nocobase/nocobase

C2

NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of production-proven infrastructure and a WYSIWYG no

★ 24k+ · nocobase/nocobase source on GitHub · this plugin in the registry

nocobase/nocobase is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It runs code at install time, command execution in build output only, starts a network server, reads credential-class env vars.

No dsh integration found — this repository carries the dsh-plugin topic but shows no sign of connecting to dsh

What it can do

CapabilityFlagEvidence
runs code at install timeinstall_scriptpostinstall: nocobase-v1 postinstall
command execution in build output onlyexec_bundled×3 in build output only, e.g. packages/core/build/src/utils/utils.ts:11, packages/core/build/src/utils/utils.ts:11
starts a network servernet_server×4 in authored code, e.g. benchmark/koa-database/index.js:86, benchmark/koa-resourcer/index.js:104
reads credential-class env varstoken_envAPI_CLIENT_SHARE_TOKEN, APP_KEY, CDN_ALI_OSS_ACCESS_KEY_ID, CDN_ALI_OSS_ACCESS_KEY_SECRET, DB_PASSWORD, UNSAFE_USE_DEFAULT_JWT_SECRET

Outbound domains

esm.sh www.npmmirror.com docs.nocobase.com registry.npmmirror.com registry-direct.npmmirror.com

Environment variables it reads

API_BASE_URL API_BASE_PATH WS_PATH API_CLIENT_STORAGE_PREFIX API_CLIENT_STORAGE_TYPE API_CLIENT_SHARE_TOKEN WEBSOCKET_URL APP_PUBLIC_PATH APP_PORT ESM_CDN_BASE_URL

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.