ZJU-REAL/Polaris

C3

Toward Autonomous Scientific Discovery

★ 100+ · ZJU-REAL/Polaris source on GitHub · this plugin in the registry

ZJU-REAL/Polaris is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, eval in build output only, base64 decoding in build output only.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
executes system commandsexec×29 in authored code, e.g. src/desktop/scripts/fetch-uv.mjs:21, src/desktop/scripts/fetch-uv.mjs:21
eval in build output onlyeval_bundled×4 in build output only, e.g. plugins/polaris-plugin-hello/dist/index.js:287, vendor/deepseek-cordis/schemastery/src/index.ts:261
base64 decoding in build output onlybase64_decode_bundled×4 in build output only, e.g. plugins/polaris-plugin-hello/dist/index.js:87, plugins/polaris-plugin-hello/dist/index.js:88
starts a network servernet_server×1 in authored code, e.g. src/kernel/src/server/rpc-http.ts:88
reads credential-class env varstoken_envPOLARIS_KERNEL_TOKEN

Services it injects

agents loader skills tools

Hooks it attaches

agent/disposed agent/error agent/pre-step agent/turn-stopping internal/config internal/plugin internal/update loader/entry-init loader/partial-dispose loader/patch-context tools/change tools/post-execute

Outbound domains

arxiv.org legacy.example.edu polaris.example.edu mirror.example.edu open.feishu.cn cordis.europa.eu api.openalex.org api.github.com doi.org pypi.tuna.tsinghua.edu.cn

Environment variables it reads

VITE_PROXY_TARGET POLARIS_DESKTOP_ENGINE POLARIS_SMOKE_SHOT POLARIS_LLM_FAKE_FALLBACK CORDIS_SHARED POLARIS_SMOKE_ENGINE POLARIS_USER_DATA_DIR POLARIS_DESKTOP_ENGINE_CONTAINER POLARIS_DESKTOP_ENGINE_PORT POLARIS_DEFAULT_SERVER_URL

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.