wj2514939573-ui / dsh-security-gate

Listed

SecurityGate(插件安检门)— inspect DSH plugins before install: dual-dimension static scan + LLM AI review + runtime watch + community ratings & bug bounty.

mainModelSkill View source

Installation

npx -y @deepseek-ai/dsh plugin --profile web add github:wj2514939573-ui/dsh-security-gate

This installation command is an unverified starting point generated from the GitHub repository address.

README

Maintainer-authored documentation snapshot.

View on GitHub ↗
Commit 6434a9cSynced Aug 18, 2026

🛡️ dsh-security-gate · 插件安检门 / SecurityGate

装插件,先过安检门。 A DSH (DeepSeek Harness / Cordis) plugin that inspects other plugins before you install them — static scan + AI review + runtime watch, community ratings and bug bounty.

  • Plugin ID: gate-2 · Package: pkg-18 (v1.0.0 / v10)
  • Platform: DeepSeek Harness dynamic Cordis plugin (Host + Client)

Why SecurityGate

dsh-plugin-marketplace validates plugins and dsh-suite tests compatibility, but those are after-the-fact checks. SecurityGate moves security to proactive defense before install:

                   ┌──────────────────────────────────────────┐
                   │   🛡️ SecurityGate · 插件安检门            │
   new plugin ───▶ │ ① Static scan (malicious score + caps)    │
                   │ ② 🤖 LLM AI review (false-positive check) │
                   │ ③ Runtime registry watch (live arrivals)  │
                   │ ④ Community ratings + bug bounty          │
                   │  → verdict & advice → install with trust  │
                   └──────────────────────────────────────────┘

Features

#FeatureDescription
1Dual-dimension scan恶意风险分 (malicious-risk score 0-100: dynamic code / shell / raw fs / obfuscation / policy bypass / persistence / exfil) separated from 权限能力面 (capability surface: network / file write / env read / services / tools — functional permissions, not malice)
2🤖 LLM AI reviewOne click: the current model re-judges static findings to filter false positives (gate_scan ai_review param)
3Runtime registry watchBaselines the visible tool set at startup, subscribes tools/change, tracks added/removed tools and recent arrivals
4New-tool alertA floating "🚨 new plugin tools detected" toast appears when any plugin registers tools during the session
5Quick accessA 🛡️ button in the session header opens a floating quick-scan panel — no need to open Settings
6Scan historyLast 20 scans persisted with the community store; per-entry verdict copy
7Share reportOne-click export + copy of a shareable inspection report with the "✅ passed SecurityGate" stamp
8Community ratings1-5 star security ratings + comments, leaderboard (local store; cloud sync on the roadmap)
9Bug bounty flowSubmit reports (critical 1000 / high 500 / medium 200 / low 50 pts), audit flow: pending → under review → confirmed (points awarded) / dismissed / fixed / blacklisted
10i18nzh-CN / en-US UI via the locale service (auto-falls back to Chinese)
11OnboardingA "SecurityGate is on duty" card in the Run card + in-app usage guide

Installation

This is a dynamic Cordis plugin for DSH. Two ways:

The file plugin/source.json contains the exact cordis_define payload:

plugin:  { kind: 'new', idPrefix: 'gate' }
name:    security-gate 插件安检门
purpose: 安装插件前先过安检门:双维静态安全扫描(恶意风险分 + 权限能力面)、
         LLM AI 复核、运行时注册观察、社区安全评分与漏洞赏金。
code.host:    plugin/host.js (or host.raw.js)
code.client:  plugin/client.js (or client.raw.js)

Ask your DSH agent to define it with code.host = plugin/host.raw.js content and code.client = plugin/client.raw.js content, then run it. Approve the client half when prompted.

B. Manual copy

plugin/host.raw.js and plugin/client.raw.js are the bare function bodies exactly as recorded by the Host — paste them into cordis_define.

How to use

Settings UI: Sidebar → Settings → 🛡️ 插件安检门

  • 🧪 Preview Sandbox: paste source or scan a local file/directory → risk score, capability surface, findings (with line numbers), dry-run trace, advice; 🤖 AI Review button
  • ⭐ Community Ratings: rate plugins 1-5 stars, leaderboard
  • 🐛 Bug Bounty: submit reports, drive the audit status flow

Conversation: just say "用安检门扫一下这个插件" — the model calls gate_scan automatically. Four model tools:

ToolPurpose
gate_scanstatic scan + dry-run preview; source or path; optional ai_review
gate_registryruntime registry watch: tools added/removed since gate start, recent arrivals
gate_ratesubmit a 1-5 star community rating
gate_reportsubmit a bug bounty report

Architecture

Host (Node process):
  static scan engine (7 malicious rules × weights → 0-100 score; 4 capability markers)
  AI review (llm service + agentDefaultModel, JSON verdict parsing)
  runtime watcher (tools baseline + tools/change subscription, arrivals log)
  community store (ratings + reports + history, persisted to <workspace>/.security-gate-store.json)
  scan history + share-text exporter
  4 model tools + 11 package-private RPCs
Client (browser):
  settings page (3 tabs) + usage guide (i18n)
  session-header 🛡️ quick button + floating quick-scan panel
  floating new-arrival alert (8s poll)
  Run card "on duty" status card

Data & privacy

  • Community data lives locally: <workspace>/.security-gate-store.json (ratings, reports, scan history)
  • SecurityGate itself makes no network calls (the plugin's own runtime sends nothing anywhere)
  • Scanning is read-only: inspected code is never executed
  • AI review sends only scan findings/snippets to the configured model

Roadmap

  • v2.0: cloud community backend (shared ratings / blacklist / bounty across users — minimal JSON API or serverless)
  • Cloud preview sandbox backend (e2b / container) behind the backend seam
  • Marketplace integration (install button → inspection gate)
  • Behavior signature library (known-malicious fingerprints + auto-blacklist)

License

MIT — see LICENSE.

Project files and signals

Shown items are public repository signals detected in the directory snapshot.

Plugin manifestDetected
Security policyDetected

Repository information

Language
JavaScript
License
MIT
Last updated
Aug 16, 2026, 4:29 PM

Install deliberately

Review source code, permissions, lifecycle hooks, dependencies and network access. Test untrusted plugins in an isolated environment.