SeaOf0/dsh-redteam-model
C3基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)
★ 500+ · SeaOf0/dsh-redteam-model source on GitHub · this plugin in the registry
SeaOf0/dsh-redteam-model is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, gates tool execution, executes system commands.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| can rewrite the system prompt | prompt_surface | systemPrompt, webServer, tools/pre-execute |
| gates tool execution | tool_gate | hook: tools/pre-execute |
| executes system commands | exec | ×14 in authored code, e.g. deploy/check-sources.mjs:28, deploy/check-sources.mjs:33 |
| eval in build output only | eval_bundled | ×8 in build output only, e.g. plugins/dsh-webshell-mgr/lib/generators.js:40, plugins/dsh-webshell-mgr/lib/generators.js:88 |
| base64 decoding in build output only | base64_decode_bundled | ×7 in build output only, e.g. plugins/dsh-webshell-mgr/lib/client.js:716, plugins/dsh-webshell-mgr/lib/client.js:733 |
| network server in build output only | net_server_bundled | ×1 in build output only, e.g. plugins/dsh-webshell-mgr/lib/protocol/tunnel.js:15 |
Services it injects
agentPresets connection locale remote settingsScope slots subagents systemPrompt tools webRuntime webServer
Hooks it attaches
agent/created agent/disposed agent/inbox/inserted session/event tools/pre-execute
Outbound domains
fofa.info hunter.qianxin.com quake.360.net
Environment variables it reads
DSH_HOME ComSpec DSH_ATLAS_DB DSH_KILL_SWITCH_FILE DSH_TRACE_VAULT_DB WSM_DEBUG
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.