SiriLee/dsh-rewind

C3

DSH 插件:便捷无感的同窗口内对话回退,从不新建分支;自带轻量工作区备份,可一并还原文件(Claude Code /rewind 语义)。 · DSH plugin: effortless in-window conversation rewind — never forking a new session; ships a lightweight workspace backup that

★ 100+ · SiriLee/dsh-rewind source on GitHub · this plugin in the registry

SiriLee/dsh-rewind is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, reads credential-class env vars.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
executes system commandsexec×4 in authored code, e.g. scripts/build.mjs:23, scripts/build.mjs:23
reads credential-class env varstoken_envGIST_TOKEN

Services it injects

commandUi commands configForms locale sessions settings slots tools

Hooks it attaches

agent/created fs/observed session/event

Outbound domains

api.github.com

Environment variables it reads

GIST_TOKEN GIST_ID DSH_REWIND_MAX_FILE_BYTES

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.