shaoshi20/dshscan
shaoshi20★ 8TypeScriptLast synced: 2026-08-21
Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.
README excerpt
DShScan English 中文 DSH 插件安全扫描器:对插件源码做静态与语义双通道检查,内置 DSH 特有攻击面规则,集成 npm audit,支持批量扫描,输出带严重等级与证据的 HTML 报告。 Demo 插件市场 已收录于 dshbase 插件目录 : 在线 Demo: 作为 DSH 插件安装: 功能 - 输入 :插件名 / GitHub 仓库地址 / 本地目录 / zip / Markdown 文件 - 输出 :JSON 报告,包含 risk score 、 severity 、 safe to install 、 recommendation 、 findings - 双通道扫描 : - 静态规则扫描(完全离线) - 可选 LLM 语义扫描(需 API Key) - dshbase 集成 :输入插件名时自动读取本地索引元数据(stars / trust / verified / npm / cmd) - npm 源码扫描 :npm 插件可自动 npm pack 下载并扫描包内容 - 依赖审计 :检查未锁定版本、远程依赖源、依赖包名仿冒;可选 --audit 调用 npm audit - DSH manifest 校验 :检查 dsh.bundle 、 cordis.patch.yml 、LICENSE、README - DSH 攻击面规则 :R010 插件树注入、R011 浏览器侧恶意代码、R012 profile 篡改、R013 manifest 混淆、R014 远程动态加载、R015 内置工具影子劫持 - Benchmark 评估集 :内置恶意/良性样例, dshscan --benchmark 输出查全率、误报率、F1 与逐规则指标 - 自定义规则 :支持 --rules 加载 JSON 规则 - 策略文件 :支持 --policy 配置 ignoreRules / severityOverrides / includeScopes / excludeScopes - 审计日志 :支持 --audit-log 以 JSONL 记录每个被标记项 - Web Dashboard :支持 --serve 启动本地可视化面板,内置风险分数趋势、发现数量趋势、严重级分布图,并自动把扫描历史写入 .dshscan-history.json - HTML 报告 :支持 --html 输出独立网页报告 - 误报处理 :每条 finding 都带证据 + 修复建议 - 批量扫描 :支持对 dshbase 插件目录批量扫描并输出汇总 JSON / HTML - 定时巡检 :GitHub Actions 每日自动拉取 dshbase 目录并批量扫描 安装与构建 构建后生成 dist/main.js ,可通过 dshscan.cmd 或 node dist/…
View full README on GitHub →Category
DeepSeek Harness: Everything is a Plugin.
★ 182,325
amruthpillai/reactive-resumeA one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!
★ 41,477
anywhere-labs/deepseek-harness-desktop为 DeepSeek Harness (DSH) 插件生态打造的现代化桌面端解决方案。万物皆「插件」,桌面本身也是「插件」。
★ 17,784