Eternalloveone/dsh-palm

C3

Standalone mobile surface for the dsh web GUI: scan-to-pair device trust, /m/ phone UI, realtime SSE mux, task plan & background jobs, offline outbox, PWA

★ 0 · Eternalloveone/dsh-palm source on GitHub · this plugin in the registry

Eternalloveone/dsh-palm is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can intercept API traffic, executes system commands, decodes base64 payloads.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
can intercept API trafficapi_interceptwebServer, api/gate
executes system commandsexec×28 in authored code, e.g. perf/run-t1.mjs:7, perf/run-t1.mjs:7
decodes base64 payloadsbase64_decode×7 in authored code, e.g. scripts/capture-gif.mjs:329, scripts/capture-gif.mjs:331

Services it injects

agentPresets connection locale remote sessionController settingsController slots subagents webServer workspaceController

Hooks it attaches

api/gate approval/request user-questions/request webserver/index-inject

Outbound domains

your-tunnel.example.com ollama.com sctapi.ftqq.com api.day.app api.telegram.org wxpusher.zjiecode.com www.pushplus.plus api.deepseek.com api.moonshot.cn openrouter.ai

Environment variables it reads

DSH_PALM_REPO HTTPS_PROXY https_proxy PERF_BASE DSH_PALM_GIT_PROXY PERF_OUT FFMPEG DSH_PALM_PATHS DSH_PALM_GUARD_REGEX DSH_PALM_PUSH_PROXY

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.