wulun811/dsh-plugin-vet

Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.

dsh-plugin-vet is a security gate for DSH plugins: audit before install, guard at runtime. Static rules (R1-R20) produce a deterministic verdict, the agent investigates sensitive points via the vet-audit-protocol skill, and a final scorecard goes to a human/model to decide. It is positioned as a monitoring alarm, not an enforcer — in the default configuration it never auto-uninstalls, kills processes, rewrites configs or blocks anything. Runtime guard (opt-in): T1 sentinel (memory/fd/child-process), T2 hooks (fs/child_process/network interception) and N7 confirmation blocking (credential-file deletion/overwrite). Safety tiers: standard (defaults), hardened (wakes dormant capabilities) and paranoid (strictest blocking); mode report vs deny; autoScan static-scans new plugins; requireAudit gates third-party plugin loads on a health record.

Development & Runtime ★ 0 updated 2026-09-11
View on GitHub ↗

Install

dsh plugin --profile <profile> add @jieai/dsh-plugin-vet

npm @jieai/dsh-plugin-vet 0.3.5 verified 2026-09-04 (scoped npm package; repository field → github.com/wulun811/dsh-plugin-vet; README EN primary w/ zh edition; landing site wulun811.github.io/dsh-plugin-vet). Install: dsh plugin --profile <profile> add @jieai/dsh-plugin-vet — pnpm install → reconcilePlugins reads dsh.bundle → loadProfile mounts the bundle on next start. Default config is fail-open (report only, blocks nothing); interception wakes only with explicit config (confirmBlock / mode / hardened-and-above tiers). Requires Node.js >=22.19.

Compatibility

DeepSeek Harness profiles; Node.js >=22.19; read-only by default (report mode), interception only in documented scopes.

Details

Recent updates

v0.3 line added safety tiers (standard/hardened/paranoid), runtime guard stack and N7 confirmation blocking.

FAQ

Does vet block plugins by default?
No — default mode is report (fail-open): it checks, alarms and advises but never auto-uninstalls, kills processes, rewrites configs or blocks. Interception only wakes with explicit config (deny mode, confirmBlock, or hardened/paranoid tiers).
What does the static scan check?
Deterministic rules R1-R20 over the plugin package — sensitive points and quality issues get an investigation pass by the agent following vet-audit-protocol, then a scorecard for a human/model to decide.
How do I enable the runtime guard?
Set runtimeGuard: watch (or the hardened tier): T1 sentinel monitors memory/fd/child processes, T2 hooks intercept fs/child_process/network, and the N7 confirmation block stops credential-file deletion/overwrite and post-confirmation destructive ops.

Alternatives

Xrainsmile/DSH-Plugin-Doctor · truelove-dreamer/dsh-plugin-security-audit

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins