Back to Marketplace
Security & governancePlugin

dsh-plugin-audit

jkrandom-sudo/dsh-plugin-audit

dsh-plugin-audit is a tool for DeepSeek Harness. Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sentinel gating credential access and unknown-host egress · DSH plugin security audit: static permission profile (with file/line evidence) + runtime sentinel that asks for your approval before touching credentials or sending data to unknown hosts

jkrandom-sudo/dsh-plugin-audit Screenshot preview
Stars
4
Forks
0
Issues
0
Update
50 days

REVIEW SCORECARD

Review Scorecard

7.5/10Average
License compliance9.0
Engineering quality5.4
Content completeness7.0
Repository scale7.0
Maintenance activity8.0

✓ No risk detected · Automated scan results are for reference only, not an official endorsement

AI DEEP REVIEW

Worth AI Review

8.4/10Recommended

A well-documented, read-only security auditor and runtime sentinel that adds real safety value to DSH plugin installs.

Code quality8

README documents a read-only scanner contract with a writesPerformed:false invariant, file/line evidence, and explicit file/size caps, though no test or CI details are shown.

Security8

The plugin itself makes no network calls, is read-only by contract, and its sentinel defaults to deny when no approval channel exists, with only the optional invariant companion left unwired.

Utility9

It addresses a genuine gap by profiling third-party plugin permissions statically and gating credential access or unknown-host egress at runtime before damage occurs.

Maintenance8

Last updated 2026-08-14 with a verified-against snapshot date and explicit acknowledgment of DSH's frequent breaking changes, though stars are low at 4.

Documentation9

The README covers install/uninstall commands, configuration YAML, quick-start examples, compatibility table, and permissions/data handling in clear detail.

Generated by AI after reading the project README — a decision aid, not an endorsement. Neutral scores are given when information is limited.

PROJECT READMEREADMEExpandCollapse

Loading GitHub README...

PROJECT TOPICS

Project topics

VALIDATION LADDER

Validation progress

Structure check pending
01Store discoveryPassed
02ClassificationPassed
03Structure checkPending
04Sandbox validationPending

FAQ

Frequently Asked Questions

What is dsh-plugin-audit used for?

Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sentinel gating credential access and unknown-host egress · DSH plugin security audit: static permission profile

How popular is dsh-plugin-audit?

dsh-plugin-audit has 4 stars and 0 forks on GitHub, last updated 2026-08-14.

What license does dsh-plugin-audit use?

dsh-plugin-audit is distributed under the MIT license.

Is dsh-plugin-audit compatible with DeepSeek Harness?

dsh-plugin-audit is listed in the DSH Universe directory as a tool for DeepSeek Harness. This plugin is listed in the DSH Universe directory and covered by its validation pipeline.

CLASSIFICATION EVIDENCE

Classification evidence

Project typePlugin
Feature categorySecurity & governance
Rule confidenceHigh

The system checks GitHub Topics against the site taxonomy and keyword rules. Current matches:audit、security。