Introduction¶
DeepSeek Harness (DSH) adopts the “everything is a plugin” architecture, and the plugin ecosystem is rapidly expanding. As the number of plugins in the catalog surges, the risk of malicious code being mixed into plugin installation scripts, credential theft, or network callbacks also increases. dsh-plugin-gate is a security plugin designed for this purpose. Before running dsh plugin add, it performs a static scan of the plugin source code and can block or warn before dangerous commands are executed.
Plugin Overview¶
- Plugin Name:
dsh-plugin-gate - Maintainer: 863683348
- Open Source License: MIT
- Core Positioning: An installation security gate and data protection guard for DeepSeek Harness.
Core Features¶
The plugin mainly provides three capabilities:
-
Installation Source Scanning
- Uses 60 static rules to scan plugin source code. The rules are divided into three severity levels: high (31), medium (24), and low (5).
- Scanned content covers malicious installation scripts, credential theft, code obfuscation, and network callbacks.
- Supports scanning targets as
npm tarballor local directories. - Checks known supply-chain vulnerabilities through Google OSV.
- Security Feature: The scanning process is read-only. It never executes the scanned code and does not write files to disk.
-
Diff Reports
- Generates baselines for comparing historical scan results.
- Provides the
gate_difftool to identify newly added, resolved, or changed risk points.
-
Data Protection Guard
- Provides the
gate_guardtool to assess risks before destructive operations are executed. - Checks whether the target path is within the current workspace boundary and whether it is a critical file (such as
.gitormemory.json). - Based on signatures of
rm -rf-style commands, returns a verdict ofBLOCK,WARN, orPASS.
- Provides the
Installation¶
Add the plugin to a DSH Profile configuration:
dsh plugin --profile <profile> add dsh-plugin-gate
Typical Usage¶
Scan plugin source code before installation:
gate_scan target: "npm:dsh-plugin-some-package"
gate_scan target: "npm:dsh-plugin-some-package@1.2.3"
gate_scan target: "./downloaded-plugin"
Baselines and Reports¶
Compare the current scan results with stored baselines:
gate_diff target: "npm:dsh-plugin-some-package"
gate_diff target: "./downloaded-plugin" update: true
Generate structured reports for CI or ticket attachments:
gate_report target: "npm:dsh-plugin-some-package"
gate_report target: "./plugin" format: "json" write: true
Data Protection¶
Evaluate potentially destructive commands before execution:
gate_guard command: "rm -rf ./node_modules"
gate_guard path: ".dsh-memory-setup/memory.json" action: "delete"
Configuration¶
The plugin supports the following configuration (located in the DSH Profile or configuration file):
| Configuration Item | Default | Description |
|---|---|---|
maxFiles |
1000 | Maximum number of files to scan in a single directory traversal |
maxFileBytes |
2 MiB | Maximum size for reading the text content of a single file |
includeNodeModules |
false | Whether to recursively scan the node_modules directory |
maxTarballBytes |
32 MiB | Maximum download size for an npm tarball |
allowlistHosts |
[] | Host allowlist that should never be flagged as violations |
osvCheck |
true | Whether to perform OSV vulnerability queries for exact-version dependencies |
osvMaxDeps |
8 | Maximum number of dependencies per OSV query |
osvTimeoutMs |
10000 | Timeout for a single dependency OSV query (milliseconds) |
promptSection |
true | Whether to inject scanning behavior prompt guidance into the Agent |
Notes¶
- Dependency Requirements: Requires peer dependency support such as
@deepseek-ai/dsh-toolsand@deepseek-ai/cordis. - Compatibility: Compatible with
dsh-toolsversions 0.1.0-rc.6 and 0.1.1-rc.2. Earlier versions had JSON Schema syntax incompatibility causing Profile startup failure. If this error is encountered, remove or upgrade the plugin. - Scanning Limitations: This is a heuristic-based static scanner. It cannot detect previously unseen malicious code and may produce false positives by flagging ordinary code as suspicious.
- Runtime Permissions: The plugin runs with the permissions of the current DSH process. It is recommended to check the source code and license before installation.
Summary¶
dsh-plugin-gate provides a line of defense for the DSH plugin ecosystem. Through static signature scanning and blocking destructive operations, it reduces the risk of introducing malicious code or accidentally deleting critical files. Combined with gate_diff and gate_report, security checks can be automated in CI pipelines or development workflows.