wulun811/dsh-plugin-vet
Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.
dsh-plugin-vet is a security gate for DSH plugins: audit before install, guard at runtime. Static rules (R1-R20) produce a deterministic verdict, the agent investigates sensitive points via the vet-audit-protocol skill, and a final scorecard goes to a human/model to decide. It is positioned as a monitoring alarm, not an enforcer — in the default configuration it never auto-uninstalls, kills processes, rewrites configs or blocks anything. Runtime guard (opt-in): T1 sentinel (memory/fd/child-process), T2 hooks (fs/child_process/network interception) and N7 confirmation blocking (credential-file deletion/overwrite). Safety tiers: standard (defaults), hardened (wakes dormant capabilities) and paranoid (strictest blocking); mode report vs deny; autoScan static-scans new plugins; requireAudit gates third-party plugin loads on a health record.
Install
dsh plugin --profile <profile> add @jieai/dsh-plugin-vetnpm @jieai/dsh-plugin-vet 0.3.5 verified 2026-09-04 (scoped npm package; repository field → github.com/wulun811/dsh-plugin-vet; README EN primary w/ zh edition; landing site wulun811.github.io/dsh-plugin-vet). Install: dsh plugin --profile <profile> add @jieai/dsh-plugin-vet — pnpm install → reconcilePlugins reads dsh.bundle → loadProfile mounts the bundle on next start. Default config is fail-open (report only, blocks nothing); interception wakes only with explicit config (confirmBlock / mode / hardened-and-above tiers). Requires Node.js >=22.19.
Compatibility
DeepSeek Harness profiles; Node.js >=22.19; read-only by default (report mode), interception only in documented scopes.
Details
- Repo: wulun811/dsh-plugin-vet
- Category: Development & Runtime
- Stars: 0
- Version: npm @jieai/dsh-plugin-vet 0.3.5
- Last push: 2026-09-11
- First seen: 2026-08-15
Recent updates
v0.3 line added safety tiers (standard/hardened/paranoid), runtime guard stack and N7 confirmation blocking.
FAQ
- Does vet block plugins by default?
- No — default mode is report (fail-open): it checks, alarms and advises but never auto-uninstalls, kills processes, rewrites configs or blocks. Interception only wakes with explicit config (deny mode, confirmBlock, or hardened/paranoid tiers).
- What does the static scan check?
- Deterministic rules R1-R20 over the plugin package — sensitive points and quality issues get an investigation pass by the agent following vet-audit-protocol, then a scorecard for a human/model to decide.
- How do I enable the runtime guard?
- Set runtimeGuard: watch (or the hardened tier): T1 sentinel monitors memory/fd/child processes, T2 hooks intercept fs/child_process/network, and the N7 confirmation block stops credential-file deletion/overwrite and post-confirmation destructive ops.
Alternatives
Xrainsmile/DSH-Plugin-Doctor · truelove-dreamer/dsh-plugin-security-audit