返回目录
安全与治理 插件

dsh-plugin-auditor

HYY-King/dsh-plugin-auditor

DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. DSH 插件审核器:安装新插件前扫描组合兼容性,预防启动崩溃。

Stars
2
Forks
1
Issues
1
更新
4 天前

PROJECT TOPICS

项目标签

INSTALL REFERENCE

安装参考

未验证
dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor

该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。

PROJECT README

README

dsh-plugin-auditor

Audit your DSH plugin combination before adding a new one — predict whether it will crash the harness on boot.

DeepSeek Harness loads every bundle in the profile at startup. Third-party plugins that are unconfigured or conflicting (duplicate tool registrations, entry-id collisions, peer version mismatches, missing tokens/app ids) can fail the whole plugin tree. This plugin turns those lessons into a read-only pre-flight check.

Install

# from git
dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor

# or from a local directory (development)
dsh plugin --profile web add D:\path\dsh-plugin-auditor

# restart dsh web to activate

Usage

After restart, ask the agent to call the audit_plugins tool:

  • Full audit: call with no arguments to scan every bundle in the current profile.
  • New-plugin preview: pass newPlugins: ["package-name"] for a name-level conflict preview.

Checks

Check What it catches
Duplicate tool registration Two plugins registering the same tool name (e.g. two memory plugins both registering memory_forget)
Entry-id collision Multiple bundles mounting the same id in cordis.patch.yml
Peer version mismatch A plugin requiring a @deepseek-ai/* version that differs from the installed one
Memory-plugin uniqueness More than one memory plugin enabled at once — keep exactly one
Channel-plugin credentials telegram/lark/im-style plugins enabled without token/app id — disable or configure

How it works

  • Read-only: inspects the profile's package.json, cordis.patch.yml, and each installed package under node_modules; never executes audited plugin code.
  • Zero-dependency: a mini YAML parser tailored to the simple cordis.patch.yml shape.

Disclaimer

The audit is a static heuristic signal, not a compatibility guarantee. Always review a third-party plugin's source, permissions, and license before installing.

License

MIT

CLASSIFICATION EVIDENCE

分类依据

项目类型插件
功能分类安全与治理
规则置信度

系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: audit。