Introduction

DeepSeek Harness (DSH) adopts the “everything is a plugin” architecture, and the plugin ecosystem is rapidly expanding. As the number of plugins in the catalog surges, the risk of malicious code being mixed into plugin installation scripts, credential theft, or network callbacks also increases. dsh-plugin-gate is a security plugin designed for this purpose. Before running dsh plugin add, it performs a static scan of the plugin source code and can block or warn before dangerous commands are executed.

Plugin Overview

  • Plugin Name: dsh-plugin-gate
  • Maintainer: 863683348
  • Open Source License: MIT
  • Core Positioning: An installation security gate and data protection guard for DeepSeek Harness.

Core Features

The plugin mainly provides three capabilities:

  1. Installation Source Scanning

    • Uses 60 static rules to scan plugin source code. The rules are divided into three severity levels: high (31), medium (24), and low (5).
    • Scanned content covers malicious installation scripts, credential theft, code obfuscation, and network callbacks.
    • Supports scanning targets as npm tarball or local directories.
    • Checks known supply-chain vulnerabilities through Google OSV.
    • Security Feature: The scanning process is read-only. It never executes the scanned code and does not write files to disk.
  2. Diff Reports

    • Generates baselines for comparing historical scan results.
    • Provides the gate_diff tool to identify newly added, resolved, or changed risk points.
  3. Data Protection Guard

    • Provides the gate_guard tool to assess risks before destructive operations are executed.
    • Checks whether the target path is within the current workspace boundary and whether it is a critical file (such as .git or memory.json).
    • Based on signatures of rm -rf-style commands, returns a verdict of BLOCK, WARN, or PASS.

Installation

Add the plugin to a DSH Profile configuration:

dsh plugin --profile <profile> add dsh-plugin-gate

Typical Usage

Scan plugin source code before installation:

gate_scan target: "npm:dsh-plugin-some-package"
gate_scan target: "npm:dsh-plugin-some-package@1.2.3"
gate_scan target: "./downloaded-plugin"

Baselines and Reports

Compare the current scan results with stored baselines:

gate_diff target: "npm:dsh-plugin-some-package"
gate_diff target: "./downloaded-plugin" update: true

Generate structured reports for CI or ticket attachments:

gate_report target: "npm:dsh-plugin-some-package"
gate_report target: "./plugin" format: "json" write: true

Data Protection

Evaluate potentially destructive commands before execution:

gate_guard command: "rm -rf ./node_modules"
gate_guard path: ".dsh-memory-setup/memory.json" action: "delete"

Configuration

The plugin supports the following configuration (located in the DSH Profile or configuration file):

Configuration Item Default Description
maxFiles 1000 Maximum number of files to scan in a single directory traversal
maxFileBytes 2 MiB Maximum size for reading the text content of a single file
includeNodeModules false Whether to recursively scan the node_modules directory
maxTarballBytes 32 MiB Maximum download size for an npm tarball
allowlistHosts [] Host allowlist that should never be flagged as violations
osvCheck true Whether to perform OSV vulnerability queries for exact-version dependencies
osvMaxDeps 8 Maximum number of dependencies per OSV query
osvTimeoutMs 10000 Timeout for a single dependency OSV query (milliseconds)
promptSection true Whether to inject scanning behavior prompt guidance into the Agent

Notes

  • Dependency Requirements: Requires peer dependency support such as @deepseek-ai/dsh-tools and @deepseek-ai/cordis.
  • Compatibility: Compatible with dsh-tools versions 0.1.0-rc.6 and 0.1.1-rc.2. Earlier versions had JSON Schema syntax incompatibility causing Profile startup failure. If this error is encountered, remove or upgrade the plugin.
  • Scanning Limitations: This is a heuristic-based static scanner. It cannot detect previously unseen malicious code and may produce false positives by flagging ordinary code as suspicious.
  • Runtime Permissions: The plugin runs with the permissions of the current DSH process. It is recommended to check the source code and license before installation.

Summary

dsh-plugin-gate provides a line of defense for the DSH plugin ecosystem. Through static signature scanning and blocking destructive operations, it reduces the risk of introducing malicious code or accidentally deleting critical files. Combined with gate_diff and gate_report, security checks can be automated in CI pipelines or development workflows.