liangl1985/work-personal-secretary
C3DSH(DeepSeek Harness)插件集合 · 工作秘书集成体:强记忆 + 强文档处理(Word/Excel/PPT/PDF)+ 20 位专家库 + 桌宠定制层。安装:git clone 后 dsh plugin --profile desktop add <克隆目录>/modules/work-personal-secretary,重启 DSH 后在「设置 → 工作秘书 → 安装与检查」
★ 1+ · liangl1985/work-personal-secretary source on GitHub · this plugin in the registry
liangl1985/work-personal-secretary is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, runs code at install time, can rewrite the system prompt, executes system commands.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| runs code at install time | install_script | install: node scripts/install-test.mjs |
| can rewrite the system prompt | prompt_surface | systemPrompt, webServer |
| executes system commands | exec | ×29 in authored code, e.g. modules/dsh-doc-suite/scripts/media-test.mjs:7, modules/dsh-doc-suite/scripts/media-test.mjs:7 |
| uses eval / new Function | eval | ×6 in authored code, e.g. modules/work-personal-secretary/scripts/smoke-load.mjs:54, modules/work-personal-secretary/scripts/smoke-load.mjs:410 |
Services it injects
commands locale settings slots systemPrompt tools uiWorkspace webServer
Hooks it attaches
agent/inbox/claimed agent/pre-step loader/volatile-update
Outbound domains
www.python.org obsidian.md ark.cn-beijing.volces.com www.wps.cn www.wps.com ok.example.com
Environment variables it reads
DSH_HOME WPS_TEST_REAL_WORKSPACE DSH_TSC_ROOT DSH_DOC_SUITE_MERMAID WINDIR CARD_SHOW DSH_AGENTS_HOME DSH_BUNDLED_SKILL_DIR
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.