Preface¶
DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture, allowing developers to extend functionality by installing various plugins. However, unstable components in the plugin ecosystem may trigger cascading effects: a poorly configured plugin can cause the entire tool layer to crash or interfere with the normal operation of other plugins. When deploying or maintaining a DSH environment, it is essential to identify these potential risks.
dsh-stability-audit is an audit tool designed for this purpose. It scans installed plugins through static analysis, assesses stability risks (including hook surface, startup tasks, preflight health, and dependencies), and provides remediation recommendations. This avoids passive troubleshooting after a plugin has actually damaged the Harness.
What is dsh-stability-audit¶
dsh-stability-audit is an audit plugin that runs in the DSH environment and is maintained by community developer chunfenxiazhi-collab. It performs stability grading (🔴/🟡/🟢) through static code analysis and optional isolated installation verification, and gives specific remediation recommendations. The tool aims to help developers assess potential risks before installing new plugins or upgrading existing ones.
Core Features¶
The plugin provides the following core capabilities:
- Static stability analysis: Scans a plugin’s hook surface, startup tasks, preflight, and dependencies to identify potential structural issues.
- Optional isolated installation verification: Tests the plugin in an isolated environment to verify that it can be installed independently and start normally.
- Risk grading and remediation recommendations: Assigns a rating of 🔴 (high risk), 🟡 (medium risk), or 🟢 (low risk) based on analysis results, and provides specific remediation commands or operational guidance.
- Remote pre-review capability: Supports remote pre-review of plugins from online repositories (such as
owner/repo) without local installation. - Batch testing support: Supports batch stability testing for multiple online plugins.
- Machine-readable output: Provides JSON-formatted output for direct consumption and processing by other Agents or scripts.
- Zero side effects: Runs in read-only mode, never executes the audited plugin code, and keeps the environment safe.
Installation and Enablement¶
Run the following command in the terminal to install the plugin:
dsh plugin --profile web add dsh-stability-audit
After installation, restart the DSH Web service. After restart, the Agent can invoke this tool for auditing using the natural-language instruction “run the plugin stability audit”.
Typical Usage¶
In addition to invoking it through natural-language instructions in the Web interface, the tool also provides a command-line interface (CLI) that supports different audit modes.
Local Scan¶
Scan the stability of plugins installed in the current Web Profile:
node cli.mjs
Machine-Readable Output¶
Retrieve structured JSON data for processing by automation scripts:
node cli.mjs --
Remote Pre-Review (Full Workflow)¶
Clone the remote repository and perform static analysis and isolated installation testing:
node cli.mjs --remote owner/repo --dynamic
Remote Pre-Review (JSON Output)¶
Perform static analysis on the remote plugin only and output JSON:
node cli.mjs --remote owner/repo --
Applicable Scenarios and Cautions¶
Applicable Scenarios¶
- Pre-introduction assessment: Perform remote pre-review before installing community plugins from unknown sources.
- Existing environment inspection: Periodically scan installed plugins to discover potential instability risks.
- Batch maintenance: During updates of multiple plugins, use batch testing to quickly filter problematic packages.
Cautions¶
- Limitations of static analysis: Static analysis cannot fully simulate runtime behavior (such as certain Hooks throwing in specific contexts). A 🔴 level typically means “manual inspection is required” rather than an absolute conclusion that the plugin is broken.
- Limitations of the isolated environment: Isolated tests use a headless Profile. If a plugin depends on Web-exclusive services (such as
storageDomain), it may show a false negative (❌) in the isolated environment, but this only serves as a hint about environment dependencies. - Runtime probing: Runtime performance probing such as event-loop latency is not currently supported; related features are on the v2 roadmap.
- Nature of remediation recommendations: The remediation recommendations provided by the tool are only hints and are not applied automatically. Due to environment differences, manual confirmation is recommended before applying fixes.
- Read-only mode: The tool runs in read-only mode throughout; it does not execute the audited plugin code and does not produce side effects in the DSH environment.
Summary¶
dsh-stability-audit is a practical security audit tool. Through static rules and isolated testing, it makes potential risks in the plugin ecosystem explicit. Developers can use it to establish a plugin admission mechanism and reduce Harness crashes caused by plugin failures.
Directory page: chunfenxiazhi-collab/dsh-stability-audit
Source repository: chunfenxiazhi-collab/dsh-stability-audit