Preface

The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When developers need to introduce third-party plugins or review community code, running or installing them directly may introduce risks, including prompt injection, supply-chain poisoning, or potentially malicious behavior. dsh-plugin-guard aims to address this pre-installation validation problem by providing static security scanning capabilities.

Purpose

This is a pre-installation security check plugin for DeepSeek Harness plugins. It is offline and read-only by default, does not execute the scanned code, does not follow symbolic links, and does not send plugin content to large models or third-party services.

The plugin is maintained by developer MangShe3-0 and uses the MIT License.

Core Features

The plugin uses static analysis to check for the following risk signals:

  • Prompt injection: Covers system/user instructions, hidden behavior, poisoning of tool descriptions, and covert commands in Chinese and English.
  • File extortion and destruction: Recursive deletion, disk formatting, permission corruption, bulk encryption, and ransom notes.
  • Credential and data exfiltration: Environment variable enumeration, SSH/cloud credentials, browser data, and secrets-to-network chains.
  • Supply chain: Installation lifecycle scripts, download-and-execute, unpinned dependencies, and encoded payloads.
  • Dynamic execution and privilege escalation: eval, shell/subprocess, persistence, self-modification, and disabling TLS validation.
  • DSH metadata: parseability of package.json and dsh.bundle.patch activation declarations.
  • Unicode deception: Zero-width characters and bidirectional control characters.

Installation and Enablement

Before installing, make sure a tarball package has been generated in the current directory:

npm pack

Then install the package into the same profile that actually launches the Web UI. The official default Web UI usually uses the web profile:

dsh plugin --profile web add ./dsh-plugin-guard-0.1.1.tgz
dsh --profile web --dump-config

If id: plugin-guard appears in the configuration, the installation was successful. Then stop and rerun dsh web; creating a new conversation will make the plugin_guard_scan tool available. Users with custom profiles should replace web in the commands above with their actual profile name.

Typical Usage

Using It in Harness

Download or extract the plugin to be reviewed into the current workspace, then ask Harness in the conversation to scan it:

Use plugin_guard_scan to scan ./untrusted-plugin. Do not install or run it yet.

The tool by default only allows scanning session.header.cwd that has been validated in the current DSH session. Relative paths are resolved against that session workspace. To scan additional directories, set the environment variable before starting Harness:

export DSH_PLUGIN_GUARD_ROOTS="/absolute/review/inbox:/another/allowed/root"

Standalone Command Line

You can scan directly without installing it into Harness:

node ./bin/dsh-plugin-guard.js /path/to/plugin
node ./bin/dsh-plugin-guard.js /path/to/plugin --json

Exit Code Descriptions

  • 0: Proceed with manual review.
  • 1: Caution; some risks are present.
  • 2: Do not install; high-severity risks are present.
  • 3: Scan failed.

Verification and Testing

The plugin includes a test suite to ensure the scanning logic is correct:

npm test
npm run check

Use Cases and Notes

This tool is intended for developers who need to perform security assessments before introducing external DSH plugins. It is based on static rule analysis; an exit code of 0 only means “manual review may continue,” not “absolutely safe.”

Known limitations:
* Static scanning can only detect known risk signals and cannot prove that a plugin is safe.
* It does not analyze images, encrypted files, compiled binaries, or actual behavior after runtime downloading.
* Regular expression rules may produce false positives and may also be bypassed by advanced obfuscation.
* It does not query OSV/CVE online; dependency vulnerabilities must be checked separately using trusted SCA tools.
* It does not replace sandboxing, least privilege, network egress controls, manual code review, or recoverable backups.

References

  • Project URL: https://github.com/MangShe3-0/dsh-plugin-guard
  • Directory page: https://www.skillhub.cn/plugins/MangShe3-0/dsh-plugin-guard