com/package/@shengsheng/dsh-taskboard", "stars": 173, "forks": 7, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-22T07:59:16Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "agent", "cordis", "deepseek-harness", "dsh", "dsh-plugin", "task-management", "taskboard" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "这是 DeepSeek Harness 的原生本地项目任务板插件。SQLite 是任务共享状态的唯一权威;Agent Session、Goal、Workspace、工具、权限和对话历史仍由 Harness 管理。", "en": "Native, local project task management for DeepSeek Harness. SQLite is the sole task authority. Harness Agent Sessions, Goals, Workspaces, tools, permissions, and the Web Client remain the execution and conversation owners." }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/client/index.tsx", "line": 433, "confidence": 1 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/client/controller.ts", "line": 296 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/client/index.tsx", "line": 73 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "dd5455bdeec3a86eaf84482ef2dd42d86c7b88aa", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "worldwonderer/oh-story-dsh", "name": "oh-story-dsh", "author": "worldwonderer", "description": "A DSH plugin for novel writing and short-drama production, powered by Oh Story and Drama Skills.", "repo_url": "https://github.com/worldwonderer/oh-story-dsh", "homepage": "https://github.com/worldwonderer/oh-story-dsh", "stars": 208, "forks": 35, "open_issues": 4, "watchers": 1, "pushed_at": "2026-08-27T14:18:18Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "ai-agents", "creative-writing", "deepseek-harness", "drama-skills", "dsh-plugin", "fiction-writing", "novel-writing", "oh-story", "screenwriting", "short-drama" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "oh-story-dsh 是基于 DeepSeek Harness(DSH)构建的社区插件,将 Oh Story 的小说方法库与 Drama Skills 的短剧生产流程带入 DSH。DSH 管理 Agent、会话、模型、权限和 Chat;插件提供创作 Skills、专业 Roles、项目协议与三栏工作台。" }, "risk_level": "high", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1", "读取凭据类环境变量并发送到网络,可能泄露密钥 @ scripts/native-dsh-smoke.ts" ], "risk_evidence": [ { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "packages/dsh-plugin/src/client/file-activity.ts", "line": 77 }, { "explanation": "监听键盘输入事件", "file": "packages/dsh-plugin/src/client/index.tsx", "line": 635, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/native-dsh-smoke.ts", "line": 31, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/build-dsh-plugin.ts", "line": 70 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "scripts/native-dsh-smoke.ts" }, { "explanation": "访问第三方网络地址(如 attacker.example)", "file": "scripts/native-dsh-smoke.ts", "line": 129 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "020307080c5986aba776997117ffb8139bb2bb2a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "saya-ch/dsh-mobile", "name": "dsh-mobile", "author": "saya-ch", "description": "DeepSeek Harness 移动端适配与安全局域网访问插件,支持 Android App 和手机浏览器。", "repo_url": "https://github.com/saya-ch/dsh-mobile", "homepage": "https://github.com/saya-ch/dsh-mobile", "stars": 164, "forks": 5, "open_issues": 11, "watchers": 0, "pushed_at": "2026-08-28T04:47:21Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "android", "deepseek-harness", "dsh-plugin", "lan", "mobile", "webview" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 是这个轻量、社区维护的 Android WebView 薄壳的显示名称。它不打包另一份 DSH 前端,而是访问插件提供的同一个 HTTPS 地址,因此 App 与手机浏览器会获得相同的 DSH 功能,以及可以实时编辑的 mobile.css 外观和 mobile.js 功能。", "en": "- Continue DSH work from a phone: the same sessions, Workspaces, messages, and tools, in real time." }, "risk_level": "high", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在 Base64 解码行为", "file": "src/client.ts", "line": 282, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/gateway.ts", "line": 852, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "src/gateway.ts", "line": 1374, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/native-mobile.ts", "line": 166, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/cli.ts", "line": 62 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/client.ts", "line": 233 }, { "explanation": "访问第三方网络地址(如 gateway.invalid)", "file": "src/http-security.ts", "line": 36 }, { "explanation": "访问第三方网络地址(如 dsh.home.arpa、harness.example、user)", "file": "tests/config-network.test.ts", "line": 36 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "218cd8b470cdbd43fc44db2219fd950ab3d743b9", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "wssfk12138/dsh-damage-pulse", "name": "dsh-damage-pulse", "author": "wssfk12138", "description": "DeepSeek Harness token balance monitor with game-style damage pulse animations", "repo_url": "https://github.com/wssfk12138/dsh-damage-pulse", "homepage": "https://github.com/wssfk12138/dsh-damage-pulse", "stars": 138, "forks": 2, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-28T02:50:08Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "balance-monitor", "damage-animation", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "token-monitor", "token-usage" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH(DeepSeek Harness)扣血式 Token 余额监控插件:每次产生 token 消耗,余额数字都会受击回弹,并飘出红色扣费数值;同时提供会话用量、精确金额和 DeepSeek 账户实时余额。" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "9a955fc4c1efaf5ea250c7394831ed5d81ca5538", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "RevolutionLA/dsh-dream-skin", "name": "dsh-dream-skin", "author": "RevolutionLA", "description": "DeepSeek Harness 换肤 / 壁纸 / 主题包插件 (dsh-plugin) — 8 套 Mirage 主题、每用户强调色、壁纸2.0、主题包导入导出/分享链接、收藏与随机,纯原生 token 系统实现。", "repo_url": "https://github.com/RevolutionLA/dsh-dream-skin", "homepage": "https://github.com/RevolutionLA/dsh-dream-skin", "stars": 124, "forks": 12, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-27T17:23:38Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "dsh-plugin-theme", "skin", "theme", "wallpaper" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "为 DeepSeek Harness 换上一张克制、清透、有质感的「脸」。", "en": "Give DeepSeek Harness a face that's restrained, clear and textured." }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 2251, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "lib/client.js", "line": 2245 }, { "explanation": "存在 Base64 解码行为", "file": "tests/client.persistence.test.cjs", "line": 68, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "tests/client.smoke.test.cjs", "line": 44, "confidence": 1 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/client.js", "line": 11 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "lib/client.js", "line": 1906 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/index.js", "line": 53 }, { "explanation": "访问第三方网络地址(如 x)", "file": "tests/client.persistence.test.cjs", "line": 42 }, { "explanation": "访问第三方网络地址(如 example.com、w3.org、x)", "file": "tests/client.smoke.test.cjs", "line": 47 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "96fe8c5494d626dc322e97475591fdc73fc72771", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "EverMind-AI/SkillCorpus", "name": "SkillCorpus", "author": "EverMind-AI", "description": "Open-source infrastructure that turns scattered SKILL.md files into curated, retrieval-ready agent-skill corpora—with retrieval and evaluation tooling included.", "repo_url": "https://github.com/EverMind-AI/SkillCorpus", "homepage": "https://evermind.ai/skillhub", "stars": 257, "forks": 48, "open_issues": 1, "watchers": 33, "pushed_at": "2026-08-28T04:59:53Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "agent-memory", "agent-skills", "ai-agents", "benchmark", "dataset", "deepseek-harness", "dsh", "dsh-plugin", "embeddings", "hugginface", "information-retrieval", "llm-agents", "llm-evaluation", "long-term-memory", "python", "reranking", "semantic-search", "skill-md", "skill-routing", "vector-search" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "description_i18n": { "zh": "SkillCorpus 是 EverMind 将公开仓库中散落的 SKILL.md 文件转化为可靠 agent 上下文的开源流水线: 它聚合源仓库,执行安全与许可门禁,评估质量,并在 agent 作答前匹配与任务相关的技能。", "en": "SkillCorpus is EverMind's open-source pipeline for turning scattered SKILL.md files from public repositories into reliable agent context. It aggregates sources, applies safety and license gates, evaluates quality, and matches task-specific skills before the" }, "risk_level": "moderate", "risk_notes": [ "读取本地环境配置文件(dotenv .env) @ skillcorpus_plugin/engine-typescript/src/bundle.ts" ], "risk_evidence": [ { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "skillcorpus_plugin/engine-typescript/src/bundle.ts" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.openai.com)", "file": "skillcorpus_plugin/plugin-openclaw/src/config.ts", "line": 144 }, { "explanation": "访问第三方网络地址(如 api.openai.com)", "file": "skillcorpus_plugin/plugin-openclaw/src/config.ts", "line": 60 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f098ca6e47e8bc203a8cdb58b1b128218123447d", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "zhu1090093659/dsh-web-ui", "name": "dsh-web-ui", "author": "zhu1090093659", "description": "Plugin and skin collection for DeepSeek Harness (DSH) Web UI - task board, git graph, right-side panel, remote mobile UI, pet, live token stats, and skin center.", "repo_url": "https://github.com/zhu1090093659/dsh-web-ui", "homepage": "https://gallery.dsh-market.com", "stars": 6325, "forks": 415, "open_issues": 12, "watchers": 7, "pushed_at": "2026-08-28T04:47:12Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "web-ui" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> 一个注册表驱动的桌面伴侣:内置鲸鱼娘,也接受你放入的任何宠物。", "en": " " }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#3", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#4", "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#5", "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68) @ " ], "risk_evidence": [ { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "gallery/styles.js", "line": 36 }, { "explanation": "依赖 js-yaml@4.1.0 存在已知漏洞(GHSA-52cp-r559-cp3m, GHSA-5p4m-2wfm-xmqj, GHSA-h67p-54hq-rp68)", "file": "" }, { "explanation": "访问第三方网络地址(如 schemas.linxin666.org)", "file": "gallery/manifest.js", "line": 6 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "gallery/styles.js", "line": 28 }, { "explanation": "访问第三方网络地址(如 x)", "file": "packages/dsh-aionui-panel/src/host/routes.ts", "line": 505 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e85ddd2275f33f644350703cf1392174234e07b9", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "strukto-ai/mirage", "name": "mirage", "author": "strukto-ai", "description": "The World's First Unified Virtual Filesystem For AI Agents", "repo_url": "https://github.com/strukto-ai/mirage", "homepage": "https://www.strukto.ai/mirage", "stars": 3573, "forks": 259, "open_issues": 111, "watchers": 9, "pushed_at": "2026-08-28T06:19:02Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "agent-sandbox", "agent-tools", "ai-agents", "bash", "claude-code", "dsh", "dsh-plugin", "fuse", "llm-agents", "openai-agents", "python", "typescript", "vfs", "virtual-filesystem" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "依赖 DSH/Cordis 生态包 @deepseek-ai/cordis", "description_i18n": { "zh": "- 一个接口,而不是 N 个 SDK 和 M 个 MCP。 每个服务都使用同一套文件系统语义,管道可以像在本地磁盘上一样跨服务组合。", "en": "- One interface instead of N SDKs and M MCPs. Every service speaks the same filesystem semantics, and pipelines compose across services as naturally as on a local disk." }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ integ/runners/typescript/adapters.ts", "依赖 @modelcontextprotocol/sdk@1.0.0 存在已知漏洞(GHSA-w48q-cv73-mx4w) @ ", "读取本地环境配置文件(dotenv .env) @ examples/typescript/browser/src/gdocs_pkce.ts", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ examples/typescript/runtimes/ssh/ssh.ts" ], "risk_evidence": [ { "explanation": "硬编码敏感凭据(Slack Token)", "file": "integ/runners/typescript/adapters.ts", "line": 1474 }, { "explanation": "硬编码敏感凭据(Slack Token)", "file": "integ/runners/typescript/adapters.ts", "line": 1482 }, { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "integ/runners/typescript/adapters.ts" }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "examples/typescript/browser/src/gdocs_pkce.ts", "line": 97 }, { "explanation": "依赖 @modelcontextprotocol/sdk@1.0.0 存在已知漏洞(GHSA-w48q-cv73-mx4w)", "file": "" }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "examples/typescript/browser/src/gdocs_pkce.ts" }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "examples/typescript/browser/src/gdocs_pkce.ts", "line": 77 }, { "explanation": "访问第三方网络地址(如 accounts.google.com、apache.org、console.cloud.google.com、googleapis.com)", "file": "examples/typescript/browser/src/gdocs_pkce.ts", "line": 6 }, { "explanation": "访问第三方网络地址(如 apache.org)", "file": "examples/typescript/other/custom_resource.ts", "line": 6 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "examples/typescript/runtimes/ssh/ssh.ts" }, { "explanation": "访问第三方网络地址(如 apache.org、example.com)", "file": "integ/runners/typescript/adapters.ts", "line": 6 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "b425d0fcf53165237635050872eb6d32edd7c454", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "ccch1mneyyy/dsh-TUI", "name": "dsh-TUI", "author": "ccch1mneyyy", "description": "DSH 官方公众号收录的 TUI 补位插件:Claude Code 风,鲸鱼顶栏/实时状态/流式思考/双击 Esc 回滚/上下文进度+TPS。npm 一键装。 DSH official WeChat featured TUI plugin — Claude Code style: whale bar, live status, streaming thoughts, double-Esc rollback, context bar + TPS. npm one-click.", "repo_url": "https://github.com/ccch1mneyyy/dsh-TUI", "homepage": "https://dshtui.com/", "stars": 2643, "forks": 134, "open_issues": 79, "watchers": 2, "pushed_at": "2026-08-28T06:34:36Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "claude-code", "coding-agent", "deepseek", "deepseek-harness", "dsh-plugin", "ink", "react", "terminal", "tui" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": ">一个美观且实用的 Claude Code 风格 TUI 插件:像素鲸鱼顶栏、双流光大字、实时工作状态行、思考流式展开、双击 Esc 时间回溯、蓝白上下文进度条 + TPS 仪表。", "en": "dsh-TUI is an interactive terminal front door for DeepSeek Harness. It is mounted as a Cordis plugin and provides a Claude Code-style conversation, tool, session, and fullscreen terminal experience while continuing to use the" }, "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "依赖 lodash-es@4.17.0 存在已知漏洞(GHSA-29mw-wpgm-hmr9, GHSA-35jh-r3h4-6jhm, GHSA-f23m-r3pf-42rh) @ ", "依赖 semver@7.0.0 存在已知漏洞(GHSA-c2qf-rxjj-qqgw) @ ", "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ scripts/verify-update.mjs" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "子进程以 shell 模式启动(spawn(...,{shell:true}))", "file": "scripts/verify-launcher.mjs", "line": 99, "confidence": 1 }, { "explanation": "存在编码转义字符串(疑似混淆)", "file": "src/cc/figures.ts", "line": 89 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/cc/markdown.ts", "line": 430 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/components/AlternateScreen.tsx", "line": 88 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/components/App.tsx", "line": 828 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/components/ClockContext.tsx", "line": 114 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/components/ScrollBox.tsx", "line": 243 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/components/Text.tsx", "line": 264 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "src/ink/ink.tsx", "line": 2066 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 339 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 347 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 407 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 409 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 470 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 472 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 1060 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "src/ink/parse-keypress.ts", "line": 1259 }, { "explanation": "依赖 lodash-es@4.17.0 存在已知漏洞(GHSA-29mw-wpgm-hmr9, GHSA-35jh-r3h4-6jhm, GHSA-f23m-r3pf-42rh)", "file": "" }, { "explanation": "依赖 semver@7.0.0 存在已知漏洞(GHSA-c2qf-rxjj-qqgw)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "bin/dsh-tui.js", "line": 101 }, { "explanation": "访问第三方网络地址(如 example.com)", "file": "scripts/plugin-test-utils.ts", "line": 33 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.example.com)", "file": "scripts/smoke.tsx", "line": 10 }, { "explanation": "访问第三方网络地址(如 api.example.com)", "file": "scripts/smoke.tsx", "line": 136 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.com)", "file": "scripts/verify-plugin-negotiation.ts", "line": 27 }, { "explanation": "访问第三方网络地址(如 gw.example)", "file": "scripts/verify-provider-wizard.mjs", "line": 187 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "scripts/verify-update.mjs" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 env-registry.example.com、lower-registry.example.com、mirror.example.com)", "file": "scripts/verify-update.mjs", "line": 107 }, { "explanation": "访问第三方网络地址(如 env-registry.example.com、lower-registry.example.com、mirror.example.com)", "file": "scripts/verify-update.mjs", "line": 111 }, { "explanation": "访问第三方网络地址(如 sw.kovidgoyal.net)", "file": "src/ink/parse-keypress.ts", "line": 1008 }, { "explanation": "访问第三方网络地址(如 mitchellh.com)", "file": "src/ink/screen.ts", "line": 353 }, { "explanation": "访问第三方网络地址(如 a.com、b.com)", "file": "src/ink/selection.ts", "line": 361 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 ghostty.org、iterm2.com)", "file": "src/ink/terminal.ts", "line": 45 }, { "explanation": "访问第三方网络地址(如 ghostty.org、iterm2.com)", "file": "src/ink/terminal.ts", "line": 64 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f4e302b764afa71596025713b859cbbffcd52a9f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "zhaoolee/notes", "name": "notes", "author": "zhaoolee", "description": "开源版锤子便签,复刻锤科美学,一键Docker私有化部署,支持skill调用,支持dsh plugin,支持多租户,一键生成公众号格式,支持导出便签为图片", "repo_url": "https://github.com/zhaoolee/notes", "homepage": "https://notes.fangyuanxiaozhan.com", "stars": 154, "forks": 5, "open_issues": 2, "watchers": 0, "pushed_at": "2026-08-25T08:16:47Z", "archived": false, "language": "TypeScript", "license": "unknown", "topics": [ "dsh-plugin", "notes", "smartisan" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "| 支持手机版 | 一键发送公众号 | | --- | --- | | | |" }, "risk_level": "high", "risk_notes": [ "【高风险,请自行审计】读取凭据类环境变量并发送到网络,可能泄露密钥 @ server/index.ts", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1", "依赖 multer@2.1.1 存在已知漏洞(GHSA-3p4h-7m6x-2hcm, GHSA-72gw-mp4g-v24j) @ ", "读取本地环境配置文件(dotenv .env) @ frontend/tests/settings-panel.test.ts" ], "risk_evidence": [ { "explanation": "读取凭据类环境变量并发送到网络,可能泄露密钥", "file": "server/index.ts" }, { "explanation": "存在 Base64 解码行为", "file": "backend/tests/api-feedback.test.ts", "line": 254, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "server/index.ts", "line": 951, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "server/index.ts", "line": 2935, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "server/index.ts", "line": 2961, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/App.tsx", "line": 824, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/App.tsx", "line": 857, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/App.tsx", "line": 885, "confidence": 1 }, { "explanation": "依赖 multer@2.1.1 存在已知漏洞(GHSA-3p4h-7m6x-2hcm, GHSA-72gw-mp4g-v24j)", "file": "" }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 cdn、cdn.example.test、example.com、notes.example.invalid)", "file": "backend/tests/api-feedback.test.ts", "line": 206 }, { "explanation": "访问第三方网络地址(如 cdn、cdn.example.test、example.com、notes.example.invalid)", "file": "backend/tests/api-feedback.test.ts", "line": 49 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 example.com、mmbiz.qpic.cn)", "file": "backend/tests/auth-feedback.test.ts", "line": 238 }, { "explanation": "访问第三方网络地址(如 example.com、mmbiz.qpic.cn)", "file": "backend/tests/auth-feedback.test.ts", "line": 154 }, { "explanation": "访问第三方网络地址(如 cdn.example.com、example.com、notes)", "file": "frontend/tests/markdown-rendering.test.ts", "line": 158 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "frontend/tests/settings-panel.test.ts" }, { "explanation": "访问第三方网络地址(如 notes.example.com)", "file": "frontend/tests/settings-panel.test.ts", "line": 507 }, { "explanation": "访问第三方网络地址(如 archive.local、notes.fangyuanxiaozhan.com、w3.org)", "file": "server/index.ts", "line": 292 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 api.weixin.qq.com)", "file": "server/wechat-official.ts", "line": 54 }, { "explanation": "访问第三方网络地址(如 api.weixin.qq.com)", "file": "server/wechat-official.ts", "line": 56 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "e76628622f2361c09c6a7887825d3c9d8e8cd703", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "summer1238/dsh-remote-web-gateway", "name": "dsh-remote-web-gateway", "author": "summer1238", "description": "手机平板远程 DeepSeek Harness:扫码即可继续使用电脑上的 DSH,无需远程桌面 / SSH / 公网 IP,支持一次性配对、Github授权加密登录,独立设备授权与随时撤销,实现远程连接很简单,但安全才是我们所想要的。", "repo_url": "https://github.com/summer1238/dsh-remote-web-gateway", "homepage": "https://github.com/summer1238/dsh-remote-web-gateway", "stars": 155, "forks": 7, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-21T13:38:39Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "cloudflare-tunnel", "deepseek", "deepseek-harness", "developer-tools", "dsh", "dsh-mobile-app", "dsh-model-switch", "dsh-plugin", "mobile", "qr-code", "quick-tunnel", "remote-access", "remote-control" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1" ], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "plugin/scripts/verify-client-boundary.mjs", "line": 140, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "plugin/src/client/mobile/MobileOverlay.tsx", "line": 76, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "plugin/src/client/workspace-browse/MobileDirectoryFlow.tsx", "line": 153, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugin/src/home.ts", "line": 28 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8dbeef3795177e6237974a1dc2c7482bf463a055", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n": {}, "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "lire1131/dsh-undo-savepoint", "name": "dsh-undo-savepoint", "author": "lire1131", "description": "DSH crash-rescue plugin: undo config & plugin-code changes, secret-safe snapshots, one-click SAFE MODE, plus offline CLI/GUI that work even when DSH won't boot.", "repo_url": "https://github.com/lire1131/dsh-undo-savepoint", "homepage": "https://github.com/lire1131/dsh-undo-savepoint", "stars": 131, "forks": 5, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-28T01:27:25Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "backup", "crash-recovery", "deepseek-harness", "dsh", "dsh-plugin", "powershell", "rollback", "snapshot", "undo", "windows" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH 崩溃急救插件:配置与插件代码一键回滚、快照密钥脱敏、一键安全模式,DSH 起不来时也能用(离线 CLI/GUI)。", "en": "DSH crash-rescue plugin: undo config & plugin-code changes, secret-safe snapshots, one-click SAFE MODE, plus offline CLI/GUI that work even when DSH won't boot." }, "risk_level": "high", "risk_notes": [ "读取本地环境配置文件(dotenv .env) @ lib/client.js" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 883, "confidence": 1 }, { "explanation": "读取本地环境配置文件(dotenv .env)", "file": "lib/client.js" }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "lib/client.js", "line": 219 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "lib/client.js", "line": 286 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dsh.local)", "file": "lib/index.js", "line": 53 }, { "explanation": "访问第三方网络地址(如 dsh.local)", "file": "lib/index.js", "line": 2596 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "tools/e2e-watch.mjs", "line": 7 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8e278b9e22d31b8b381b064157e59b45875c141c", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z" }, { "id": "volcengine/ark-cli", "name": "ark-cli", "author": "volcengine", "description": "The fastest way to put Volcengine Ark in your terminal and your AI agent — go from prompt to generated media, multimodal answer, or deployed endpoint in a single command, no API glue code.", "repo_url": "https://github.com/volcengine/ark-cli", "homepage": "https://github.com/volcengine/ark-cli", "stars": 111, "forks": 10, "open_issues": 8, "watchers": 1, "pushed_at": "2026-08-27T15:34:22Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "ai-agent", "ai-skills", "ark", "cli", "doubao", "dsh-plugin", "llm", "multimodal", "text-to-image", "text-to-video", "volcengine" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "给你的 AI Agent 赋予火山方舟的全部能力" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "访问第三方网络地址(如 volcengine.com)", "file": "dsh-plugins/ark-managed-agents/package.json", "line": 8 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c7607d6f84a869971718b97df70c664e0a38a317", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-22T07:46:20.467Z", "description_i18n_checked_at": "2026-08-22T09:36:22.739Z" }, { "id": "yjh051108/dsh-routing-suite", "name": "dsh-routing-suite", "author": "yjh051108", "description": "dsh-routing-suite — injector + router-standard kit: install the runtime injector first, then the task-aware reasoning-mode router preset (measured P1-P23).", "repo_url": "https://github.com/yjh051108/dsh-routing-suite", "homepage": "https://github.com/yjh051108/dsh-routing-suite", "stars": 6917, "forks": 139, "open_issues": 63, "watchers": 17, "pushed_at": "2026-08-24T23:56:40Z", "archived": false, "language": "PowerShell", "license": "unknown", "topics": [ "ai-agents", "cordis", "deepseek-harness", "dsh", "dsh-plugin" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "一个仓库装齐「运行时手术台 + 思维模式路由预设」:先装注入器(免重启运行时管理层), 再用它装配 router-standard 预设(任务感知思维模式路由,P1-P23 实测)。", "en": "One repository for the full stack: the runtime surgery table (dsh-super-injector, restart-free plugin management) plus the reasoning-mode routing presets (dsh-router-standard: task-aware reasoning-mode routing)." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c87f5ba13c9c3ce4aeb5b057fd5cb54f98c42707", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-23T05:43:53.708Z" }, { "id": "vibeinging/dsh-desktop", "name": "dsh-desktop", "author": "vibeinging", "description": "DeepSeek Harness Desktop App: a local AI desktop workspace for DSH Sessions, projects, files, web research, plugins, and Office artifacts.", "repo_url": "https://github.com/vibeinging/dsh-desktop", "homepage": "https://github.com/vibeinging/dsh-desktop", "stars": 632, "forks": 35, "open_issues": 3, "watchers": 0, "pushed_at": "2026-08-27T03:37:01Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "agentic-workflows", "ai-agent", "ai-workbench", "data-analysis", "deepseek-harness", "desktop-app", "dsh", "dsh-plugin", "electron", "local-first", "mcp", "model-context-protocol", "office-automation", "react", "typescript" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "这个私有 Profile Bundle 在不导入、不修改 DSH 源码检出目录的前提下扩展官方 DSH Web Profile。它只持有应用指令上下文,不再注册任何 Tool、页面、模型继承钩子或记忆提供方。它消费按 Session 寻址的 productHost 服务,该服务由 @vibeinging/dsh-work-product-host-ipc 提供;portable 的 @vibeinging/dsh-model-inheritance Bundle 持有父 Agent 到子 Agent 的模型继承", "en": "| Principle | Product contract | Direct benefit | | --- | --- | --- | | Official Web is the only primary interface | The main window loads the official Client graph directly, and desktop UI joins as regular dshClient Bundles | DSH Sessions, settings, and" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json", "package.json 的 postinstall 脚本会在安装/发布时自动执行 @ package.json#1" ], "risk_evidence": [ { "explanation": "package.json 的 postinstall 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "存在 Base64 解码行为", "file": "electron/main.js", "line": 114, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "electron/main.js", "line": 1567, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "electron/main.js", "line": 97, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "electron/main.js", "line": 332, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "electron/main.js", "line": 1478, "confidence": 1 }, { "explanation": "存在疑似混淆内容(长 Base64 块)", "file": "server/src/app/models/index.js", "line": 122 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "electron/main.js", "line": 65 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f695819b6e809ac4747b8d6f75883eba894cf343", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-23T05:43:53.708Z" }, { "id": "ericshang98/Perfect-Web-Clone", "name": "Perfect-Web-Clone", "author": "ericshang98", "description": "Pixel-perfect clones of any webpage. Paste a URL, get a measured Vite + React replica.", "repo_url": "https://github.com/ericshang98/Perfect-Web-Clone", "homepage": "https://github.com/ericshang98/Perfect-Web-Clone", "stars": 258, "forks": 23, "open_issues": 6, "watchers": 1, "pushed_at": "2026-08-22T14:39:08Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "ai-agent", "automation", "dsh", "dsh-plugin", "pixel-perfect", "playwright", "python", "web-cloning" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "完美复刻任意网页。 本仓是测量核心。产品是 Skill:一套 agent harness,一句话 clone 走完整页、带分数的复刻。", "en": "Pixel-perfect clones of any webpage. This repo is the measured core. The product is the skill: an agent harness that turns one clone into a full-page, scored replica." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugin/index.js", "line": 18 }, { "explanation": "访问第三方网络地址(如 vitejs.dev)", "file": "templates/base-project/vite.config.js", "line": 4 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c846c37937a70497d37d082c26c85aa1289a9fa5", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-23T05:43:53.708Z" }, { "id": "EthanYoQ/Invoice-Downloader", "name": "Invoice-Downloader", "author": "EthanYoQ", "description": "InvoiceFlowAI:Windows 与 macOS 发票助手,自动下载邮箱电子发票、OCR 识别、分类归档并生成 Excel 报销汇总;可安装为 DeepSeek Harness 插件。", "repo_url": "https://github.com/EthanYoQ/Invoice-Downloader", "homepage": "https://github.com/EthanYoQ/Invoice-Downloader/releases/latest", "stars": 194, "forks": 19, "open_issues": 1, "watchers": 5, "pushed_at": "2026-08-23T19:07:21Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "dsh-plugin", "dsh-plugin-market", "dsh-plugins", "e-invoice", "e-invoice-automation", "email", "expense-management", "fapiao", "fapiao-helper", "imap", "invoice", "invoice-assistant", "invoice-management", "ocr", "ofd", "python", "reimbursement", "windows" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "如果有帮到你,麻烦动动小手点亮STAR ✨✨", "en": "A desktop invoice assistant for personal work reimbursement: connect QQ Mail / 163 Mail → download PDF/OFD/XML e-invoices and Baiwang invoice links → AI OCR recognition → local archive → Excel reimbursement summary" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "plugins/dsh-invoice-downloader/scripts/prepare-engine.mjs", "line": 97, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "templates/index_app.js", "line": 502, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "templates/index_app.js", "line": 722, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "plugins/dsh-invoice-downloader/src/activate.ts", "line": 46 }, { "explanation": "访问第三方网络地址(如 bigmodel.cn)", "file": "templates/index_app.js", "line": 64 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "f0b1652753539aecaa643b4f82960d6d13473b19", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-23T05:43:53.708Z" }, { "id": "Totoro-qaq/dsh-plugin-bridge", "name": "dsh-plugin-bridge", "author": "Totoro-qaq", "description": "DeepSeek Harness plugin for previewable cross-preset session migration. Fixed-schema handoffs preserve state, source-model intent, and unresolved images; the original session stays untouched.", "repo_url": "https://github.com/Totoro-qaq/dsh-plugin-bridge", "homepage": "https://github.com/Totoro-qaq/dsh-plugin-bridge", "stars": 152, "forks": 8, "open_issues": 2, "watchers": 9, "pushed_at": "2026-08-27T08:13:30Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "context-migration", "cordis", "deepseek-harness", "dsh", "dsh-plugin", "preset-migration", "session-migration" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "在 Web preset 做到一半,想换 Code preset 继续?直接切换会让旧工具组的调用历史留在新组合里。Bridge 先生成一份有界、可编辑的五段交接,再建立干净目标会话;原会话始终不动。", "en": "Halfway through a task and need another tool preset? Switching the produced session in place would leave tool history that belongs to the old assembly. Bridge previews a bounded five-part handoff, opens a clean target, and leaves the original session" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json" ], "risk_evidence": [ { "explanation": "package.json 的 prepack 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/record-demo.mjs", "line": 114, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "lib/cli.js", "line": 104 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "5acea430d6af01f8a180a6b3f6232ca02951bb3b", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-23T05:43:53.708Z" }, { "id": "ZSeven-W/dsh-android", "name": "dsh-android", "author": "ZSeven-W", "description": "DeepSeek Harness plugin for Android — build, run, and interact with a live emulator or USB device stream inside a conversation, driven entirely through adb.", "repo_url": "https://github.com/ZSeven-W/dsh-android", "homepage": "https://github.com/ZSeven-W/dsh-android", "stars": 122, "forks": 9, "open_issues": 0, "watchers": 1, "pushed_at": "2026-08-21T23:26:27Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DSH Android 把一台真实的 Android 设备交给 agent,同时把画面交给你。agent 可以在模拟器或 USB 手机上开流、构建并安装 Gradle 工程、按 resource-id/文本或 OCR 驱动界面、读取 logcat、检查进程与内存;与此同时设备画面实时渲染在侧边栏面板里,你可以直接在视频上点击、拖拽、旋转,并按下 返回 / 主页 / 多任务。没有 image block,也没有录屏文件:可视字节只通过 DSH webserver 提供的签名短时 URL 抵达界面。", "en": "DSH Android gives the agent a real Android device inside the conversation — and gives you the pixels. The agent can start a stream on an emulator or a USB-connected phone, build and install a Gradle project, drive the UI by resource-id/text or by OCR, read" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "scripts/_smoke-harness.mjs", "line": 143, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-adb-smoke.mjs", "line": 40, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-adb-smoke.mjs", "line": 83, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-adb-smoke.mjs", "line": 386, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/dev-adb-smoke.mjs", "line": 551, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/dev-emulator-smoke.mjs", "line": 116, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-routes-static-smoke.mjs", "line": 37, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/dev-routes-static-smoke.mjs", "line": 120, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-tools-smoke.mjs", "line": 35, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-uitree-smoke.mjs", "line": 514, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/dev-uitree-smoke.mjs", "line": 513, "confidence": 1 }, { "explanation": "存在 Base64 解码行为", "file": "scripts/dev-vision-smoke.mjs", "line": 35, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "scripts/dev-vision-smoke.mjs", "line": 143, "confidence": 1 }, { "explanation": "使用屏幕/画面采集能力", "file": "src/android-host.ts", "line": 415, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/android-device-menu.tsx", "line": 118, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 x)", "file": "scripts/_smoke-harness.mjs", "line": 80 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "scripts/dev-logs-smoke.mjs", "line": 33 }, { "explanation": "访问第三方网络地址(如 evil.example)", "file": "scripts/dev-routes-static-smoke.mjs", "line": 165 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8c1d19a0019f2fbf65265ac8a09225d0b2fdf8c4", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-24T04:06:41.232Z" }, { "id": "pengyue-polaron/deepseek-harness-genui", "name": "deepseek-harness-genui", "author": "pengyue-polaron", "description": "Task-specific React apps for DeepSeek Harness with state carried into the next Agent turn", "repo_url": "https://github.com/pengyue-polaron/deepseek-harness-genui", "homepage": "https://github.com/pengyue-polaron/deepseek-harness-genui", "stars": 107, "forks": 11, "open_issues": 0, "watchers": 5, "pushed_at": "2026-08-27T07:57:04Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "deepseek-harness", "dsh", "dsh-plugin", "generative-ui", "genui", "mcp", "react" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "有些任务用文字来回描述很别扭。DeepSeek Harness GenUI 让 Agent 可以为当前任务生成一个聚焦界面,用来讲清复杂关系,或收集难以用一段话表达的用户选择。", "en": "Some tasks are awkward in text. DeepSeek Harness GenUI lets an Agent create a focused interface for the current task: something that explains a difficult relationship or collects a complex user response." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/client/index.tsx", "line": 294, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "src/client/index.tsx", "line": 326, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 1161, "confidence": 1 }, { "explanation": "监听键盘输入事件", "file": "lib/client.js", "line": 1192, "confidence": 1 } ], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "59fa47b01281bf34dd1234f153ae60d2dc30a759", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-24T04:06:41.232Z" }, { "id": "anywhere-labs/dsh-desktop", "name": "dsh-desktop", "author": "anywhere-labs", "description": "为 DeepSeek Harness (DSH) 插件生态打造的现代化桌面端解决方案。万物皆「插件」,桌面本身也是「插件」。", "repo_url": "https://github.com/anywhere-labs/dsh-desktop", "homepage": "https://dshdesktop.cn", "stars": 21324, "forks": 1036, "open_issues": 253, "watchers": 50, "pushed_at": "2026-08-28T04:30:09Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "cordis", "cordis-plugin", "deepseek", "deepseek-harness", "desktop", "dsh", "dsh-plugin", "dsh-plugin-desktop" ], "category": "plugin", "kind": "dsh-client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.client manifest", "description_i18n": { "zh": "这是旧链接的兼容入口。当前中文产品 README 是 README.md,完整文档索引在 docs/README.md。", "en": "Current release installers support Windows x64 and macOS Universal. No extra environment is needed — download, install, and start using it with one click." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#2", "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#3", "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c) @ " ], "risk_evidence": [ { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "dsh-community-fabric/scripts/verify-docs.mjs", "line": 133, "confidence": 1 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "dsh-community-market/scripts/verify-docs.mjs", "line": 97, "confidence": 1 }, { "explanation": "依赖 pnpm@11.7.0 存在已知漏洞(GHSA-qrv3-253h-g69c)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "dsh-plugin-desktop/src/main.ts", "line": 451 }, { "explanation": "访问第三方网络地址(如 catalog.example、json-schema.org、plugins.example.org、user)", "file": "dsh-community-market/scripts/verify-docs.mjs", "line": 126 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com)", "file": "dsh-community-market/src/adapters/dsh-1024store.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 api.dshfind.com)", "file": "dsh-community-market/src/adapters/dshfind.ts", "line": 8 }, { "explanation": "访问第三方网络地址(如 deepseek1024.com、dshfind.com)", "file": "dsh-community-market/src/catalog/service.ts", "line": 36 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "efc72d4fa8da2d8ef1e11fcf7d40bf2fe3ab409a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z" }, { "id": "zhu1090093659/dsh-web", "name": "dsh-web", "author": "zhu1090093659", "description": "DeepSeek Harness(DSH)Web 插件聚合生态包 · 一切皆插件,创意工坊分发", "repo_url": "https://github.com/zhu1090093659/dsh-web", "homepage": "https://dsh-market.com", "stars": 6325, "forks": 415, "open_issues": 12, "watchers": 7, "pushed_at": "2026-08-28T04:47:12Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "cordis", "deepseek-harness", "dsh", "dsh-plugin", "dsh-web", "dsh-web-ui" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "这里只放一类设计文档。Agent Note(Agent 决策记录)记录一个影响本仓库的决策或提案——变更背后的 why 与 放弃了什么,即代码和普通文档承载不了的部分。本文件定义 Agent Note 的存放位置、写作时机与文件内格式。", "en": " " }, "risk_level": "high", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "market/telemetry-view/src/index.js", "line": 34, "confidence": 1 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "market/shell/packages/dsh-web-tryon/src/index.ts", "line": 216 }, { "explanation": "访问第三方网络地址(如 dsh-market.com)", "file": "market/telemetry-view/src/index.js", "line": 17 }, { "explanation": "访问第三方网络地址(如 challenges.cloudflare.com、dsh-market.com、rfc-editor.org)", "file": "market/worker/src/index.js", "line": 49 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/dsh-doctor/src/index.ts", "line": 62 }, { "explanation": "读取环境变量并访问第三方地址,需确认未外发敏感信息(如 dsh-market.com)", "file": "packages/dsh-market/lib/index.js", "line": 68 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "720a71f30610d3c7f91cd1a7ca87f9166ca5c15f", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z" }, { "id": "agentscope-ai/ReMe", "name": "ReMe", "author": "agentscope-ai", "description": "ReMe: Memory Management Kit for Agents - Remember Me, Refine Me.", "repo_url": "https://github.com/agentscope-ai/ReMe", "homepage": "https://reme.agentscope.io/", "stars": 3361, "forks": 292, "open_issues": 24, "watchers": 19, "pushed_at": "2026-08-28T05:27:21Z", "archived": false, "language": "Python", "license": "Apache-2.0", "topics": [ "agent", "ai-agents", "dsh-plugin", "memory", "memoryscope", "rag", "reme" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "- Memory as File, File as Memory:以带 frontmatter 和 wikilink 的 Markdown 作为记忆节点,用户和 Agent 都能直接查看、编辑、移动和备份。", "en": "- Memory as File, File as Memory: Markdown files with frontmatter and wikilinks serve as memory nodes that both users and agents can inspect, edit, move, and back up directly." }, "risk_level": "high", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json#1", "依赖 dompurify@3.2.6 存在已知漏洞(GHSA-39q2-94rc-95cp, GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm) @ " ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "github-pages/src/main.js", "line": 438, "confidence": 1 }, { "explanation": "依赖 dompurify@3.2.6 存在已知漏洞(GHSA-39q2-94rc-95cp, GHSA-55q2-fjhq-7xh7, GHSA-76mc-f452-cxcm)", "file": "" }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "github-pages/src/main.js", "line": 57 }, { "explanation": "访问第三方网络地址(如 contextlab.alibaba-inc.com)", "file": "skills/dingtalk-message/package.json", "line": 6 }, { "explanation": "访问第三方网络地址(如 reme.agentscope.io)", "file": "packages/typescript/src/dsh/client/status-page.tsx", "line": 507 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/typescript/src/dsh/config.ts", "line": 72 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "626c850ccb2c25be92a9ce575886a85f54e8683a", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z" }, { "id": "Unclecheng-li/DeepSec", "name": "DeepSec", "author": "Unclecheng-li", "description": "DeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC. ", "repo_url": "https://github.com/Unclecheng-li/DeepSec", "homepage": "https://unclecheng-li.github.io/deepsec.com/", "stars": 349, "forks": 24, "open_issues": 5, "watchers": 2, "pushed_at": "2026-08-24T15:04:51Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "agent", "ai", "ai-agents", "aisecurity", "cybersecurity", "dsh", "dsh-bundle", "dsh-plugin", "dsh-plugin-desktop", "dsh-plugin-market", "dsh-plugin-verify", "dsh-plugins", "dsh-skill", "hacker", "plugin", "redteam", "security", "vscode", "vulnerabilities", "vulnerability" ], "category": "plugin", "kind": "dsh-bundle", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle manifest", "description_i18n": { "zh": "DeepSec 是由 VibeGuard 进化而来的 AI 安全平台,将 Shield(AI 代码安全审计)与 Spear(授权渗透测试引擎)统一到一套 CLI、一个 TUI 终端工作台和一组 IDE 插件中。", "en": "DeepSec is an AI security platform evolved from VibeGuard. It unifies Shield (AI code security audit) and Spear (authorized penetration testing engine) into a single CLI, a TUI terminal workbench, and a set of IDE plugins." }, "risk_level": "high", "risk_notes": [ "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ src/cli.ts" ], "risk_evidence": [ { "explanation": "读取环境变量(可能包含敏感信息)", "file": "dsh-plugins/deepsec-shield/lib/cli.js", "line": 36 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "src/cli.ts" }, { "explanation": "访问第三方网络地址(如 crates.io、dashboard.example.com、guard.example.com、index.golang.org)", "file": "src/cli.ts", "line": 2343 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "fff031fc01fb36b95348214c8ee359f6ede8aa8b", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z" }, { "id": "zenstory-ai/oh-story-dsh", "name": "oh-story-dsh", "author": "zenstory-ai", "description": "A DSH plugin for novel writing and short-drama production, powered by Oh Story and Drama Skills.", "repo_url": "https://github.com/zenstory-ai/oh-story-dsh", "homepage": "https://github.com/zenstory-ai/oh-story-dsh", "stars": 208, "forks": 35, "open_issues": 4, "watchers": 1, "pushed_at": "2026-08-27T14:18:18Z", "archived": false, "language": "Python", "license": "MIT", "topics": [ "ai-agents", "creative-writing", "deepseek-harness", "drama-skills", "dsh-plugin", "fiction-writing", "novel-writing", "oh-story", "screenwriting", "short-drama" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "oh-story-dsh 是基于 DeepSeek Harness(DSH)构建的社区插件,将 Oh Story 的小说方法库与 Drama Skills 的短剧生产流程带入 DSH。DSH 管理 Agent、会话、模型、权限和 Chat;插件提供创作 Skills、专业 Roles、项目协议与三栏工作台。" }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepack 脚本会在安装/发布时自动执行 @ package.json#1" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "packages/dsh-plugin/src/client/index.tsx", "line": 624, "confidence": 1 }, { "explanation": "使用 String.fromCharCode 构造字符串(常见于混淆代码)", "file": "packages/dsh-plugin/src/client/file-activity.ts", "line": 81 }, { "explanation": "通过子进程 shell 执行命令(child_process.exec/execSync)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/cdp-utils.js", "line": 88, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/cdp-utils.js", "line": 28 }, { "explanation": "访问第三方网络地址(如 ciweimao.com)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/ciweimao-rank-scraper.js", "line": 22 }, { "explanation": "访问第三方网络地址(如 fanqienovel.com)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/fanqie-rank-scraper.js", "line": 248 }, { "explanation": "访问第三方网络地址(如 jjwxc.net)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/jjwxc-rank-scraper.js", "line": 29 }, { "explanation": "访问第三方网络地址(如 m.qidian.com、qidian.com)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/qidian-rank-scraper.js", "line": 34 }, { "explanation": "访问第三方网络地址(如 qimao.com)", "file": "packages/knowledge/oh-story/skills/story-long-scan/scripts/qimao-rank-scraper.js", "line": 24 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "09a9362214d9f1e81dc76fc88017bbdb65e78850", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z", "description_i18n_checked_at": "2026-08-25T05:41:37.358Z" }, { "id": "dream-num/dsh-univer-office", "name": "dsh-univer-office", "author": "dream-num", "description": "Preview, create, edit office spreadsheets, docs & slides inside DeepSeek Harness. Power by Univer.", "repo_url": "https://github.com/dream-num/dsh-univer-office", "homepage": "https://univer.ai", "stars": 181, "forks": 18, "open_issues": 2, "watchers": 1, "pushed_at": "2026-08-27T03:28:54Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "deepseek-harness", "deepseek-harness-plugin", "dsh-plugin", "office", "office-harness" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> 让 DeepSeek Harness 直接创建、编辑、检查和交付表格、文档、幻灯片、多维表格与画布。", "en": "> Give DeepSeek Harness the ability to create, edit, inspect, and deliver spreadsheets, documents, presentations, databases, and canvases." }, "risk_level": "high", "risk_notes": [ "读取本地凭据文件(如 .ssh/.aws/.npmrc) @ scripts/verify-public-runtime-dependencies.mjs" ], "risk_evidence": [ { "explanation": "监听键盘输入事件", "file": "src/client/components/review-panel.tsx", "line": 57, "confidence": 1 }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/gateway-app/main.ts", "line": 5 }, { "explanation": "读取本地凭据文件(如 .ssh/.aws/.npmrc)", "file": "scripts/verify-public-runtime-dependencies.mjs" } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "105cab9053153d338236d54b2ea94d59a56a17f7", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-25T04:01:02.743Z" }, { "id": "chainbase-labs/Agentkey", "name": "Agentkey", "author": "chainbase-labs", "description": "Connect your AI agent to the world — Web search, Social media, Crypto & On-chain data. One plugin, zero extra config.", "repo_url": "https://github.com/chainbase-labs/Agentkey", "homepage": "https://agentkey.app", "stars": 606, "forks": 64, "open_issues": 4, "watchers": 1, "pushed_at": "2026-08-24T16:55:44Z", "archived": false, "language": "Shell", "license": "Apache-2.0", "topics": [ "dsh-plugin", "gemini-cli-extension" ], "category": "plugin", "kind": "code", "official": false, "compatibility": "compatible", "compatibility_reason": "源码/路径引用 @deepseek-ai/dsh 或 @deepseek-ai/cordis", "description_i18n": { "zh": "| 你对 Agent 说 | 没装会怎样 | 装了 AgentKey 后 | | ----------------------------------------------------- | ----------------------- | ---------------------------------- | | 🐦 马斯克最近在推特上在说什么 | 看不了,搜不到完整推文 | 一次拉全相关推文,帮你总结结论 |", "en": "| You ask your agent to... | Without AgentKey | With AgentKey | | ------------------------------------------------------ | ----------------------------- | ---------------------------------------------- | | 🐦 What has Musk been saying on Twitter lately? |" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "访问第三方网络地址(如 agentkey.app)", "file": "package.json", "line": 7 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "8e93c67a3362a8ec088896a71e3ef228af868932", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-26T04:04:18.409Z" }, { "id": "Minglink/dsh-infinite-gen-2", "name": "dsh-infinite-gen-2", "author": "Minglink", "description": "DeepSeek 专用破甲插件「无限二代」dsh-infinite-gen-2 — armor-breaking plugin for DeepSeek稳定化破甲提示词,求 Star 收藏 ⭐", "repo_url": "https://github.com/Minglink/dsh-infinite-gen-2", "homepage": "https://deepseek.stream/plugins/dsh-infinite-gen-2", "stars": 564, "forks": 26, "open_issues": 4, "watchers": 0, "pushed_at": "2026-08-26T06:27:28Z", "archived": false, "language": "PowerShell", "license": "MIT", "topics": [ "armor-breaking", "deepseek", "deepseek-harness", "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> ## 💬 DeepSeek 破甲交流群 2 群 > > ### 👉 QQ 群号:971281629" }, "risk_level": "low", "risk_notes": [], "risk_evidence": [], "privacy_risk": false, "privacy_notes": [], "security_notes": [], "reviewed_commit": "c72d2d178021d51547d08d70d33393324e3d58fa", "source": "discovered", "review_status": "approved", "reviewed_at": "2026-08-26T04:04:18.409Z", "description_i18n_checked_at": "2026-08-26T05:44:35.871Z" }, { "id": "GraySilver/dsh-evolve-modes", "name": "dsh-evolve-modes", "author": "GraySilver", "description": "让 Agent 的工作方式可组合、可审查、可持续改进,最终实现 Agent Self Evoling。 DeepSeek Harness Web plugin with composable task controls and isolated, human-reviewed self-evolution.", "repo_url": "https://github.com/GraySilver/dsh-evolve-modes", "homepage": "https://www.npmjs.com/package/@graysilver/dsh-evolve-modes", "stars": 152, "forks": 8, "open_issues": 1, "watchers": 6, "pushed_at": "2026-08-26T13:53:10Z", "archived": false, "language": "TypeScript", "license": "MIT", "topics": [ "acceptance-review", "agent-review", "ai-agents", "deepseek-harness", "dsh", "dsh-plugin", "plan-mode", "prompt-engineering" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "> 让 Agent 的工作方式可组合、可审查、可持续改进,最终实现 Agent Self Evoling。", "en": "> Make every agent turn intentional." }, "risk_level": "low", "risk_notes": [], "risk_evidence": [ { "explanation": "存在 Base64 解码行为", "file": "lib/client.js", "line": 3, "confidence": 1 }, { "explanation": "访问第三方网络地址(如 json-schema.org)", "file": "lib/client.js", "line": 64 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "d1f717c8e7e6deae21e6f8e22c728c8572999cc9", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-26T04:04:18.409Z" }, { "id": "PerryLink/dsh-auto-review", "name": "dsh-auto-review", "author": "PerryLink", "description": "Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).", "repo_url": "https://github.com/PerryLink/dsh-auto-review", "homepage": "https://www.npmjs.com/package/dsh-auto-review", "stars": 112, "forks": 1, "open_issues": 0, "watchers": 0, "pushed_at": "2026-08-26T14:46:10Z", "archived": false, "language": "TypeScript", "license": "Apache-2.0", "topics": [ "ai-safety", "approval", "auto-review", "cordis", "deepseek", "deepseek-harness", "dsh", "dsh-plugin", "llm", "sandbox", "second-model", "subagent" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "DeepSeek Harness 的第二模型 AI 审批 —— 一个只读审查子代理在审批链上做出允许/拒绝决策,默认失败关闭。", "en": "Second-model AI approval for DeepSeek Harness — a read-only reviewer subagent decides allow/deny on the approval chain, fail-closed by default." }, "risk_level": "moderate", "risk_notes": [ "package.json 的 prepare 脚本会在安装/发布时自动执行 @ package.json", "依赖 yaml@2.8.2 存在已知漏洞(GHSA-48c2-rrv3-qjmp) @ " ], "risk_evidence": [ { "explanation": "package.json 的 prepare 脚本会在安装/发布时自动执行", "file": "package.json" }, { "explanation": "子进程以 shell 模式启动(spawn(...,{shell:true}))", "file": "scripts/smoke-package.mjs", "line": 79, "confidence": 1 }, { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "src/eval/report.ts", "line": 111, "confidence": 1 }, { "explanation": "依赖 yaml@2.8.2 存在已知漏洞(GHSA-48c2-rrv3-qjmp)", "file": "" }, { "explanation": "读取环境变量(可能包含敏感信息)", "file": "src/eval/cli.ts", "line": 279 } ], "privacy_risk": true, "privacy_notes": [], "security_notes": [], "reviewed_commit": "fb1031196c0041e759bc81abc76f7667fef09fd1", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-26T04:04:18.409Z" }, { "id": "e2mcc/dsh-popout-sidebar", "name": "dsh-popout-sidebar", "author": "e2mcc", "description": "A sidebar can pop out a separate browser tab (drag it to another monitor)", "repo_url": "https://github.com/e2mcc/dsh-popout-sidebar", "homepage": "https://github.com/e2mcc/dsh-popout-sidebar", "stars": 129, "forks": 2, "open_issues": 1, "watchers": 0, "pushed_at": "2026-08-20T16:51:38Z", "archived": false, "language": "JavaScript", "license": "MIT", "topics": [ "dsh-plugin" ], "category": "plugin", "kind": "dsh-bundle+client", "official": false, "compatibility": "compatible", "compatibility_reason": "存在 DSH 插件注册文件:package.json 声明 dsh.bundle / dsh.client manifest", "description_i18n": { "zh": "可弹出式侧边栏:侧边栏展示产物与文件树,支持多种文件预览形式;并可弹出为独立浏览器标签页(可拖至另一显示器上更大更清晰的观看);兼容其他 sidebar 插件,可以同时显示。" }, "risk_level": "moderate", "risk_notes": [ "使用动态代码执行(全局 eval / new Function) @ src/index.js:15", "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发) @ src/client.js:451", "访问第三方网络地址(如 w3.org) @ src/host/page.js:237" ], "risk_evidence": [ { "explanation": "使用动态代码执行(全局 eval / new Function)", "file": "src/index.js", "line": 15, "confidence": 1 }, { "explanation": "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "file": "src/client.js", "line": 451 }, { "explanation": "访问第三方网络地址(如 w3.org)", "file": "src/host/page.js", "line": 237 } ], "privacy_risk": true, "privacy_notes": [ "读取浏览器 Cookie/存储(未发现值进入请求,需自行确认不外发)", "访问第三方网络地址(如 w3.org)" ], "security_notes": [ "使用动态代码执行(全局 eval / new Function)" ], "reviewed_commit": "e9a8458cb65c0a863ba5c86bf4ad272b1e0e3162", "source": "discovered", "review_status": "flagged", "reviewed_at": "2026-08-27T14:14:24.288Z", "description_i18n_checked_at": "2026-08-27T22:55:38.264Z" } ] }