Introduction¶
DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture, and developers typically extend its capabilities by adding external plugins. When introducing third-party plugins, directly running unverified code carries supply chain poisoning risks. dsh-poison-guard is a preinstalled supply chain poisoning scanner aimed at addressing this issue. It does not execute plugin code; instead, before you run dsh plugin add, it uses static analysis to check whether the code contains malicious behavior.
Core Capabilities¶
The plugin uses a three-layer detection mechanism to identify potential threats:
-
AST Analysis
It uses NodeSecure JS-X-Ray to perform static application security testing (SAST). It can trace variables, resolve dynamic imports, identify obfuscators, and detect dangerous operations such aseval/Function/vm, as well as risks such as data exfiltration, environment variable serialization, and dangerous shell commands. -
Deobfuscation Decoding
It decodes common encoding patterns, includingatob(),Buffer.from(..., "base64"/"hex"),String.fromCharCode(...), and\xNN,\uNNNNescape sequences. After decoding, it rescans the decoded strings to look for hidden keys, URLs, and shell commands. -
Regex Heuristics
As the final line of defense, it matches suspicious content in obvious literals, non-code files, and installation-time scripts such asprepare/postinstall/install/preinstall.
Installation and Activation¶
Add the plugin scanner to DSH:
dsh plugin --profile web add github:zoahdev/dsh-poison-guard
After installation, the tool is integrated into the DSH environment as a standalone command-line tool.
Usage¶
After installation, you can use the command to scan any local plugin directory. Scan results are returned via exit codes: 0 indicates clean code, and 1 indicates detected threats, making it suitable for gate checks in CI workflows.
# 扫描指定插件目录
dsh-poison-guard scan ./some-plugin
# 输出机器可读格式(用于 CI)
dsh-poison-guard scan ./some-plugin --json
Use Cases and Notes¶
- Static Detection: The tool performs static analysis only and does not execute plugin code or observe runtime behavior.
- Obfuscation Limitations: Although it handles common simple obfuscation, strong obfuscation (such as tools combining string arrays and control-flow flattening) may still hide malicious payloads.
- False Positives: The sensitivity of the AST layer is set to an “aggressive” level for maximum visibility, so benign code (such as legitimate logic that genuinely uses
eval) may also be flagged. - Sandbox Dependency: The plugin itself does not enforce sandboxing policies. The actual security boundary depends on the Harness sandbox configuration; unverified plugins should always be restricted to
workspace-writepermissions and avoiddanger-full-access.
This is a community-maintained template project, licensed under the MIT license, and is not an official DeepSeek product.