gcry13067381632-jpg/dsh-qqbot
C3AI 统管 QQ 群组:审核放行、群发文件、沟通其他web会话的ai! 气氛组担当:表情包自动入库,AI 自己决定开口,多预设多人格轮班陪聊! 远程办公:权限审批、提问卡片转发qq
★ 10+ · gcry13067381632-jpg/dsh-qqbot source on GitHub · this plugin in the registry
gcry13067381632-jpg/dsh-qqbot is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, executes system commands, decodes base64 payloads.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| can rewrite the system prompt | prompt_surface | systemPrompt, webServer |
| executes system commands | exec | ×7 in authored code, e.g. settings-host.js:9, settings-host.js:1147 |
| decodes base64 payloads | base64_decode | ×4 in authored code, e.g. settings-host.js:1733, settings-host.js:3649 |
| reads credential-class env vars | token_env | QQBOT_TOKEN_BASE_URL |
Services it injects
agents sessions settings slots systemPrompt tools webServer
Hooks it attaches
qqbot/settings-changed user-questions/request
Outbound domains
schemas.openxmlformats.org api.bot.qq.com hf-mirror.com huggingface.co q.qq.com qq.com bots.qq.com www.baidu.com
Environment variables it reads
DSH_HOME USERPROFILE QQBOT_DIAG_FILE VIPS_WARNING DSH_QQBOT_DEBOUNCE_DBG TEMP TMP DSH_QQBOT_NODHASH QQBOT_BASE_URL QQBOT_TOKEN_BASE_URL
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.