nanshan1995/DSH-Plugin-Market
C3DeepSeek Harness 插件市场:精选目录 + GitHub 实时浏览、中英翻译搜索、安装前静态安全审计闸门。Plugin market for DeepSeek Harness with a pre-install security audit gate.
★ 1+ · nanshan1995/DSH-Plugin-Market source on GitHub · this plugin in the registry
nanshan1995/DSH-Plugin-Market is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, reads credential-class env vars.
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| executes system commands | exec | ×16 src, e.g. lib/audit-scanner.js:11, lib/audit-scanner.js:11 |
| reads credential-class env vars | token_env | DSHMARKET_GITHUB_TOKEN, GITHUB_TOKEN |
Services it injects
locale slots
Outbound domains
api.github.com codeload.github.com
Environment variables it reads
APPDATA LOCALAPPDATA PROGRAMDATA ProgramFiles DSH_HOME DSHMARKET_AUDIT_GATE DSHMARKET_GITHUB_TOKEN GITHUB_TOKEN DSHMARKET_TRANSLATE_PROVIDER DSHMARKET_TRANSLATE_MODEL
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.