Introduction

DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture, and developers typically extend its capabilities by adding external plugins. When introducing third-party plugins, directly running unverified code carries supply chain poisoning risks. dsh-poison-guard is a preinstalled supply chain poisoning scanner aimed at addressing this issue. It does not execute plugin code; instead, before you run dsh plugin add, it uses static analysis to check whether the code contains malicious behavior.

Core Capabilities

The plugin uses a three-layer detection mechanism to identify potential threats:

  1. AST Analysis
    It uses NodeSecure JS-X-Ray to perform static application security testing (SAST). It can trace variables, resolve dynamic imports, identify obfuscators, and detect dangerous operations such as eval/Function/vm, as well as risks such as data exfiltration, environment variable serialization, and dangerous shell commands.

  2. Deobfuscation Decoding
    It decodes common encoding patterns, including atob(), Buffer.from(..., "base64"/"hex"), String.fromCharCode(...), and \xNN, \uNNNN escape sequences. After decoding, it rescans the decoded strings to look for hidden keys, URLs, and shell commands.

  3. Regex Heuristics
    As the final line of defense, it matches suspicious content in obvious literals, non-code files, and installation-time scripts such as prepare/postinstall/install/preinstall.

Installation and Activation

Add the plugin scanner to DSH:

dsh plugin --profile web add github:zoahdev/dsh-poison-guard

After installation, the tool is integrated into the DSH environment as a standalone command-line tool.

Usage

After installation, you can use the command to scan any local plugin directory. Scan results are returned via exit codes: 0 indicates clean code, and 1 indicates detected threats, making it suitable for gate checks in CI workflows.

# 扫描指定插件目录
dsh-poison-guard scan ./some-plugin

# 输出机器可读格式(用于 CI)
dsh-poison-guard scan ./some-plugin --json

Use Cases and Notes

  • Static Detection: The tool performs static analysis only and does not execute plugin code or observe runtime behavior.
  • Obfuscation Limitations: Although it handles common simple obfuscation, strong obfuscation (such as tools combining string arrays and control-flow flattening) may still hide malicious payloads.
  • False Positives: The sensitivity of the AST layer is set to an “aggressive” level for maximum visibility, so benign code (such as legitimate logic that genuinely uses eval) may also be flagged.
  • Sandbox Dependency: The plugin itself does not enforce sandboxing policies. The actual security boundary depends on the Harness sandbox configuration; unverified plugins should always be restricted to workspace-write permissions and avoid danger-full-access.

This is a community-maintained template project, licensed under the MIT license, and is not an official DeepSeek product.