Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.
- GitHub stars
- 4
- Added
- 2026-08-15
GitHub info
- GitHub stars
- 4
- Primary language
- JavaScript
- Last push
- Aug 17, 2026, 2:14 AM
- Maintainer
- truelove-dreamer
- Added
- 2026-08-15
Install
dsh plugin --profile web add dsh-plugin-vettingREADME badge
Add this Markdown to your plugin README to link back to its listing.
[](https://dshget.com/plugins/truelove-dreamer/dsh-plugin-vetting)Related plugins
Security & Permissionsapi-relay-audit
★ 819Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
dsh-pentest
★ 324Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
dsh-auto-review
★ 120Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.