DeepSeek Harness 插件

863683348/dsh-plugin-scorecard

Star 数 ★ 0 分类 插件市场与管理 收录于 2026-08-19

DSH 插件生态体检评分卡:同步 dsh-plugin 目录,对任意插件做质量与安全审计(0-100 分、A-D 等级、安全一票否决),榜单、搜索与历史评分曲线(目录持久化)。

安装

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:863683348/dsh-plugin-scorecard

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

DSH 插件体检评分卡:质量与安全审计、榜单与搜索。Quality & security scorecard, rankings and search for the dsh-plugin ecosystem.

一个 Cordis 插件,把「哪些插件值得装、哪个有风险」变成可执行的评分与报告:

  • plugin_sync_catalog 同步 GitHub dsh-plugin topic 目录(star 排序,可配上限)
  • plugin_audit <名称> 对单个插件出体检报告:0-100 分、A/B/C/D 等级、信号明细、证据链;高危安装脚本一票否决(🚨 封顶 30 分)
  • plugin_top 榜单(按评分 / star / 最近更新)
  • plugin_search <关键词> 语义搜索目录
  • plugin_history <名称> 历史评分曲线(时间/分数/等级、趋势方向)
  • plugin_export 导出目录与评分开放数据 JSON(默认 .dsh/scorecard-export.json)

Compatibility

Tool schemas are validated against the @deepseek-ai/dsh-tools value-schema DSL at plugin load (checked against dsh-tools 0.1.0-rc.6 and 0.1.1-rc.2). Earlier releases used JSON-Schema required at the root of output.schema and closed nested objects without declared properties, which made the host abort the whole profile boot with unsupported JSON schema: schema.required is not supported by the value schema DSL and could reject the tool's own results. Current releases fix both; if an affected version left your DSH unable to start, remove the plugin from the profile (or upgrade) — no data is lost.

评分模型

维度 满分 说明
维护活跃度 30 最近 push、star 量、是否归档
文档质量 25 README、描述、许可证、标签
npm 可装性 15 npm 包存在性、更新度、周下载
安全 30 安装脚本高危模式(curl

等级:A ≥80 · B ≥60 · C ≥40 · D <40。命中高危模式 → 封顶 30 分 + 🚨 不推荐。

安装

dsh plugin add dsh-plugin-scorecard

或编辑 profile 的组合:cordis.patch.yml 已内置 insert 条目(id: dsh-plugin-scorecard)。

配置(可选)

字段 默认 说明
githubToken "" GitHub Token,提升 API 限额(无 Token 时 60 次/小时)
securityScan true 是否扫描安装脚本
cacheTtlMs 900000 目录缓存 TTL(含工作区文件缓存)
catalogFile .dsh/scorecard-catalog.json 目录持久化文件(会话工作区内)
historyFile .dsh/scorecard-history.json 评分历史文件(会话工作区内)
historyMaxEntries 100 历史快照条数上限
exportFile .dsh/scorecard-export.json 开放数据导出文件(会话工作区内)
maxCatalogSize 200 每次同步的仓库数上限

开发

node --check lib/index.js
node test/scorer.test.mjs   # 主模块方式(沙箱里勿用 node --test)
node test/format.test.mjs

路线图

  • v0.2 ✅:目录持久化(JSON 缓存)+ 历史评分曲线(plugin_history)
  • v0.3 ✅:目录增量同步(新增/更新/未变/移出)+ 开放数据导出(plugin_export)
  • v0.3:Web 设置页榜单(ui-settings-plugins 扩展点)+ 开放数据导出 JSON
  • v0.4:企业审计报告导出 / 私有化

License

MIT

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →

社区评论

评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。