DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Tool Npm Safe — DeepSeek Harness 插件(DSH Plugin)
← Plugins

@npm-safe/dsh-tool-npm-safe

Tool Npm Safe

DeepSeek Harness 插件,通过元数据和深度供应链扫描阻止有风险的 npm 安装

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add @npm-safe/dsh-tool-npm-safe@0.1.4
README兼容性版本

兼容性与来源证明

Tool Npm Safe 以 @npm-safe/dsh-tool-npm-safe 发布,当前版本为 0.1.4。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.1.4stable
2026/8/29
0.1.3stable
2026/8/29

相关插件

正在加载相关插件…

最新版
0.1.4
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
33.7 kB
文件数
6
Surface
any
许可证
Apache-2.0
发布源
npm
GitHub
★ 5
周下载
38
最近提交
2026/8/29
查看源码 ↗
项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

@npm-safe/dsh-tool-npm-safe

A DeepSeek Harness (dsh) tool plugin that exposes the @npm-safe/core-dsh supply-chain security engine as 14 dsh tools. AI agents can call package security scans directly inside a conversation, acting as a "check before you install" gate.

If this plugin is useful in your workflow, please Star the repository so other DSH users can find it.

Installation

dsh plugin --profile tui add @npm-safe/dsh-tool-npm-safe --allow-build=better-sqlite3
dsh --profile tui

The package declares a DSH bundle and activates cordis.patch.yml automatically. The --allow-build flag grants install-script permission only to the SQLite driver used for the local cache; pnpm continues blocking build scripts from other dependencies. Restart an already-running profile after installation.

Peer Dependencies

This plugin requires the following peer packages (all from the same RC family):

PackageVersion
@deepseek-ai/cordis^4.0.1
@deepseek-ai/dsh-tools0.1.0-rc.6
@deepseek-ai/dsh-jobs-local0.1.0-rc.6

Quick Start

Configure a model provider in DSH, then ask the agent to scan a package. A DeepSeek API key is only required when DeepSeek is your selected provider.

dsh --profile tui
Deep-scan fast-glob before installing it. Explain every finding.

Tools

The plugin registers the following 14 tools in a dsh session:

ToolPurposeExecution
check_packageCheck one package; optional deep tarball inspectionForeground (signal-forwarded)
check_packagesCheck multiple packages; optional deep inspectionForeground (rate-limited)
search_packagesKeyword search of the npm registryForeground
watch_addAdd a package to the watchlistForeground
watch_removeRemove a package from the watchlistForeground
watch_listList all watched packagesForeground
rules_listList all scan rules with statusForeground
rule_enableEnable a scan rule (persisted)Foreground
rule_disableDisable a scan rule (persisted)Foreground
rule_set_severityOverride a rule's severity (persisted)Foreground
settings_getRead an engine settingForeground
settings_setWrite an engine setting (persisted)Foreground
ci_scanDependency gate scan; optional deep inspectionForeground
refresh_allRefresh all watched packagesBackground (ctx.jobs.start)

Usage Examples

Check a single package

> Use check_package to check lodash

lodash@4.18.1: safe (85/100, 2 findings)

For higher assurance before installation, ask the agent to set deep: true:

> Deep-scan lodash with check_package before installing it

lodash@4.17.21: safe (82/100, 2 findings); deep scan complete, 154 files, integrity verified

Deep mode downloads the published tarball, rejects cross-origin downloads, verifies npm integrity metadata, and inspects bounded source content entirely in memory. It is optional because archive downloads add latency and bandwidth.

Batch check

> Use check_packages to check lodash, express, and axios

lodash: safe (85/100, 2 findings)
express: suspicious (62/100, 5 findings)
axios: safe (90/100, 1 findings)

CI gate scan

> Use ci_scan to scan dependencies

dir: /project
dependencies: 142
fail level: dangerous
failed: false
safe: 130
suspicious: 10
dangerous: 2

Background refresh

> Use refresh_all to refresh all watched packages

Background refresh job started: job-abc123

Engine

This plugin is powered by @npm-safe/core-dsh, a fork of @npm-safe/core re-architected for dsh integration. The engine provides:

  • 10 metadata rules plus 12 deep-content rules for archive integrity, unsafe paths, remote shell execution, obfuscation, process execution, secrets, and binaries
  • SQLite-backed caching with TTL-based staleness (default 1 hour)
  • TokenBucket rate limiter (5 tokens/s, 10 burst) to prevent registry throttling
  • Typed API for programmatic use

Original Repository

  • This plugin: https://github.com/nisconder/npm-safe-forDSH
  • Engine original repository: https://github.com/nisconder/npm-safe
  • dsh platform: https://github.com/deepseek-ai/deepseek-harness

License

Apache-2.0 — Copyright 2026 Nisconder, InfiniteScope, Escap1ng, StoryBegins.