安装
npx -y @deepseek-ai/dsh plugin --profile web add github:unStone/dsh-xray此安装命令根据 GitHub 仓库地址生成,是未经验证的安装起点。
README
维护者编写的文档快照。
最近一次目录同步未能刷新此 README 快照。
dsh-xray
X-ray for DeepSeek Harness plugins — what they declare vs. what their code actually does.
给每个 dsh 插件拍一张 X 光片:声明了什么权限,代码实际在做什么。
🔍 Website: unstone.github.io/dsh-xray · Registry: /registry.html — English / 简体中文 / 日本語
Why
The dsh-plugin ecosystem went from ~200 to 6,900+ repos in 30 days. Plugins run arbitrary code inside your agent runtime: they can rewrite your system prompt (system-prompt/assemble), intercept every API call (api/gate), spawn subprocesses, read GITHUB_TOKEN from your env, and even patch the runtime itself (manifest.bundle.patch). Today nothing surfaces any of that before you install.
dsh-xray statically scans every plugin in the ecosystem and publishes a capability card:
| Dimension | Examples |
|---|---|
| Declared surface | manifest, injected services, registered tools, hooks |
| Powerful capabilities | systemPrompt / apiProxy / subprocess injection, tools/pre-execute gate, runtime patches |
| Sensitive behavior | exec / eval / base64 decode in shipped code, install-time scripts, outbound domains, credential-like env reads |
| Transparency gaps | capability used in code but absent from the manifest |
Every flag carries file:line evidence. Levels C0–C3 measure capability surface and transparency — not maliciousness. A C3 plugin can be perfectly legitimate; you just deserve to know before it touches your agent.
Badge
Plugin authors: show users your capability card.
[](https://unstone.github.io/dsh-xray/registry.html#<owner>__<repo>)
Run it yourself
python scanner/discover.py 3 # top repos via topic:dsh-plugin (needs gh auth)
cd scanner && python pipeline.py 200 8 # tarball-download + scan, no git clone
Outputs: data/scans/*.json (full cards), docs/data.json (site data), docs/badge/*.json (shields endpoints).
A daily GitHub Action (.github/workflows/scan.yml) refreshes everything. Pushing that file needs the workflow OAuth scope:
gh auth refresh -s workflow && git -C . add .github/workflows/scan.yml && git commit -m "ci: daily scan" && git push
Methodology & fair play
- Static analysis only; nothing is executed.
- Shipped code and test/dev code are classified separately; risk flags fire on shipped code only.
- False positive? Open an issue — cards link evidence so disputes are checkable, and rules get fixed in public.
Roadmap
- Full-ecosystem coverage (6.9k repos) + daily diff feed ("what changed in plugins you use")
-
cordis.patch.ymlruntime-patch audit view - Install-gate companion plugin: block/ask on C2+ installs from inside dsh
- Multi-harness: Abu-Cowork & Claude Code plugin formats
- Private registry / org policy engine (enterprise)
Apache-2.0
项目文件与信号
以下项目是目录快照中检测到的公开仓库信号。
仓库信息
- 开发语言
- Python
- 许可证
- Apache-2.0
- 最后更新
- 2026年8月18日 08:33
谨慎安装
请检查源代码、权限、生命周期脚本、依赖与网络访问;不受信任的插件应先在隔离环境中测试。