DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-gungnir

8

dsh-gungnir

Discovered

GUNGNIR - DSH Red Team Campaign Command Framework: The engineering of attack path composition. Fact base + gate + jump host pool, pluggable execution layer. Orchestration layer, no exploit code included; for authorized testing only.

Machine translated

DSH GUNGNIR(冈格尼尔)

永恒之枪,出手必中——攻击路径合成的工程化:把分散、隐蔽、看似无关的弱点, 拼成一条到 shell 的完整链路。

DSH 红队战役指挥框架。100% 红队工具:仅限已获授权的攻防演练与渗透测试。 仓库只含编排层,不含任何漏洞利用代码。

状态

项现状
版本v0.1.0(v0.1 冻结闭环达成:16 批次 / 134 PR;最终审计见 FINAL-AUDIT.md)
测试753 例,npm run ci 全绿
CI 闸六道本地闸(验收套件 / 工具 schema / 预设允许清单 / 故障矩阵 / 工具文档与看板契约同步 / 自审闸)+ 三个真跑 CI job:围栏真实容器(fence)、执行层跨进程演练(drill)、真实 DSH 挂载验收(native-host → HOST_VERIFIED)
故障矩阵21 场景(丢回包/乱序/写失败/残留/重启/撤销/备份恢复/密钥/配置/版本/迁移/路由/心跳/知识库/交付边界/门禁/确认边界/归档幂等/门禁同源)
工具36 个 warroom_*(schema 严格校验;以 presets/warroom.preset.json 允许清单为准)
验收对照docs/ACCEPTANCE.md(逐条状态 + 证据命令)
最终审计docs/FINAL-AUDIT.md(§8 十二项 11/12 闭环;未闭环项均需操作员 DSH 环境)
故障矩阵docs/FAULT-MATRIX.md(21 场景:场景/期望/契约归属)

六件套与动线(一屏)

阶段命令产出
起好init → doctor → config init家目录、配置、体检
开工engage(授权冻结)→ jump acquire → egress → preflight可动手的战役 + 出口 + 预检结论
干活wave --dry-run(先演练)→ wave(依赖驱动)→ watch/rate(值班)事实入库、任务结项、油表可见
收口checklist(缺什么)→ deliver(一键交付)→ evidence/report报告(md/json/html,客户版/蓝队版)+ 证据包 + 门禁结论
留存weekly --archive → backup --keep 7 → aggregate周报、备份、跨会话聚合(只读)
对外gate-check.mjs(外部门禁)→ CI-INTEGRATION.md你的流水线可直接用

判断顺序:告警 → 油表 → 漂移;值班一屏 = watch(内置油表),跨战役 = watch --all。

规格与架构决策(本仓库为唯一真源)

治理:ADR 一经 Accepted 即不可变,修正以新 rev 重写并留修订记录;规格/doctrine 改动走 PR + RFC。 贡献流程、六闸门槛、写作用域与外部 PR 审查方式见 CONTRIBUTING.md(含 CODEOWNERS)。

快速开始(CLI,不依赖 DSH)

node bin/warroom.mjs engage --target 10.0.0.0/24 --rhythm open      # 开工指令即授权,冻结授权对象
node bin/warroom.mjs exec  --engagement eng_... --command-id c1 --target 10.0.0.5 --class active
node bin/warroom.mjs status --engagement eng_... --task wt_...
node bin/warroom.mjs cancel --engagement eng_... --task wt_...
node bin/warroom.mjs report --engagement eng_...
node bin/warroom.mjs secret put --plaintext '...' --label ssh-pw     # 明文只进加密库
node bin/warroom.mjs jump import --id jh-1 --addr-v4 203.0.113.9

全部子命令支持 --json;默认 home 为 $WARROOM_HOME 或 ./.warroom。

包结构

包平面内容
packages/shared-types共同契约状态机与迁移表、错误码、四元组/契约/回执校验
packages/warroom-corehost事实库(fact.db/global.db)、门闸 broker、跳板池、秘密库、报告、adapter(fake / redteam-mode / DSH 桥)
packages/warroom-toolsagent36 个 warroom_* 工具定义(允许清单制的唯一副作用入口)
packages/warroom-pluginDSH 插件host 服务骨架 + warroom_* 工具包装(挂载层入口)
presets/预设三角色(commander/recon/chain)+ 允许清单

测试与四闸

npm run ci                           # 六道闸一次跑完(推荐;验收套件 753 例)
node scripts/executor-drill.mjs      # 执行层落地演练(fake / --mode bridge)
node scripts/ci.mjs --quiet          # 只看汇总(别用 | tail,管道会吞退出码)
node --test                          # 只跑验收套件
node scripts/validate-tool-schemas.mjs   # 工具 schema(DSH 挂载硬要求)
node scripts/check-preset.mjs            # 预设允许清单闭合
node scripts/fault-matrix.mjs            # 故障矩阵 21 场景(与 docs/FAULT-MATRIX.md / SCENARIOS 同源)
node scripts/self-review.mjs             # 自审:秘密/链接/验收引用/代码卫生

数据位置

$WARROOM_HOME/engagements/<engagement_id>/fact.db(战役事实)+ $WARROOM_HOME/global.db (跳板/租约/op_log/命令队列/秘密)+ $WARROOM_HOME/secrets/(密钥,700/600,不随备份走)。

Comments

Loading…

Similar plugins

dsh-super-injector

by yjh051108

推荐组件(非必须):DeepSeek Harness 运行时注入器;已随 dsh-routing-suite 单仓库化保留,本仓库继续维护/发布。

Development & InfrastructureManifest valid

★ 166

TypeScript

Sep 18, 2026

dsh plugin --profile web add @dsh-external/dsh-super-injector

by Cavan-Ou

Battle-tested multi-agent collaboration playbook for DeepSeek Harness: model-tier routing, spec discipline, git single-writer rule — as an installable skill. 多 agent 管线里运行 DSH 的实战协作规范

Agent skillsManifest valid

★ 7

MIT

JavaScript

Sep 11, 2026

dsh plugin --profile web add hermes-dsh-collab

by 782042369

DSH compatibility guard: repairs compaction limits, fail-safe sandbox escalation, and missing tool descriptions for third-party models; capability lookups are cached and the deprecated prompt-injection path is off by default.

Tools & CapabilitiesSecurity & AuditManifest valid

★ 0

MIT

JavaScript

Sep 8, 2026

dsh plugin --profile web add dsh-model-compat-guard

by akira399

DSH 插件开发与 GitHub 发布工作流技能插件 (consent-gated) — develop, verify, publish & marketplace-visible DSH plugins

Terminal & ClientsDevelopment & InfrastructureManifest valid

★ 2

MIT

JavaScript

Aug 14, 2026

dsh plugin --profile web add dsh-plugin-publisher

by Areium

DeepSeek Harness(DSH)插件:自动记录所有执行模式(原生工具 / PTC run_code / 代码内嵌工具调用)的工具失败错因,去重、计数、确定性排序后沉淀进 skill 的机器维护实录区段——让 Agent 越用越少错。

Tools & CapabilitiesManifest valid

★ 10

↓ 109/wk

MIT

JavaScript

Sep 20, 2026

dsh plugin --profile web add dsh-fail-logger

by MkaliezZ

Dependency-installation guard for DeepSeek Harness: classifies package-manager commands as ALLOW, ASK, or BLOCK before execution.

Manifest valid

★ 0

TypeScript

Aug 29, 2026

dsh plugin --profile web add @mkaliezz/dsh-dependency-firewall