LivXue/dsh-plugin-shop

C3

The most comprehensive DeepSeek Harness plugin market — refreshed daily, sourced across the Internet, reviewed before publishing.

★ 1.0k · LivXue/dsh-plugin-shop source on GitHub · this plugin in the registry

LivXue/dsh-plugin-shop is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, reads credential-class env vars.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
executes system commandsexec×16 in authored code, e.g. registry/scripts/src/backfill-first-seen.ts:13, registry/scripts/src/backfill-first-seen.ts:13
reads credential-class env varstoken_envGITHUB_TOKEN, LLM_API_KEY, NPM_TOKEN, STARS_TOKEN

Services it injects

invariants locale remote slots

Outbound domains

registry.npmmirror.com api.github.com livxue.github.io dsh-plugin-shop.dev registry-direct.npmmirror.com www.npmjs.com

Environment variables it reads

NPM_TOKEN NPM_BACKUP_REGISTRY SHOP_EMIT_REPO_PEERS GITHUB_TOKEN SHOP_HARVEST_REPOS REPO_BACKFILL_BUDGET SHOP_HARVEST_SUBPACKAGES STARS_TOKEN SHOP_CATALOG_V5 LLM_BASE_URL

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.