omdsh-dev/dsh-container
C2DeepSeek Harness (DSH) Docker 容器化封装方案,支持安全沙箱、局域网中继与数据持久化。 / Hardened Docker container for DeepSeek Harness (DSH) with LAN access relay and persistence.
★ 1+ · omdsh-dev/dsh-container source on GitHub · this plugin in the registry
omdsh-dev/dsh-container is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It starts a network server.
Not installable — declares only dsh.client, which dsh plugin add cannot install
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| starts a network server | net_server | ×1 in authored code, e.g. docker/auth-relay/server.mjs:104 |
Services it injects
connection locale slots
Environment variables it reads
DSH_CONTAINER_INTERNAL_PORT DSH_CONTAINER_RELAY_PORT DSH_CONTAINER_TRUSTED_HOSTS DSH_PERMISSION_MODE DSH_TELEMETRY_DISABLED
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.