Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture, where user permissions and configuration are introduced by plugins. When managing these plugins, you need to assess whether the current environment presents risks (such as high-risk code injection or permission abuse). dsh-security-doctor, as a DSH Web interface plugin, provides a one-click local security check feature through the “Security Checkup” button in the sidebar.
Plugin Overview¶
Name: dsh-security-doctor
Maintainer: ChenChen913
Category: admin-security
Purpose: A one-click security checkup tool for the DSH Web interface.
The core value of this plugin is “read-only” and “zero outbound transmission.” It does not execute any code from the inspected target, does not send any data externally by default, and does not require an API Key. By performing static scanning and configuration auditing, it helps users quickly identify security risks in the environment.
Core Features¶
The plugin provides three core capabilities: tiered reporting, AI deep review, and an experimental guardian mode.
Tiered Reports¶
Reports use a conclusion-first design. High-risk issues directly trigger a card that explains the specific plugin, the cause, and recommended remediation actions, while technical details are collapsed at the bottom. Reports include a ring score (0–100), bilingual Chinese/English output, and a remediation checklist, and support exporting to JSON or copying Markdown.
AI Deep Review¶
For suspicious plugins, the plugin provides an “AI Deep Review” feature. Users can copy a structured deep-review prompt with one click, hand it off via the clipboard to their own Agent for review, and paste conclusions back into the plugin. This process involves zero API calls and is fully local.
Guardian Mode (Experimental)¶
Guardian mode is disabled by default. When enabled, the plugin shifts from a “doctor” to a “monitor.” It provides two layers of protection:
1. Outbound Audit: Monitors HTTP/HTTPS requests initiated by plugins and records “plugin → domain → method → whether credential-like content is present.” Data is stored in an in-memory ring buffer (50 entries), and payload content is never logged.
2. Change Sentinel: Snapshots patches/configuration and instruction files under ~/.dsh every 45 seconds. When changes are detected, a badge lights up and lists the changed files.
Installation and Enablement¶
After installing the plugin, you must restart dsh web for it to take effect (running instances do not hot-load).
Installation Command¶
dsh plugin --profile web add github:ChenChen913/dsh-security-doctor#v1.1.0
Verify Installation¶
After installation, a “Security Checkup” button should appear in the sidebar. You can also verify from the command line:
curl -H 'x-dsh-security-doctor: 1' http://127.0.0.1:3080/dsh-security-doctor/self-test
A response of ok:true indicates successful installation.
Detailed Checks¶
The plugin scans and grades the following items:
!!jsexpressions: Scans cordis patches/configuration under~/.dshand detects!!jssyntax, which is executed on load.- Security-layer patches: Checks
remove:/replace:targets that point to protection plugins such as approval / sandbox / permission. - Third-party plugin inventory: Inventories dependencies across profiles, distinguishes official plugins from external ones, and flags unlocked git references and
postinstallscripts. - Network egress and intent patterns: Statically scans external plugin source code to identify external domains and
eval/base64 obfuscation patterns. If the same file contains both “credential access” and “network egress,” the risk rating is upgraded to high. - Credential file permissions: Checks permission bits and ACL account names for
~/.dsh/.credentials.yaml. Only permissions are inspected; content is never read. - Instruction files: Scans files such as
AGENTS.md/CLAUDE.md/.cursor/rules/and compares changes across runs using SHA-256 hashing. - Endpoint configuration: Checks
baseURLin configuration and theDEEPSEEK_BASE_URLenvironment variable (only the hostname is displayed). - Protection services and policies: Checks loaded services and actual policy values, such as approval set to
neveror thedanger-full-accesspreset, as well as session-level overrides byDSH_PERMISSION_MODE.
Guardian Mode Caveats¶
Guardian mode is an experimental feature, and its boundaries should be considered when using it:
* Not covered: Does not monitor fetch or raw sockets; audit attribution is inferred from the call stack on a best-effort basis, and advanced code may spoof it.
* Blind spots: Rapid changes within the 45-second polling interval may be missed; for large files, only size and mtime are recorded.
* Uninstall reverts state: Turning the switch off disables it immediately; uninstalling the plugin restores the original module exports.
Use Cases and Notes¶
This plugin is suitable for developers who frequently manage DSH plugins and are concerned about local environment security.
Prerequisites¶
Before installation, review the source code and license, because the plugin runs with the permissions of the DSH process.
Important Notes¶
- Restart required: After installation or update, you must restart
dsh web; otherwise, the plugin will not take effect. - Static scanning limitations: Static scanning is only an initial screening. The absence of anomalies does not guarantee absolute safety (for example, obfuscated encoding or runtime-constructed addresses cannot be detected).
- Permission-bit limitations: Checking POSIX permission bits is not equivalent to full ACL detail inspection.
Conclusion¶
dsh-security-doctor helps reduce the cost of security triage in agent development environments by providing tiered reporting and AI deep review. For users who want to perform security auditing without leaving the DSH Web interface, it is a practical helper tool.