api-relay-audit
toby-bridges
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:MicroMilo/upstream-radar
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
Know which DeepSeek Harness plugins still work—before users find out they do not.
简体中文 ·
Upstream Radar watches exact DSH and plugin releases, persists every affected case, and wakes an Agent only when the input changes. The Agent reads the repository, chooses evidence-backed Node.js and execution profiles, installs and runs the exact artifacts in disposable CI, watches them while they run, and publishes a reviewable compatibility report.
No guessed matrix. No “install succeeded, therefore compatible.” No silent unknowns.
flowchart LR
Change["Schedule or upstream change"] --> Task["Persist exact task"]
Task --> Agent["Agent reviews repository evidence"]
Agent --> Run["Install, run, watch, recover"]
Run --> Report["Versioned report and logs"]
Report --> State["Deduplicate or retry"]
State --> Change
The model recommends and operates within a bounded tool contract. Deterministic code selects exact versions, verifies artifacts, isolates execution, and decides whether evidence is complete. Plugin code never receives model credentials or repository write tokens.
context Agent run
— repository review, Node/profile reasoning, isolated execution, and active
watches in one case.Reports preserve compatible, incompatible, unknown, and externally blocked
outcomes separately. Missing credentials, missing coverage, and executor faults
cannot become a pass.
Inspect one exact published artifact without executing plugin code:
npx --yes upstream-radar@0.45.0 inspect \
@sanqi-normal/dsh-webui-market-plugin@0.5.4 \
--deep --fail-on never
Or review a public plugin repository without installing it:
npx --yes upstream-radar@0.45.0 scan \
https://github.com/owner/dsh-plugin \
--fail-on never
The static commands read bounded package and repository evidence. They do not install dependencies, execute lifecycle scripts, start DSH, or call an LLM.
Start from one maintained workflow:
This repository's deployed loop runs from
upstream-observer.yml. Its single
operator entry point is
examples/dsh/active-agent/policy.json:
{
"schema": "upstream-radar.dsh-active-agent-policy/v1alpha1",
"dsh": { "channel": "next" },
"defaults": {},
"plugins": [
{ "targetId": "context" },
{ "targetId": "dsh-tui" }
]
}
Leave Node.js and profiles unset to let the Agent infer them. Override them
globally or per plugin when you need a fixed experiment. Exact DSH or plugin
versions require a matching sourceRef, so repository evidence cannot drift
from installed bytes. See the policy reference.
| Result | Meaning |
|---|---|
compatible |
The exact tested cell completed its required install and runtime checks. |
incompatible |
Reproducible evidence failed a required compatibility boundary. |
unknown |
Execution happened, but coverage or attribution was insufficient. |
blocked |
An external account, credential, source, or executor prevented completion. |
Results are scoped observations, not permanent compatibility badges or security certificates. A new artifact, source commit, DSH release, runtime policy, or expired evidence creates a new input.
Upstream Radar is listed by awesome-dsh-plugin, awesome-deepseek-harness, and awesome-deepseek-harness-plugins.
If this is the compatibility loop your plugin ecosystem needs, give Upstream Radar a Star ⭐
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: agent-security、dependency-monitoring、dependency-security、developer-tools、plugin-security、supply-chain-security、vulnerability-monitoring。