alibaba/anolisa

C2

ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.

★ 100+ · alibaba/anolisa source on GitHub · this plugin in the registry

alibaba/anolisa is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It runs code at install time, executes system commands, starts a network server.

What it can do

CapabilityFlagEvidence
runs code at install timeinstall_scriptpostinstall: node scripts/postinstall.js
executes system commandsexec×38 src, e.g. src/copilot-shell/integration-tests/test-helper.ts:7, src/copilot-shell/integration-tests/test-helper.ts:7
starts a network servernet_server×1 src, e.g. src/copilot-shell/integration-tests/test-mcp-server.ts:38

Outbound domains

bailian.console.aliyun.com unpkg.com dashscope.aliyuncs.com cn.clawhub-mirror.com fonts.googleapis.com api.deepseek.com open.bigmodel.cn api.moonshot.cn coding.dashscope.aliyuncs.com fonts.gstatic.com

Environment variables it reads

DEV PII_CHECKER_MODE XDG_DATA_HOME SKILL_LEDGER_MODE CLI_VERSION AGENTSIGHT_EMBED INTEGRATION_TEST_USE_INSTALLED_GEMINI TB_TIMEOUT_MINUTES CODE_SCANNER_MODE PII_CHECKER_HOOK_ENABLED

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.