Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-plugin-gate
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:863683348/dsh-plugin-gate
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Installation safety gate & data-protection guard for DeepSeek Harness — 60 static signature rules (31 high / 24 medium / 5 low) scan plugin sources for malicious install scripts, credential theft, obfuscation and network callbacks before you run dsh plugin add, and 12 destructive-command patterns plus workspace-boundary checks stop rm -rf-class accidents before they happen.
The plugin marketplace is growing fast (thousands of entries), and malicious code mixed into a plugin is only a matter of time. dsh-plugin-gate gives the agent a gate_scan tool that inspects a plugin source — a local directory or an npm tarball — for the classic malware shapes:
| Domain | What it checks |
|---|---|
| Scripts | npm lifecycle scripts (pre/install/postinstall), exec/spawn/shell:true, curl |
| Obfuscation | eval / new Function / vm.runIn*, hex-escape floods, base64 blobs, char-array packing |
| Permissions | credential env reads (OPENAI_API_KEY etc.), ssh/aws/npmrc file reads, writes to system/home/dotfile paths, chmod 777, sandbox-escalation requests |
| Network | external URLs & hosts, fetch/axios/socket/WebSocket/DNS APIs, cloud-metadata endpoints (169.254.169.254), Discord/Telegram/Slack webhooks, .onion, read-then-send exfiltration shape |
| Secrets | hardcoded sk- keys, ghp_ tokens, AWS keys, private key blocks, bearer tokens |
| Supply chain | exact-version direct dependencies checked against Google OSV (ranges and official @deepseek-ai packages skipped; configurable, offline-degrades) |
The gate is read-only: it never executes scanned code and never writes files.
Compatibility
Tool schemas are validated against the @deepseek-ai/dsh-tools value-schema DSL at plugin load (checked against dsh-tools 0.1.0-rc.6 and 0.1.1-rc.2). Earlier releases used JSON-Schema required at the root of output.schema and closed nested objects without declared properties, which made the host abort the whole profile boot with unsupported JSON schema: schema.required is not supported by the value schema DSL and could reject the tool's own results. Current releases fix both; if an affected version left your DSH unable to start, remove the plugin from the profile (or upgrade) — no data is lost.
Install
In your DSH profile:
dsh plugin --profile <profile> add dsh-plugin-gate
# or add the bundle patch manually:
# dsh --profile <profile> --patch ./node_modules/dsh-plugin-gate/cordis.patch.yml
Usage
Ask the agent to scan a plugin before installing it (the plugin also injects prompt guidance that tells the agent to do this automatically):
gate_scan target: "npm:dsh-plugin-some-package"
gate_scan target: "npm:dsh-plugin-some-package@1.2.3" # pinned version
gate_scan target: "./downloaded-plugin" # local directory
v1.3 - Baselines & reports
After a fix, prove the risk is gone — and that nothing new appeared:
gate_diff target: "npm:dsh-plugin-some-package" # new / resolved / changed / unchanged vs the stored baseline
gate_diff target: "./downloaded-plugin" update: true # store this scan as the new baseline
Findings are fingerprinted by rule + severity + file (line shifts do not create false "new" entries). The baseline lives at .dsh/gate-baseline.json inside the session workspace.
Attach evidence to a ticket, PR or CI job:
gate_report target: "npm:dsh-plugin-some-package" # Markdown report
gate_report target: "./plugin" format: "json" write: true # JSON report written to .dsh/gate-report.json
v1.1 - Data-protection guard
Before any destructive operation, ask the agent to evaluate it with gate_guard (also injected into prompt guidance):
gate_guard command: "rm -rf ./node_modules"
gate_guard path: ".dsh-memory-setup/memory.json" action: "delete"
- BLOCK - device/root-level destruction (rm -rf /, rmdir /s /q, format, dd to a block device, mkfs, drive-root deletes): refuse.
- WARN - recursive/force deletes, targets outside the workspace, or critical files (memory.json, .git, ...): confirm the exact target first.
- PASS - no destructive signature detected.
Result shape:
{
"verdict": "BLOCK" | "WARN" | "PASS",
"score": 254,
"summary": { "high": 0, "medium": 1, "low": 3, "categories": { "network": 4 } },
"network": { "hosts": [...], "unallowlisted": [...], "readAndSendFiles": [...] },
"hits": [{ "rule": "fetch_call", "category": "network", "severity": "medium",
"file": "lib/index.js", "line": 12, "evidence": "...", "hint": "..." }],
"recommendations": [...]
}
Verdict semantics
- BLOCK — at least one high-severity signature. Do not install until the maintainer ships a clean rebuild you can scan again.
- WARN — medium-severity patterns that need manual review (network I/O, home-path writes, base64 blobs). Inspect every hit in context.
- PASS — no risky signatures. Heuristic only — keep normal caution with unknown maintainers.
Context-aware rules: exec()/execSync() hits are downgraded when the file does not import child_process (typical RegExp#exec false positive); code-context rules (exec, eval, curl|sh, PowerShell…) are downgraded to low when found in comments or documentation (examples, not behavior) — while secrets and webhooks stay flagged even in comments. Dependencies installed from git/http/file URLs are flagged as risky_dependency, and >4000-char minified lines as minified_line (low).
Configuration
| Key | Default | Meaning |
|---|---|---|
maxFiles |
1000 | hard cap on scanned files per directory walk |
maxFileBytes |
2 MiB | per-file text cap |
includeNodeModules |
false | descend into node_modules |
maxTarballBytes |
32 MiB | npm tarball download cap |
allowlistHosts |
[] | hosts never listed as unallowlisted |
osvCheck |
true | query Google OSV for known vulnerabilities on exact-version deps |
osvMaxDeps |
8 | max exact-version direct deps checked |
osvTimeoutMs |
10000 | per-dep OSV query timeout |
promptSection |
true | inject agent guidance |
sectionOrder |
5 | prompt section order |
Development
node --check lib/*.js
node test/rules.test.mjs # main-module mode (node --test is blocked in the DSH sandbox)
node test/scan.test.mjs
Pure logic lives in lib/rules.js (signatures), lib/targz.js (in-memory tar.gz), lib/scan.js (orchestration + verdict). The Cordis plugin is lib/index.js.
Security
The gate never executes scanned content. It is a heuristic signature scanner — it can miss novel malware and over-flag innocent code. Review BLOCK/WARN hits yourself; see SECURITY.md.
License
MIT
Roadmap
See ROADMAP.md — next five versions (v1.3.0 – v1.7.0): baselines & reports, configurable rules, pre-install interception, dependency SBOM, team policy & CI.
Links
More in this category
toby-bridges/api-relay-audit★ 865
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 655
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 571
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 219
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 164
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 115
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.