Every DeepSeek Harness plugin gets a capability card: what it declares vs. what its code actually does — with file:line evidence.
An open-source AI agent runtime built on the principle that everything is a plugin. Its plugin ecosystem went from roughly 200 repositories to over 7,000 in about 30 days.
Arbitrary code running inside your agent, using the same interfaces the core itself uses. There is no privilege gap between a third-party plugin and dsh internals.
No manifest field describes what a plugin can do, and installing one asks you nothing. The information exists only in the code — so we read the code.
The dsh-plugin ecosystem grew from ~200 to 7,000+ repositories in 30 days. A plugin is arbitrary code inside your agent runtime — and today nothing surfaces its real capability surface before you install it.
A plugin hooking system-prompt/assemble silently shapes every instruction your model sees.
apiProxy and api/gate sit between you and the model; some plugins read GITHUB_TOKEN-class environment variables.
manifest.bundle.patch lets a plugin modify dsh core behavior — the deepest supply-chain surface there is.
Every repo under the dsh-plugin topic, rescanned daily.
Static analysis of shipped code: injected services, hooks, runtime patches, exec/eval, outbound domains, credential-like env reads. Nothing is executed.
A capability card per plugin with file:line evidence, a C0–C3 level, and an embeddable badge.
No notable capability surface.
Ordinary: registers tools/services, calls external domains.
Powerful: prompt surface, API interception, subprocess, exec, credential reads or install scripts.
Powerful capabilities combined with sensitive behavior.
Levels measure capability surface and transparency — not maliciousness. A C3 plugin can be perfectly legitimate; you just deserve to know before it touches your agent.
Type the plugin name or author into the registry.
C0–C3 tells you how much surface it has; the chips tell you which kind.
Every flag cites a file and line. Disagree with one? The source is one click away.
The companion plugin answers the same question in the agent, while you are deciding whether to install something.
dsh plugin add https://github.com/unStone/dsh-xray-plugin/releases/download/v0.1.0/dsh-xray-plugin-0.1.0.tgz
Every plugin that can do a particular thing, in one list.
patch the runtime rewrite the system prompt intercept API traffic spawn subprocesses read credentials run code at install time no notable surface
No. C3 means broad capability plus sensitive behavior — which is exactly what a desktop shell or a design tool legitimately needs. It means you should know, not that you should refuse.
No. This is static capability analysis; it cannot establish intent, and we did not look for malice. A determined bad actor evades a static scanner easily. The gap we address is that nobody knows what ordinary plugins do.
Open an issue. Every flag cites the file and line it came from, so disputes are checkable. Rules get fixed in public and the next daily scan picks up the correction.
A scheduled run rescans the ecosystem daily. Repositories that have not changed reuse their previous card, so new and updated plugins are what actually get re-read.
Yes — it is Apache-2.0 Python with no service dependency. Clone the repository and run discovery and the pipeline against your own list.
For now. The capability model is not dsh-specific, and support for other plugin formats such as Abu-Cowork and Claude Code is on the roadmap.
dsh-xray only reads plugins. These are the projects it reads about.
The agent runtime itself — everything is a plugin.
The plugin framework dsh is built on: contexts, services, typed events.
The community-curated list of dsh plugins.
A plugin manager panel: enable, disable and install from within dsh.
A local-first open-source agent desktop app, with dsh integration in progress.
Plugin authors: embed your capability badge. Users click through to the full evidence card.
[](https://unstone.github.io/dsh-xray/registry.html#<owner>__<repo>)
Coming next: full-ecosystem coverage with daily diffs, a runtime-patch audit view, an install-gate plugin that blocks or asks on C2+ installs, multi-harness support (Abu-Cowork, Claude Code), and a private registry with org policy for enterprises.