KeepLost/harniverse

C3

This is the coding agent that it should be. No business promotion or advertisement from specific LLM vendor. It's as vast as the universe, composed by harness plugins as 'planets'. Universe of the har

★ 1+ · KeepLost/harniverse source on GitHub · this plugin in the registry

KeepLost/harniverse is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, runs code at install time, can intercept API traffic, can spawn subprocesses.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patchcordis.patch.yml
runs code at install timeinstall_scriptpostinstall: node scripts/ensure-spawn-helper.mjs
can intercept API trafficapi_interceptapiProxy, subprocess, webServer
can spawn subprocessessubprocess_serviceinject: subprocess
executes system commandsexec×37 in authored code, e.g. benchmarks/terminal-io.bench.ts:110, apps/cli/src/plugin.ts:13
decodes base64 payloadsbase64_decode×2 in authored code, e.g. packages/attachment/attachment/src/admission.ts:10, packages/client/runtime/src/client/sessions/session.ts:309
starts a network server in development tooling the package does not shipnet_server_tooling×2 in development tooling the package does not ship, e.g. apps/desktop/scripts/packaging-browser.ts:310, apps/desktop/scripts/packaging-browser.ts:411

Services it injects

agentDefaultModel agents apiProxy attachments authStartup authentication clientAuthentication clientModules cmdlineArgs connection desktopAdmission desktopShell invariants loader modules remote sandboxPolicy scheduler sessions settingsScope slots subprocess terminalController typert webServer

Hooks it attaches

agent/error agent/inbox/claimed approval/request authentication/available authentication/revoked authentication/unavailable internal/plugin internal/service locale/change remote-runtime/ownerless session/event

Outbound domains

www.deepseek.com docs.deepseek.com

Environment variables it reads

DSH_TELEMETRY_DISABLED DSH_DESKTOP_DIAGNOSTICS APPIMAGE DSH_CLIENT_TITLE CORDIS_SHARED DSH_DESKTOP_HOST_ENTRY DSH_DESKTOP_INSTALL_ANCHOR DSH_DESKTOP_RENDERER DSH_DESKTOP_PRELOAD DSH_DESKTOP_RUNTIME_ROOT

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.