ArcanePivot/dsh-api-balance

C2

DeepSeek Harness Web UI widget for viewing DeepSeek API balance from the host side.

★ 5+ · ArcanePivot/dsh-api-balance source on GitHub · this plugin in the registry

ArcanePivot/dsh-api-balance is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It uses eval / new Function, base64 decoding in build output only, ships no manifest.

Not installable — has plugin code but no manifest to install it by

What it can do

CapabilityFlagEvidence
uses eval / new Functioneval×1 in authored code, e.g. scripts/test-usage-analytics.mjs:12
base64 decoding in build output onlybase64_decode_bundled×1 in build output only, e.g. files/dsh-host-apiproxy/lib/index.js:907
ships no manifestno_manifestuses 15 services, 0 tool regs, no manifest

Services it injects

agentDefaultModel agents attachments directoryPicker layout llm locale sessionQuery sessions slots subagents tools userQuestions workspaceRegistry workspaces

Hooks it attaches

agent/error agent/status approval/request domain/changed session/created session/disposed session/event

Outbound domains

api-docs.deepseek.com api.deepseek.com

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.