dsh-remote-link
BotonJ/dsh-remote-link
官方 Web UI 的安全远程接入:带认证的局域网/隧道网关,QR + HMAC 一次性配对、按设备吊销,mDNS 发现,附 fork_session 会话分叉工具。
DeepSeek Harness 插件
插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。
跳到安装方式把 GitHub 链接发给 DSH、Codex 或其他 Agent,请它先说明用途、权限、安装和卸载方法。确认后再复制命令;Agent 打不开链接时,可以粘贴 README 内容。
dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel此命令由社区插件清单提供。运行前请打开仓库,确认安装说明和会执行的脚本。
下面保留社区清单中的原始字段,方便和 GitHub 仓库核对。
registry-record.json使用前请到 GitHub 核对{
"name": "dsh-plugin-sentinel",
"owner": "BotonJ",
"category": "dev",
"description": "Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.",
"descriptionZh": "插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。",
"install": "dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel",
"npm": null,
"stars": 0,
"added": "2026-08-15",
"source": "registry"
}看它会改哪些文件、访问哪些网站或 API key、运行哪些安装脚本,以及是否提供许可证和卸载方法。GitHub stars 只表示关注度。