Preface¶
The DeepSeek Harness (DSH) ecosystem allows extending functionality through community plugins. The official documentation warns about the GitHub installation method: the prepare script has permission to execute code during installation and is not restricted by the host sandbox. dsh-plugin-sentinel is a static pre-installation audit tool designed to address the need to “clear security checks before installation”.
What It Is¶
This is a zero-dependency static security-check tool that parses tar packages in memory. It is maintained by BotonJ and detects potential risks in plugin packages by using combined rules, outputting a structured risk report before installation.
Core Features¶
The plugin has the following features:
- Zero dependencies, zero install scripts, zero builds: No
scriptsordependenciesinpackage.json; installing from GitHub requires no additional permissions and carries no install-time execution risk. - Native JSON-Schema ToolDefinition registration: All source code depends only on Node built-in modules and does not depend on any runtime packages.
- Pure JS tar parsing: Uses
node:zliband a hand-written ustar/pax/GNU-longname parser to audit.tgzfiles in memory; malicious code is not written to disk. - Lexical stripping scan: Strips comments and string literals first before matching dangerous APIs to prevent false positives; retains detection of code inside template interpolation to prevent false negatives.
- Combined rule detection: For example,
process.envaccess × network egress = credential exfiltration signature.
Installation and Enablement¶
Add the plugin to the specified profile using the following command:
dsh plugin --profile <你的profile> add github:<你的fork>/dsh-plugin-sentinel
Typical Usage¶
After installation, interact with the model through the following tools:
- Audit a specific plugin: Enter “Help me install the plugin github:xxx/yyy”; the model calls
audit_pluginto run security checks. If the risk level isblock, installation is rejected. - Audit installed plugins: Enter “Check whether the plugins installed in my current profile are safe”; the model calls
audit_installedto check all community bundles.
Audit results are sorted by severity. The classification criteria are as follows:
- pass: Pass
- review: Requires manual review
- block: Rejection recommended
Weights: critical=10 / high=5 / medium=2 / low=1.
Audit Coverage¶
The plugin checks the following items:
- package.json: Detects install-time lifecycle scripts (critical), disguised plugins, and runtime dependencies.
- JS/TS source code: Detects
child_process,eval/new Function/vm, network egress,process.envaccess, file writes, dynamic require, and homedir probing. - String literals: Detects sensitive paths (
.ssh,.env), cloud credentials, external URLs, and long encoded payloads (obfuscation signatures). - cordis.patch.yml: Detects
!!jsexpressions (load-time host execution, critical),disabled: truesilently disabling security lines (critical), and reconfigured security lines (high). - tarball structure: Detects path traversal (critical), symbolic links (high), and abnormal archives.
Limitations and Notes¶
- Scanner limitation: The lexical scanner is not a complete AST. For deliberately crafted evasion techniques (such as hiding malicious code in pseudo-comments inside interpolation), false negatives may occur. It aims to catch common malicious patterns and does not promise adversarial completeness.
- Permission note:
reviewandblockare recommendations; the final decision rests with the user. The plugin runs with the current DSH process permissions; before installation, check the source code and license.