Introduction¶
The DeepSeek Harness (dsh) plugin runs with real filesystem and process access. Existing audit tools (such as dsh-security-audit) are usually good at detecting capabilities (for example, a plugin can access the filesystem or network), but explicitly avoid judging intent, stating that they are only “audit assistance” rather than “antivirus software.” dsh-malware-audit fills this specific gap: it scans the actual Abstract Syntax Trees (ASTs) of installed plugins to look for malicious intent patterns, rather than relying on signature databases or raw text matching.
Installation and Enablement¶
- Install the plugin using the official command.
dsh plugin --profile <name> add dsh-malware-audit
- Add the plugin name to the
dsh.profile.bundleslist; otherwise, the plugin will not be activated. Reference configuration is as follows:
{
"dsh": {
"profile": {
"bundles": [
"@deepseek-ai/dsh-base",
"@deepseek-ai/dsh-web-app",
"dsh-malware-audit"
]
}
}
}
- Verify that the configuration takes effect by checking whether the
malware-auditconfiguration item exists.
dsh --profile <name> --dump-config
Core Features and Usage¶
Manual Scan¶
Enter /scan-plugins in any session. This command scans all installed plugins that declare dsh.bundle, prints a discovery summary, and saves the full report to the .dsh-malware-audit/scan-<timestamp>.txt file in the current directory.
Scheduled Scans¶
By default, scanning is read-only. To enable scheduled scanning, set scheduleMinutes in the configuration file.
scheduleMinutes: 60
Set a value greater than 0 to enable it. Note: values less than 5 are rejected.
Automatic Quarantine¶
Enable the automatic quarantine feature (autoQuarantine: true). When a scan finds a critical-severity issue, the plugin is automatically quarantined.
Detection Rules¶
The plugin uses heuristic rules for scanning and does not include a known malicious package signature database. It mainly detects the following patterns:
| Rule | Severity | Detection |
|---|---|---|
dynamic-eval |
critical | eval(), new Function(), and vm.Script-related calls |
decode-then-execute |
critical | Base64 decoding followed by direct input to eval() or require() |
fetch-and-execute |
critical | child_process invoking external commands such as curl/wget |
cross-plugin-write |
critical | Writing files into another plugin’s node_modules directory |
raw-ip-network |
warning | Using raw IP addresses instead of domain names for network requests |
env-exfil-shape |
warning | Network request parameters referencing process.env |
child-process-shell |
notice | Any child_process call |
Configuration Reference¶
Configure plugin behavior in cordis.patch.yml:
- insert:
- id: malware-audit
name: 'dsh-malware-audit'
config:
maxFiles: 400
maxFileBytes: 262144
ignoreRuleIds: []
ignorePlugins: []
scheduleMinutes: 0
autoQuarantine: false
| Field | Default Value | Description |
|---|---|---|
maxFiles |
400 | Maximum number of files per plugin; if exceeded, scanning of that plugin stops |
maxFileBytes |
262144 | Maximum file size limit (256 KiB); if exceeded, the file is skipped |
ignoreRuleIds |
[] | Skip detection for specific rules |
ignorePlugins |
[] | Skip scanning specific plugins |
scheduleMinutes |
0 | Automatic scan interval; 0 means disabled |
autoQuarantine |
false | Automatically quarantine when a critical issue is found |
Quarantine Mechanism and Recovery¶
Quarantine Behavior¶
When autoQuarantine: true and a critical issue is found, quarantinePlugin() performs the following:
1. Moves the plugin’s node_modules entry to .dsh-malware-audit/quarantine/<name>-<timestamp>/.
2. Removes the plugin name from the dsh.profile.bundles list in all local configuration files.
Quarantine takes effect at the next startup and does not immediately stop the currently running process.
Restoring a Plugin¶
Manual restoration is required after quarantine:
1. Move the directory from .dsh-malware-audit/quarantine/ back under the profile’s node_modules.
2. Re-add the plugin name to dsh.profile.bundles in the configuration.
Notes¶
- Resource Limits: Scanning is limited to the plugin’s own directory and excludes
node_modules,.git,lib,dist, andbuild. The per-plugin resource budget is a maximum of 400 files or 256 KiB. - File Types: Only
.js/.tssource files are scanned; documentation files such as.mdand.jsonare not scanned. - Not Antivirus Software: It is based on heuristic rules and does not include a known malicious package signature database.
- Dependency Environment: Requires Node.js >= 22.
- False Positive Risk: Although it performs AST scanning, known false positives are still possible (for example, certain JSDoc comments). It is recommended to manually run several scans and verify before enabling automatic quarantine.
Summary¶
dsh-malware-audit provides a static code analysis perspective different from traditional antivirus software, specifically targeting malicious intent patterns. It does not replace a full code audit but serves as a security assistance tool to help identify potentially malicious behavior in plugins.