DSH Plugins Marketplace

DSH Plugins

Plugins

/

Security & Audit

/

dsh-plugin-update-audit

M

dsh-plugin-update-audit

Manifest valid

Read-only update auditing for DeepSeek Harness profile plugins

hasBundlePatch

dsh-plugin-update-audit

Read-only update auditing for direct plugin dependencies in a DeepSeek Harness Profile.

The plugin adds one tool, plugin_update_audit. It inventories the selected Profile and checks each direct dependency according to its declared source:

  • npm dependencies are compared with the official npm Registry latest manifest;
  • GitHub dependencies are compared with the repository's current HEAD through the GitHub API;
  • local tarballs and directories are reported as manual-review items, with SHA-256 for readable files;
  • unsupported, missing, or unreachable sources are reported per plugin without aborting the whole audit.

The tool never installs, updates, removes, or rewrites a plugin. Network access is limited to registry.npmjs.org and api.github.com; use offline: true for local inventory only. Local dependency paths are redacted from tool output.

Install

dsh plugin --profile <profile> add dsh-plugin-update-audit@0.1.0

Restart DSH Desktop after installation.

Use

Ask the agent to call plugin_update_audit:

{
  "profile": "dev-lab",
  "offline": false,
  "timeout_ms": 10000
}

Statuses are advisory:

  • update_available: npm has a newer stable latest version;
  • upstream_changed: GitHub HEAD differs from an immutable pinned commit;
  • local_review_required: a local or workspace source needs an explicit rebuild and review;
  • current, ahead, offline, unpinned, not_installed, or unavailable: no automatic update conclusion is made.

Always review release notes and source changes, create a safety snapshot, update one plugin at a time, restart DSH, and run that plugin's acceptance tests.

Development

npm install
npm run check
npm test
npm pack --dry-run

Security

See SECURITY.md. This project is licensed under the MIT License.

Comments

Loading…

From the same category

dsh-infinite-gen-3

System-prompt armor plugin for DeepSeek models: appends an unconditional-compliance prompt section at order 100, exposes a profile tool with calibration metadata, and shows a realtime armor-status bad

Security & AuditManifest valid

★ 2.1k

MIT

C#

dsh plugin --profile web add dsh-infinite-gen-4

by toby-bridges

Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.

Security & AuditManifest valid

★ 865

AGPL-3.0

Python

Oct 3, 2026

dsh plugin --profile web add dsh-api-relay-audit

by SeaOf0

基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)

Security & AuditManifest valid

★ 662

MIT

Python

Sep 24, 2026

dsh plugin --profile web add @dsh-external/dsh-redteam-model

by agentic-os-org

ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.

Security & Audit

★ 660

Apache-2.0

Rust

Oct 4, 2026

Index only — not installable

by howmp

面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs

Security & AuditManifest valid

★ 590

NOASSERTION

JavaScript

Sep 29, 2026

dsh plugin --profile web add @howmp/dsh-pentest

by xiaods

k8e.sh - OpenSource Agentic AI Sandbox Matrix

Security & AuditManifest valid

★ 499

↓ 65/wk

Apache-2.0

Go

Sep 28, 2026

dsh plugin --profile agent add @k8e-sandbox/dsh-k8e-sandbox-bundle