XiangSu-ce/dsh-plugin-freecodego

C3

Unofficial DeepSeek Harness (DSH) plugin for FreeCodeGo: managed gateway and free-model catalogs, per-provider accounts, media generation, and the engineering graph + memory toolchain. AGPL-3.0-only.

★ 1+ · XiangSu-ce/dsh-plugin-freecodego source on GitHub · this plugin in the registry

XiangSu-ce/dsh-plugin-freecodego is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, runs code at install time, can rewrite the system prompt, can spawn subprocesses.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch['./cordis.patch.yml', './presets/freecodego.patch.yml', './presets/augmentcode.patch.yml']
runs code at install timeinstall_scriptpostinstall: node scripts/install-lefthook.mjs
can rewrite the system promptprompt_surfacesubprocess, systemPrompt, tools/pre-execute
can spawn subprocessessubprocess_serviceinject: subprocess
gates tool executiontool_gatehook: tools/pre-execute
executes system commandsexec×30 in authored code, e.g. plugin/packages/freecodego/harness-plugin/src/community-catalog-utils.ts:4, plugin/packages/freecodego/harness-plugin/src/community-catalog-utils.ts:414
decodes base64 payloadsbase64_decode×7 in authored code, e.g. plugin/packages/freecodego/harness-plugin/src/account-remotes.ts:499, plugin/packages/freecodego/harness-plugin/src/claude-protocol-bridge.ts:598
starts a network servernet_server×5 in authored code, e.g. plugin/packages/freecodego/harness-plugin/src/claude-protocol-bridge.ts:119, plugin/packages/freecodego/harness-plugin/src/claude-protocol-bridge.ts:121
reads credential-class env varstoken_envGROQ_WHISPER_API_KEY, LOGFARE_API_KEY, NVIDIA_API_KEY, SENSENOVA_API_KEY, VYCE_API_KEY

Services it injects

agentLoop agents credentials freeCodeGoHarness fs llm lsp sessionPersistence sessions settings skills subprocess systemPrompt tools

Hooks it attaches

agent/assistant-stream agent/created agent/disposed agent/pre-step agent/request agent/status agent/turn-stopping credentials/record-updated credentials/reference-updated llm/adapters-updated loader/entry-init loader/partial-dispose session/disposed session/event settings/document-updated tools/post-execute tools/pre-execute

Outbound domains

openapi.qoder.sh openapi.qoder.com.cn mcp.so logfare.ai gateway.qoder.com.cn apihub.agnes-ai.com api.workos.com api.github.com skills.sh vyceai.com

Environment variables it reads

DSH_HOME ComSpec LOCALAPPDATA USERPROFILE PLAYWRIGHT_BROWSERS_PATH FREECODEGO_HOME VYCE_API_KEY GROQ_WHISPER_API_KEY LOGFARE_API_KEY SENSENOVA_API_KEY

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.