hoyyang/dsh-mall
C3全网最强 DeepSeek Harness 插件商场:全量收录 GitHub #dsh-plugin 生态插件,五维实用评分雷达图,智能搜索(AI 理解需求)、智能安装/更新/卸载(AI 装前审查+装后诊断)、一键批量更新、编辑精选与个性化推荐,自带 Skills 工具与 dsh-mall 技能,中英多语言界面。
★ 10+ · hoyyang/dsh-mall source on GitHub · this plugin in the registry
hoyyang/dsh-mall is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, reads credential-class env vars.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| executes system commands | exec | ×4 in authored code, e.g. src/headless.ts:19, src/headless.ts:91 |
| reads credential-class env vars | token_env | DSHM_GITHUB_TOKEN |
Services it injects
locale slots
Outbound domains
cdn.jsdelivr.net api.github.com api.npmjs.org avatars.githubusercontent.com awesome-dsh-plugin.com
Environment variables it reads
DSH_HOME DSHM_GITHUB_TOKEN DSH_STORE_REGISTRY_URL DSH_MARKET_PROFILE
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.