lhh010/dsh-paste-input
C2DSH WebUI 文件输入增强:Ctrl+V 粘贴 + 拖拽 + 选择文件(图片悬停预览 / 缩放查看器 / 防伪造校验),发送时复制进会话工作区临时目录;无视觉模型发送失败自动移除图片附件并提示重发;桌面端经 base64 通道可用
★ 5+ · lhh010/dsh-paste-input source on GitHub · this plugin in the registry
lhh010/dsh-paste-input is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It executes system commands, base64 decoding in build output only.
Not installable — declares only dsh.client, which dsh plugin add cannot install
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| executes system commands | exec | ×4 in authored code, e.g. sync-mirrors.mjs:14, sync-mirrors.mjs:14 |
| base64 decoding in build output only | base64_decode_bundled | ×2 in build output only, e.g. lib/client.js:47, lib/index.js:512 |
Services it injects
conversation inputTriggers loader sessions slots webServer
Outbound domains
data.jsdelivr.com
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.