Preface

The DeepSeek Harness (DSH) ecosystem allows extending functionality through community plugins. The official documentation warns about the GitHub installation method: the prepare script has permission to execute code during installation and is not restricted by the host sandbox. dsh-plugin-sentinel is a static pre-installation audit tool designed to address the need to “clear security checks before installation”.

What It Is

This is a zero-dependency static security-check tool that parses tar packages in memory. It is maintained by BotonJ and detects potential risks in plugin packages by using combined rules, outputting a structured risk report before installation.

Core Features

The plugin has the following features:

  1. Zero dependencies, zero install scripts, zero builds: No scripts or dependencies in package.json; installing from GitHub requires no additional permissions and carries no install-time execution risk.
  2. Native JSON-Schema ToolDefinition registration: All source code depends only on Node built-in modules and does not depend on any runtime packages.
  3. Pure JS tar parsing: Uses node:zlib and a hand-written ustar/pax/GNU-longname parser to audit .tgz files in memory; malicious code is not written to disk.
  4. Lexical stripping scan: Strips comments and string literals first before matching dangerous APIs to prevent false positives; retains detection of code inside template interpolation to prevent false negatives.
  5. Combined rule detection: For example, process.env access × network egress = credential exfiltration signature.

Installation and Enablement

Add the plugin to the specified profile using the following command:

dsh plugin --profile <你的profile> add github:<你的fork>/dsh-plugin-sentinel

Typical Usage

After installation, interact with the model through the following tools:

  1. Audit a specific plugin: Enter “Help me install the plugin github:xxx/yyy”; the model calls audit_plugin to run security checks. If the risk level is block, installation is rejected.
  2. Audit installed plugins: Enter “Check whether the plugins installed in my current profile are safe”; the model calls audit_installed to check all community bundles.

Audit results are sorted by severity. The classification criteria are as follows:
- pass: Pass
- review: Requires manual review
- block: Rejection recommended

Weights: critical=10 / high=5 / medium=2 / low=1.

Audit Coverage

The plugin checks the following items:

  • package.json: Detects install-time lifecycle scripts (critical), disguised plugins, and runtime dependencies.
  • JS/TS source code: Detects child_process, eval/new Function/vm, network egress, process.env access, file writes, dynamic require, and homedir probing.
  • String literals: Detects sensitive paths (.ssh, .env), cloud credentials, external URLs, and long encoded payloads (obfuscation signatures).
  • cordis.patch.yml: Detects !!js expressions (load-time host execution, critical), disabled: true silently disabling security lines (critical), and reconfigured security lines (high).
  • tarball structure: Detects path traversal (critical), symbolic links (high), and abnormal archives.

Limitations and Notes

  • Scanner limitation: The lexical scanner is not a complete AST. For deliberately crafted evasion techniques (such as hiding malicious code in pseudo-comments inside interpolation), false negatives may occur. It aims to catch common malicious patterns and does not promise adversarial completeness.
  • Permission note: review and block are recommendations; the final decision rests with the user. The plugin runs with the current DSH process permissions; before installation, check the source code and license.