hoyyang/dsh-mall

C3

全网最强 DeepSeek Harness 插件商场:全量收录 GitHub #dsh-plugin 生态插件,五维实用评分雷达图,智能搜索(AI 理解需求)、智能安装/更新/卸载(AI 装前审查+装后诊断)、一键批量更新、编辑精选与个性化推荐,自带 Skills 工具与 dsh-mall 技能,中英多语言界面。

★ 10+ · hoyyang/dsh-mall source on GitHub · this plugin in the registry

hoyyang/dsh-mall is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, reads credential-class env vars.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch./cordis.patch.yml
executes system commandsexec×4 in authored code, e.g. src/headless.ts:19, src/headless.ts:91
reads credential-class env varstoken_envDSHM_GITHUB_TOKEN

Services it injects

locale slots

Outbound domains

cdn.jsdelivr.net api.github.com api.npmjs.org avatars.githubusercontent.com awesome-dsh-plugin.com

Environment variables it reads

DSH_HOME DSHM_GITHUB_TOKEN DSH_STORE_REGISTRY_URL DSH_MARKET_PROFILE

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.