Xrainsmile/DSH-Plugin-Doctor
Compatibility, security, isolated install, and rollback doctor for DeepSeek Harness plugin bundles
DSH Plugin Doctor audits DeepSeek Harness npm bundles before they reach a real Profile. It validates the Bundle manifest, scans risky behavior, installs into a temporary DSH_HOME, boots the Web Profile, and produces machine- and human-readable reports (JSON, Markdown and a badge SVG under reports/). It can also install with automatic Profile rollback: acquisition uses npm pack --ignore-scripts so static inspection never executes the target package, and isolated/real installs pass --ignore-scripts too; strict mode (--strict --allow-permission hooks) blocks unacknowledged high-risk permissions. The doctor follows the official DSH quickstart for isolated installs.
Install
npm install -g dsh-plugin-doctornpm dsh-plugin-doctor 0.1.1 verified 2026-09-03 (repository field → github.com/Xrainsmile/DSH-Plugin-Doctor; README EN primary). This is a global CLI doctor for plugin bundles, not a profile plugin: npm install -g dsh-plugin-doctor, then dsh-plugin-doctor check . for a local checkout, dsh-plugin-doctor check <pkg> --dsh-version 0.1.0-rc.6 for a published package against specific DSH releases, dsh-plugin-doctor install <pkg> --profile web to isolate-test then install into a real profile, and dsh-plugin-doctor rollback --profile web to restore the last profile snapshot. Node 24 recommended for isolated checks (DSH itself requires Node ^22.19 || >=24).
Compatibility
Node ^22.19 || >=24 (24 recommended); audits npm bundles against DSH releases (e.g. 0.1.0-rc.2/rc.3/rc.6); npm pack --ignore-scripts acquisition.
Details
- Repo: Xrainsmile/DSH-Plugin-Doctor
- Category: Other
- Stars: 0
- Version: npm dsh-plugin-doctor 0.1.1
- Last push: 2026-08-19
- First seen: 2026-08-14
Recent updates
Manifest validation + risky-behavior scan; isolated temp-DSH_HOME install and boot test; JSON/MD/badge reports; install with auto-rollback; --ignore-scripts throughout; strict high-risk-permission mode.
FAQ
- What does check do?
- Validates a local checkout or npm package's Bundle manifest, scans risky behavior statically (npm pack --ignore-scripts, so nothing executes), installs into a temporary DSH_HOME, boots the Web Profile and writes reports.
- Can it install plugins into my real profile?
- Yes — dsh-plugin-doctor install <pkg> --profile web audit-tests then installs, and rollback --profile web restores the latest saved Profile snapshot.
- Is this a runtime plugin for DSH?
- No — it is a global CLI that audits bundles before they reach a profile; it is not itself loaded as a profile plugin.
Alternatives
bowenliang123/dsh-plugin-checker · BotonJ/dsh-plugin-sentinel · deLightor-dsh-depguard