863683348/dsh-plugin-gate
Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".
An installation safety gate and data-protection guard for DeepSeek Harness. A gate_scan tool runs 60 static signature rules (31 high / 24 medium / 5 low severity) over plugin sources to catch malicious install scripts, credential theft, obfuscation and network callbacks before you run dsh plugin add, and the plugin also blocks destructive commands with 12 patterns plus workspace-boundary checks so rm -rf-class accidents stop before they happen. Exact-version direct dependencies are checked against Google OSV through the supply-chain rule, skipping ranges and official @deepseek-ai packages, with the check configurable and degrading to offline. The README documents verdict semantics and pins scans to explicit versions.
Install
dsh plugin --profile <profile> add dsh-plugin-gateREADME Install section quoted verbatim (replace <profile>). Registry-verified live 2026-09-15: dsh-plugin-gate 1.3.2 (published 2026-09-11) with a matching repository field (github.com/863683348/dsh-plugin-gate). The README's compatibility note records that tool schemas are validated against the @deepseek-ai/dsh-tools value-schema DSL at plugin load (checked against dsh-tools 0.1.0-rc.6 and 0.1.1-rc.2) and that earlier releases used JSON-Schema required at the root of output.schema, which could make the host abort the whole profile boot with unsupported JSON schema: schema.required is not supported by the value schema DSL — current releases fix both, and if an affected version left DSH unable to start you remove the plugin from the profile or upgrade, with no data lost.
Compatibility
Installs into a DSH profile and needs the profile to boot after load, so match it to a dsh-tools version whose value-schema DSL accepts the tool schemas (the README verified 0.1.0-rc.6 and 0.1.1-rc.2). The OSV supply-chain check is configurable and degrades to offline.
Details
- Repo: 863683348/dsh-plugin-gate
- Category: Development & Runtime
- Stars: 0
- Version: npm dsh-plugin-gate 1.3.2 (registry-verified 2026-09-15)
- Last push: 2026-08-18
- First seen: 2026-08-17
Recent updates
The README documents the rule set, scan usage and verdict semantics rather than a release table; the registry version when checked on 2026-09-15 was 1.3.2, and the README's own notes cover the v1.3 baselines-and-reports work and the v1.1 data-protection guard.
FAQ
- When does it check a plugin?
- The README says it scans plugin sources for malicious install scripts, credential theft, obfuscation and network callbacks before you run dsh plugin add, via the gate_scan tool.
- Does it need network access?
- Only for the optional OSV dependency check; the README states that check is configurable and degrades to offline.
- What if an older version broke my DSH startup?
- The README says earlier releases could abort profile boot with an unsupported-JSON-schema error; current releases fix it, and the remedy is to remove the plugin from the profile or upgrade — no data is lost.
Alternatives
ai-eks/dsh-auth-tunnel · Airmetro/dsh-update-checker · AngelosZou/graphlint#integrations/dsh