dsh-plugin-update-audit
Manifest validRead-only update auditing for DeepSeek Harness profile plugins
dsh-plugin-update-audit
Read-only update auditing for direct plugin dependencies in a DeepSeek Harness Profile.
The plugin adds one tool, plugin_update_audit. It inventories the selected Profile and checks each direct dependency according to its declared source:
- npm dependencies are compared with the official npm Registry
latestmanifest; - GitHub dependencies are compared with the repository's current
HEADthrough the GitHub API; - local tarballs and directories are reported as manual-review items, with SHA-256 for readable files;
- unsupported, missing, or unreachable sources are reported per plugin without aborting the whole audit.
The tool never installs, updates, removes, or rewrites a plugin. Network access is limited to registry.npmjs.org and api.github.com; use offline: true for local inventory only. Local dependency paths are redacted from tool output.
Install
dsh plugin --profile <profile> add dsh-plugin-update-audit@0.1.0
Restart DSH Desktop after installation.
Use
Ask the agent to call plugin_update_audit:
{
"profile": "dev-lab",
"offline": false,
"timeout_ms": 10000
}
Statuses are advisory:
update_available: npm has a newer stablelatestversion;upstream_changed: GitHubHEADdiffers from an immutable pinned commit;local_review_required: a local or workspace source needs an explicit rebuild and review;current,ahead,offline,unpinned,not_installed, orunavailable: no automatic update conclusion is made.
Always review release notes and source changes, create a safety snapshot, update one plugin at a time, restart DSH, and run that plugin's acceptance tests.
Development
npm install
npm run check
npm test
npm pack --dry-run
Security
See SECURITY.md. This project is licensed under the MIT License.
Comments
Loading…
From the same category
System-prompt armor plugin for DeepSeek models: appends an unconditional-compliance prompt section at order 100, exposes a profile tool with calibration metadata, and shows a realtime armor-status bad
★ 2.1k
MIT
C#
dsh plugin --profile web add dsh-infinite-gen-4by toby-bridges
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
★ 865
AGPL-3.0
Python
Oct 3, 2026
dsh plugin --profile web add dsh-api-relay-auditby SeaOf0
基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)
★ 662
MIT
Python
Sep 24, 2026
dsh plugin --profile web add @dsh-external/dsh-redteam-modelby agentic-os-org
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
★ 660
Apache-2.0
Rust
Oct 4, 2026
by howmp
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs
★ 590
NOASSERTION
JavaScript
Sep 29, 2026
dsh plugin --profile web add @howmp/dsh-pentestby xiaods
k8e.sh - OpenSource Agentic AI Sandbox Matrix
★ 499
↓ 65/wk
Apache-2.0
Go
Sep 28, 2026
dsh plugin --profile agent add @k8e-sandbox/dsh-k8e-sandbox-bundle