h4dex/opc-nexus

C2

开源的企业版的数字员工工作台, OPC-Nexus(One Person Company Nexus)是一款本地优先的桌面 AI Agent 管理器。它为单人公司 / 独立开发者提供统一的 AI 数字员工管理平台 —— 从 Agent 创建、任务编排、多引擎接入,到消息渠道集成、工作流自动化和专家团协作,一站式覆盖。

★ 100+ · h4dex/opc-nexus source on GitHub · this plugin in the registry

h4dex/opc-nexus is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It runs code at install time, executes system commands, eval in build output only, decodes base64 payloads.

A skill, not an installable plugin — ships SKILL.md with no plugin manifest

What it can do

CapabilityFlagEvidence
runs code at install timeinstall_scriptpostinstall: node patch-spectrum-mixed-attachments.mjs
executes system commandsexec×76 in authored code, e.g. scripts/acceptance-novel-studio.cjs:9, scripts/acceptance-novel-studio.cjs:9
eval in build output onlyeval_bundled×87 in build output only, e.g. vendor/hermes-agent/apps/desktop/scripts/diag-code-live.mjs:10, vendor/hermes-agent/apps/desktop/scripts/diag-drag-churn.mjs:112
decodes base64 payloadsbase64_decode×32 in authored code, e.g. scripts/acceptance-card-identity.cjs:411, scripts/acceptance-creative-studios.cjs:172
starts a network servernet_server×16 in authored code, e.g. scripts/acceptance-creative-studios.cjs:44, scripts/acceptance-creative-studios.cjs:46
reads credential-class env varstoken_envAIBOX_ACCEPTANCE_API_KEY, AIBOX_NOVEL_API_KEY, APPLE_API_KEY, APPLE_API_KEY_ID, HERMES_DESKTOP_REMOTE_TOKEN

Outbound domains

registry.npmmirror.com api.deepseek.com opencode.ai cn.bing.com docs.anthropic.com npmmirror.com deb.nodesource.com pypi.tuna.tsinghua.edu.cn duckduckgo.com html.duckduckgo.com

Environment variables it reads

LOCALAPPDATA AIBOX_ACCEPTANCE_SEED_USER_DATA PYTHONPATH HERMES_HOME HERMES_DESKTOP_REMOTE_URL SystemRoot ANDROID_SDK_ROOT ANDROID_HOME HERMES_DESKTOP_SKIP_BUILD AIBOX_CARD_ACCEPTANCE_EXECUTABLE

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.