Introduction

DeepSeek Harness (DSH) follows the “everything is a plugin” philosophy. This lowers the barrier to system extension, but it also introduces supply chain security risks. When installing third-party plugins, developers often find it difficult to verify the security or integrity of the code before execution.

dsh-plugin-guard is a static analysis plugin. It does not execute the target plugin; instead, it intercepts potential risks through static auditing and hash pinning. It performs static auditing before installation, hash and capability locking after installation, and provides peer search and mechanical detox functions.

Plugin Positioning

  • Name: taxueseek/dsh-plugin-guard
  • Maintainer: taxueseek
  • Type: Static security audit
  • Core principle: Static analysis; never execute the target plugin.
  • Architecture: Contains two layers: “Gate” and “Clinic”. Gate handles pre- and post-installation static auditing and locking; Clinic handles peer search and mechanical detox.

Core Features

  1. plugin_audit (Gate): pre-installation static audit
    Before the plugin is installed or loaded, perform static analysis of the code to identify potential security risks.

  2. plugin_verify (Gate): hash and capability locking
    After the plugin is installed, use hash verification to lock plugin integrity and combine it with capability locks to prevent malicious features from being triggered.

  3. plugin_peers (Clinic): peer search

    • Local fingerprints: fingerprint installed local plugins.
    • Query: search GitHub for the topic:dsh-plugin label and curated lists. If these results are lightweight, use argo for the query.
    • Remote: query GitHub directly; the verdict is unknown, and re-auditing is required before installation.
  4. plugin_detox (Clinic): mechanical excision
    Perform mechanical excision of installed plugins without preserving their original behavior.

Installation and Enabling

Install this plugin using the official command and restart the DSH Web service.

dsh plugin --profile web add github:taxueseek/dsh-plugin-guard
# 重启 dsh web

Typical Usage

Scoring Mechanism

The plugin scores scan results with an initial score of 100.

  • P0: Only auto-run cases that contain dangerous combinations, such as curl|bash, secrets leaving the machine, eval of network content, or poisoned install scripts. P0 deducts 40 points.
  • P1: exec appears inside tools (the model must click to trigger it). P1 deducts 12 points.
  • P2: Other cases. P2 deducts 3 points.

Verdict logic:
* Block: Any P0 or a score below 40.
* Warn: Any P1 or a score below 75.

Three Modes of plugin_peers

The plugin_peers command behaves differently depending on its parameters:

  1. path: scan only the local path (profile bundles).
  2. query: match GitHub topic:dsh-plugin + curated lists. If these lists are lightweight, use argo for the query.
  3. remote: query GitHub directly; the verdict is unknown. This means auditing must be performed before installation.

Applicable Scenarios and Precautions

This plugin is suitable for all scenarios that require strict control of the DSH plugin lifecycle, especially environments sensitive to supply chain security.

Precautions:
1. No redaction output: the plugin does not redact sensitive information.
2. Not general-purpose SAST: it is not a general-purpose static application security testing tool.
3. Cannot prove security: passing the audit does not mean the plugin is absolutely safe.
4. Detox does not preserve behavior: plugin_detox performs mechanical excision and does not preserve the original behavior logic of the plugin.
5. Permission risk: as a plugin, it runs with the permissions of the current DSH process. Before installing any plugin, always manually inspect the source code and license.

Conclusion

dsh-plugin-guard provides a set of static security defenses. Through hash locking and scoring mechanisms, it helps developers identify and block high-risk plugins. For more details and source code, visit its GitHub repository or the DSH ecosystem directory.