MkaliezZ / dsh-plugin-firewall

Listed

Offline-first static admission scanner for DeepSeek Harness community plugins: inspect a plugin package before you trust it.

mainTool View source

Installation

npx -y @deepseek-ai/dsh plugin --profile web add github:MkaliezZ/dsh-plugin-firewall

This installation command is an unverified starting point generated from the GitHub repository address.

README

Maintainer-authored documentation snapshot.

View on GitHub ↗
Commit 5bad351Synced Aug 18, 2026

dsh-plugin-firewall

Offline-first static admission scanner for DeepSeek Harness community plugins.

/plugin-firewall <path> inspects a local plugin package before you trust it. v0.1 looks for package install scripts, git/URL dependencies, native addons, Cordis/profile patches, tool registration, process/network/filesystem/environment access indicators, and emits a deterministic risk receipt with a SHA-256 digest.

v0.1 goals

  • no network calls or vulnerability database;
  • deterministic local analysis;
  • explicit LOW / MEDIUM / HIGH findings;
  • JSON-safe receipt with digest;
  • never executes the scanned plugin;
  • does not claim malware detection or complete supply-chain safety.

Development

npm install
npm test

License

MIT

Project files and signals

Shown items are public repository signals detected in the directory snapshot.

TestsDetected

Repository information

Language
TypeScript
License
Not reported
Last updated
Aug 15, 2026, 7:02 AM

Install deliberately

Review source code, permissions, lifecycle hooks, dependencies and network access. Test untrusted plugins in an isolated environment.