mirage
strukto-ai
The World's First Unified Virtual Filesystem For AI Agents
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:Eligahyu/dsh-sentinel
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
给 DeepSeek Harness 插件拍 X 光 · Plugin security & health scanner for DSH
一个零依赖、只读的 DSH 插件安全体检中心:静态启发式扫描代码执行、凭据窃取、数据外传、混淆、安装脚本与 bundle 清单合规,输出 0–100 风险分 + 裁决,并给出每一条命中的修复建议。
既可以装进 DeepSeek Harness 当 Agent 工具(sentinel_scan / sentinel_scan_profile),也可以作为 独立 CLI(npx dsh-sentinel)在 CI 里使用。
Node ≥ 18.17 · 零运行时依赖 · 不执行被扫描代码 · MIT
DeepSeek Harness 插件生态在爆发:截至 2026-08,仅 awesome-dsh-plugin 就收录了 4798 个经核实的插件仓库——其中 253 个被维护者拉黑或剔除。而插件本质上等于"让你的 AI 在完整权限下执行任意代码"(安装脚本甚至绕过沙箱直接运行),供应链风险是生态最大的隐忧。
但环顾生态:4798 个插件,几乎没有头部做"插件的安全体检"。本项目的目标就是填补这个空白:
⚠️ 免责声明:启发式静态扫描 ≠ 安全保证。命中只表示"需要人工复核",未命中不代表绝对安全。绝不要因为一份"safe"报告就盲目信任插件。
| 能力 | 说明 |
|---|---|
| 🔍 规则引擎 | 30+ 条启发式规则,覆盖 9 大类别(见 规则目录) |
| 🎯 双重形态 | DSH 工具插件(sentinel_scan / sentinel_scan_profile)+ 独立 CLI |
| 📦 清单体检 | 校验 dsh.bundle / cordis.patch.yml / 插件入口导出契约(对照 DSH loader 行为) |
| 🧹 全量审计 | sentinel_scan_profile 一键扫描 profile 里所有第三方插件(内置 @deepseek-ai/* 自动跳过,命中项标注所属包) |
| 📊 量化裁决 | 0–100 风险分 + safe / review / risky / dangerous 四级裁决,CI 友好退出码 |
| 🔒 只读安全 | 不执行被扫描代码、不跟随符号链接、跳过二进制,扫描器本身零依赖 |
| 🧪 自带验证 | 11 项自动化测试 + 恶意/正常/损坏三种 fixture |
# 本地目录安装
dsh plugin --profile web add ./dsh-sentinel
# 或从 GitHub 安装
dsh plugin --profile web add github:Eligahyu/dsh-sentinel
# npm 发布后(推荐,无需构建授权;npm 包名 deepseek-harness-sentinel,
# 因为 "dsh-sentinel" 在 npm 上已被占用):
dsh plugin --profile web add deepseek-harness-sentinel
dsh --profile web
然后在对话里直接说:
"用 sentinel_scan 检查一下
~/Downloads/some-plugin这个目录" "用 sentinel_scan_profile 审计一下我 web profile 里装的所有插件"
模型会调用工具并返回:
🚨 DANGEROUS (risk score 100/100)
scanned 3 files · 20 findings: critical 5 · high 9 · medium 4 · low 2 · info 0
manifest: evil-plugin@0.1.0 · isBundle=true · patch=./cordis.patch.yml
Top findings:
[critical] SEN-EXFIL-001 plugin/index.js:22 — 可疑数据外传端点(webhook / pastebin / 隧道 / 监听服务)
[critical] SEN-CRED-001 plugin/index.js:15 — 读取凭据文件(SSH 私钥 / AWS / npmrc / kubeconfig 等)
...
# 不安装、直接跑(零依赖)
npx dsh-sentinel <插件目录> # 或 node bin/sentinel.mjs <目录>
# CI 集成:exit 0 = safe/review,exit 1 = risky/dangerous
dsh-sentinel ./some-plugin --json --out report.json
dsh-sentinel --profile web # 审计整个 profile 的第三方插件
dsh-sentinel --rules # 打印规则目录
✅ SAFE — risk score 0/100
─────────────────────────────────────────────
target packages/bundle/web-app
manifest @deepseek-ai/dsh-web-app@0.1.0-rc.5 · isBundle=true · patch=./cordis.patch.yml
files 28 scanned (0 binary skipped)
findings 0 total · CRITICAL 0 · HIGH 0 · MEDIUM 0 · low 0 · info 0
scan time 18 ms
上面的示例是对 DeepSeek Harness 官方 dsh-web-app bundle 的真实扫描结果;对恶意 fixture 的完整报告见 docs/example-report.json。
| 严重度 | 权重 | 示例 |
|---|---|---|
| 🔴 critical | 50 | 远程代码下载执行、读取 SSH 私钥、外传端点、rm -rf $HOME、安装脚本含网络下载 |
| 🟠 high | 20 | eval、硬编码密钥、env 凭据读取、入口契约缺失 |
| 🟡 medium | 8 | shell 执行、网络调用、写入工作区外、安装生命周期脚本(需人工确认)、patch 解析问题 |
| 🟢 low | 3 | 编码载荷混用、硬编码公网 IP、缺 license/description |
| ⚪ info | 0 | 统计信息 |
总分封顶 100:0–19 ✅ safe · 20–49 👀 review · 50–79 ⚠️ risky · 80–100 🚨 dangerous——单条 critical(50 分)即达 risky,两条即 dangerous。
测试上下文:位于
test/、tests/、__tests__/等目录或*.spec.*、*.test.*、*.e2e.*文件中的命中会打上(test)标记并降一级计分(测试 fixture 通常是故意构造的恶意字符串/二进制数据),但仍完整列出、不隐藏。降噪设计:纯注释行不触发执行类规则(避免 JSDoc 里提到
spawn()被误报);同一规则在同一文件的命中最多记 10 条(能力证明即可,避免刷屏);chmod 0o600/0o700等严格权限是良好实践,只对宽松权限(777/666)告警;prepare: npm run build这类 DSH 官方推荐的构建脚本按 medium 复核项处理。
完整规则目录(30+ 条,含检测模式说明)见 docs/rules.md。
插件仓库/目录 ──► collectFiles(跳过 .git/node_modules/二进制/符号链接)
──► 逐文件跑 30+ 条启发式规则(行级 + 全文级正则)
──► inspectBundle:package.json + cordis.patch.yml 清单合规
──► 加权计分 → 裁决 → 结构化 JSON 报告
node bin/sentinel.mjs engine
会命中 SEN-FS-001/SEN-EXEC-003 等——因为规则库文件本身含有 rm -rf、eval( 这些规则字面量。这是模式扫描的固有行为(自指误报),也是项目诚实性的体现:规则作者同样需要人工复核。
用 DeepSeek Harness 官方仓库的 15 个包 + 示例组合做过一轮批量扫描,验证规则不失控:
| 语料 | 结果 |
|---|---|
官方 bundle(base/headless/web-app) |
✅ safe · 0 分 |
纯库包(tool-todo/tool-bash/hooks 等) |
👀 review · 仅"非 bundle"提示(正确) |
能力型工具包(tool-fs-search/tool-web/llm-deepseek) |
👀 review~risky · 命中均为正当"需复核"项(spawn ripgrep / fetch / 读 API key env) |
测试文件(tests/*.e2e.ts 等) |
全部正确打上 (test) 标记,不再扭曲评分 |
这轮狗粮还让扫描器自身修掉 3 个缺陷:patch 指向包根时未解析 main 字段、入口契约不认 export default { name, apply } 对象、测试文件命中按原严重度计分导致误判(现降一级计分)。
dsh-sentinel-action 自动审计 PR 里的插件改动dsh plugin add 前置钩子:安装前自动扫描,risky 以上默认拦截详见 docs/roadmap.md。
npm test # 11 项测试(引擎 + CLI + 插件加载冒烟)
npm run docs:rules # 从规则目录重新生成 docs/rules.md
npm run demo # 生成 docs/example-report.json
npm run scan:self # 扫描器扫自己(狗粮)
如果这个项目对你有用,欢迎:
MIT © dsh-sentinel contributors
dsh-sentinel is a dependency-free, read-only security & health scanner for DeepSeek Harness (DSH) plugins. The DSH ecosystem has ~4,800 plugin repos but almost no tooling to audit them — plugins run arbitrary code with your full permissions, so supply-chain hygiene matters.
sentinel_scan, sentinel_scan_profile) and a standalone CLI (npx dsh-sentinel) with CI-friendly exit codes.safe / review / risky / dangerous verdict.dsh.bundle, cordis.patch.yml rows and the plugin entry contract (name/apply exports) against the real loader semantics.$DSH_HOME/profiles/<name>/node_modules), skipping trusted @deepseek-ai/* built-ins and tagging findings per package.# standalone
npx dsh-sentinel <plugin-dir> [--json] [--out report.json]
# as a DSH plugin
dsh plugin --profile web add ./dsh-sentinel
Disclaimer: heuristic static analysis is not a security guarantee. Findings mean "review this", not "this is malicious".
Rule catalog · Example report · MIT License
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: security、static-analysis、supply-chain-security。