nocobase/nocobase
C2NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of production-proven infrastructure and a WYSIWYG no
★ 24k+ · nocobase/nocobase source on GitHub · this plugin in the registry
nocobase/nocobase is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It runs code at install time, command execution in build output only, starts a network server, reads credential-class env vars.
No dsh integration found — this repository carries the dsh-plugin topic but shows no sign of connecting to dsh
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| runs code at install time | install_script | postinstall: nocobase-v1 postinstall |
| command execution in build output only | exec_bundled | ×3 in build output only, e.g. packages/core/build/src/utils/utils.ts:11, packages/core/build/src/utils/utils.ts:11 |
| starts a network server | net_server | ×4 in authored code, e.g. benchmark/koa-database/index.js:86, benchmark/koa-resourcer/index.js:104 |
| reads credential-class env vars | token_env | API_CLIENT_SHARE_TOKEN, APP_KEY, CDN_ALI_OSS_ACCESS_KEY_ID, CDN_ALI_OSS_ACCESS_KEY_SECRET, DB_PASSWORD, UNSAFE_USE_DEFAULT_JWT_SECRET |
Outbound domains
esm.sh www.npmmirror.com docs.nocobase.com registry.npmmirror.com registry-direct.npmmirror.com
Environment variables it reads
API_BASE_URL API_BASE_PATH WS_PATH API_CLIENT_STORAGE_PREFIX API_CLIENT_STORAGE_TYPE API_CLIENT_SHARE_TOKEN WEBSOCKET_URL APP_PUBLIC_PATH APP_PORT ESM_CDN_BASE_URL
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.