jkrandom-sudo/dsh-plugin-audit
Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sen
Security audit for DeepSeek Harness plugins: profiles third-party plugins statically — which files, processes, hosts, env vars and credential paths their code touches, with file/line evidence (plugin_audit tool returning a permission profile card: filesystem, child processes, network, outbound hosts, credential-looking env, dynamic code execution, injected services) — and arms a runtime sentinel on tools/pre-execute that asks for approval when a tool call reaches for credentials, moves data to unknown hosts, or writes home-directory dotfiles. The scan is read-only by contract (writesPerformed: false).
Install
dsh plugin --profile web add dsh-plugin-auditnpm package dsh-plugin-audit 0.1.2 (registry-verified 2026-08-26). dsh plugin --profile web add dsh-plugin-audit or from GitHub dsh plugin --profile web add github:jkrandom-sudo/dsh-plugin-audit — either registers the package in dsh.profile.bundles and applies cordis.patch.yml (one row: dsh-plugin-audit, sentinelEnabled: true). Restart the profile. Uninstall: dsh plugin --profile web remove dsh-plugin-audit.
Compatibility
DeepSeek Harness (any profile). Works with the harness's normal approval flow — no approval channel means calls are denied, never silently allowed.
Details
- Repo: jkrandom-sudo/dsh-plugin-audit
- Category: Coding & Development
- Stars: 4
- Version: npm dsh-plugin-audit 0.1.2 (registry-verified 2026-08-26)
- Last push: 2026-09-11
- First seen: 2026-08-14
Recent updates
v0.1.2: static permission profiling with file/line evidence; runtime sentinel on tools/pre-execute; credential/egress/dotfile rules; read-only contract.
FAQ
- What triggers the runtime sentinel?
- Any tool argument referencing a credential path (e.g. read on ~/.ssh/id_rsa), shell egress toward a host outside allowedHosts, or a write targeting a home-directory dotfile.
- Is the scan read-only?
- Yes — every report carries writesPerformed: false, and an optional invariant companion enforces that marker at runtime.
- What happens without an approval channel?
- The matching call is denied — never silently allowed.
Alternatives
omdsh-dev/dsh-security-audit · omdsh-dev/dsh-session-health · Areium/dsh-fail-logger