DeepSeek Harness 插件

dsh-plugin-sentinel

插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。

插件开发工具未检测到许可证
跳到安装方式

来源信息

GitHub 仓库
BotonJ/dsh-plugin-sentinel
最近更新
2026年8月15日
主要分类
插件开发工具
GitHub stars
0
GitHub forks
暂无数据

先让 Agent 帮你看,再安装

把 GitHub 链接发给 DSH、Codex 或其他 Agent,请它先说明用途、权限、安装和卸载方法。确认后再复制命令;Agent 打不开链接时,可以粘贴 README 内容。

dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel

此命令由社区插件清单提供。运行前请打开仓库,确认安装说明和会执行的脚本。

查看原始目录数据

下面保留社区清单中的原始字段,方便和 GitHub 仓库核对。

原始数据1 个文件
registry-record.json只读
registry-record.json使用前请到 GitHub 核对
{
  "name": "dsh-plugin-sentinel",
  "owner": "BotonJ",
  "category": "dev",
  "description": "Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.",
  "descriptionZh": "插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。",
  "install": "dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel",
  "npm": null,
  "stars": 0,
  "added": "2026-08-15",
  "source": "registry"
}

安装前至少确认这几件事

看它会改哪些文件、访问哪些网站或 API key、运行哪些安装脚本,以及是否提供许可证和卸载方法。GitHub stars 只表示关注度。