taxueseek / dsh-plugin-guard

Listed

DSH plugin gate + clinic: static audit before and after install, hash lock, peer search, mechanical detox. Never executes the target plugin.

mainTool View source

Installation

npx -y @deepseek-ai/dsh plugin --profile web add github:taxueseek/dsh-plugin-guard

This installation command is an unverified starting point generated from the GitHub repository address.

README

Maintainer-authored documentation snapshot.

View on GitHub ↗
Commit 7b7195eSynced Aug 18, 2026

dsh-plugin-guard

One plugin, two surfaces. Static analysis only — never executes the target plugin.

SurfaceToolJob
Gateplugin_auditStatic audit before install
Gateplugin_verifyHash + capability lock after install
Clinicplugin_peersLocal fingerprint peers; query searches GitHub topic:dsh-plugin
Clinicplugin_detoxMechanical amputation, not an equivalent rewrite

plugin_peers: path stays local (profile bundles). query hits GitHub topic:dsh-plugin + the curated list; argo only if those are thin. Override with remote. Remote hits are verdict=unknown — audit before install.

Install

dsh plugin --profile web add github:taxueseek/dsh-plugin-guard
# restart dsh web

Scoring

Start at 100; P0 −40, P1 −12, P2 −3. Any P0 or score < 40 → block. Any P1 or score < 75 → warn.

P0 is only auto-run + dangerous combo (curl|bash, secrets leaving the machine, eval of network content, install-script poison). exec inside a tool the model must click is P1.

Not

  • Not output redaction
  • Not general SAST
  • Does not prove a plugin is safe
  • Detox does not keep the original behavior

License

MIT

Project files and signals

Shown items are public repository signals detected in the directory snapshot.

TestsDetected

Repository information

Language
TypeScript
License
MIT
Last updated
Aug 16, 2026, 2:56 PM

Install deliberately

Review source code, permissions, lifecycle hooks, dependencies and network access. Test untrusted plugins in an isolated environment.