SeaOf0/dsh-redteam-model

C3

基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)

★ 500+ · SeaOf0/dsh-redteam-model source on GitHub · this plugin in the registry

SeaOf0/dsh-redteam-model is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, gates tool execution, executes system commands.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
can rewrite the system promptprompt_surfacesystemPrompt, webServer, tools/pre-execute
gates tool executiontool_gatehook: tools/pre-execute
executes system commandsexec×14 in authored code, e.g. deploy/check-sources.mjs:28, deploy/check-sources.mjs:33
eval in build output onlyeval_bundled×8 in build output only, e.g. plugins/dsh-webshell-mgr/lib/generators.js:40, plugins/dsh-webshell-mgr/lib/generators.js:88
base64 decoding in build output onlybase64_decode_bundled×7 in build output only, e.g. plugins/dsh-webshell-mgr/lib/client.js:716, plugins/dsh-webshell-mgr/lib/client.js:733
network server in build output onlynet_server_bundled×1 in build output only, e.g. plugins/dsh-webshell-mgr/lib/protocol/tunnel.js:15

Services it injects

agentPresets connection locale remote settingsScope slots subagents systemPrompt tools webRuntime webServer

Hooks it attaches

agent/created agent/disposed agent/inbox/inserted session/event tools/pre-execute

Outbound domains

fofa.info hunter.qianxin.com quake.360.net

Environment variables it reads

DSH_HOME ComSpec DSH_ATLAS_DB DSH_KILL_SWITCH_FILE DSH_TRACE_VAULT_DB WSM_DEBUG

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.