Introduction¶
DeepSeek Harness (DSH) follows the “everything is a plugin” philosophy. This lowers the barrier to system extension, but it also introduces supply chain security risks. When installing third-party plugins, developers often find it difficult to verify the security or integrity of the code before execution.
dsh-plugin-guard is a static analysis plugin. It does not execute the target plugin; instead, it intercepts potential risks through static auditing and hash pinning. It performs static auditing before installation, hash and capability locking after installation, and provides peer search and mechanical detox functions.
Plugin Positioning¶
- Name:
taxueseek/dsh-plugin-guard - Maintainer: taxueseek
- Type: Static security audit
- Core principle: Static analysis; never execute the target plugin.
- Architecture: Contains two layers: “Gate” and “Clinic”.
Gatehandles pre- and post-installation static auditing and locking;Clinichandles peer search and mechanical detox.
Core Features¶
-
plugin_audit (Gate): pre-installation static audit
Before the plugin is installed or loaded, perform static analysis of the code to identify potential security risks. -
plugin_verify (Gate): hash and capability locking
After the plugin is installed, use hash verification to lock plugin integrity and combine it with capability locks to prevent malicious features from being triggered. -
plugin_peers (Clinic): peer search
- Local fingerprints: fingerprint installed local plugins.
- Query: search GitHub for the
topic:dsh-pluginlabel and curated lists. If these results are lightweight, use argo for the query. - Remote: query GitHub directly; the verdict is
unknown, and re-auditing is required before installation.
-
plugin_detox (Clinic): mechanical excision
Perform mechanical excision of installed plugins without preserving their original behavior.
Installation and Enabling¶
Install this plugin using the official command and restart the DSH Web service.
dsh plugin --profile web add github:taxueseek/dsh-plugin-guard
# 重启 dsh web
Typical Usage¶
Scoring Mechanism¶
The plugin scores scan results with an initial score of 100.
- P0: Only auto-run cases that contain dangerous combinations, such as
curl|bash, secrets leaving the machine, eval of network content, or poisoned install scripts. P0 deducts 40 points. - P1:
execappears inside tools (the model must click to trigger it). P1 deducts 12 points. - P2: Other cases. P2 deducts 3 points.
Verdict logic:
* Block: Any P0 or a score below 40.
* Warn: Any P1 or a score below 75.
Three Modes of plugin_peers¶
The plugin_peers command behaves differently depending on its parameters:
- path: scan only the local path (profile bundles).
- query: match GitHub
topic:dsh-plugin+ curated lists. If these lists are lightweight, use argo for the query. - remote: query GitHub directly; the verdict is
unknown. This means auditing must be performed before installation.
Applicable Scenarios and Precautions¶
This plugin is suitable for all scenarios that require strict control of the DSH plugin lifecycle, especially environments sensitive to supply chain security.
Precautions:
1. No redaction output: the plugin does not redact sensitive information.
2. Not general-purpose SAST: it is not a general-purpose static application security testing tool.
3. Cannot prove security: passing the audit does not mean the plugin is absolutely safe.
4. Detox does not preserve behavior: plugin_detox performs mechanical excision and does not preserve the original behavior logic of the plugin.
5. Permission risk: as a plugin, it runs with the permissions of the current DSH process. Before installing any plugin, always manually inspect the source code and license.
Conclusion¶
dsh-plugin-guard provides a set of static security defenses. Through hash locking and scoring mechanisms, it helps developers identify and block high-risk plugins. For more details and source code, visit its GitHub repository or the DSH ecosystem directory.