{"schemaVersion":1,"generatedAt":"2026-08-29T00:00:28.979Z","source":{"url":"https://raw.githubusercontent.com/cclank/dsh-plugin-hub/main/data/codex-picks.json","repository":"https://github.com/cclank/dsh-plugin-hub","state":"live","updated":"2026-08-28T16:14:08.807Z","count":34,"matched":34,"error":null},"count":34,"plugins":[{"id":"lemoncat7/dsh-knowledge","order":203,"name":"dsh-knowledge","owner":"lemoncat7","repo":"lemoncat7/dsh-knowledge","url":"https://github.com/lemoncat7/dsh-knowledge","category":"workflow","description":{"zh":"为 DSH 提供本地或远程知识库、自动召回与回写，以及可由 AI 安全维护的分层笔记工作区。","en":"Adds local or remote knowledge bases, automatic recall and write-back, plus a hierarchical note workspace that AI can maintain through guarded tools."},"added":"2026-08-28","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-28T16:09:44.492Z","lastSeenAt":"2026-08-28T16:09:44.492Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-28T16:09:44.492Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"lemoncat7/dsh-knowledge","pickedAt":"2026-08-28T16:09:44.492Z","reviewedCommit":"6c1af1d3a6e7fff70e376f385bd33381afb2fd94","category":"workflow","summary":{"zh":"为 DSH 提供本地或远程知识库、自动召回与回写，以及可由 AI 安全维护的分层笔记工作区。","en":"Adds local or remote knowledge bases, automatic recall and write-back, plus a hierarchical note workspace that AI can maintain through guarded tools."},"reason":{"zh":"v2.0 把跨会话知识沉淀和普通资料管理接成一条完整工作流：笔记可搜索、分页读取、创建、修改、移动和安全删除，也能与知识文档建立稳定引用；会话签名句柄与当前用户指令校验让 AI 操作边界足够清楚，适合需要长期积累项目规范、研究资料和决策记录的人。","en":"Version 2.0 turns cross-session knowledge and ordinary reference material into one coherent workflow: notes can be searched, paged, created, edited, moved, safely deleted, and linked to knowledge documents. Session-signed handles and current-turn intent checks make the AI mutation boundary clear enough for people maintaining long-lived project rules, research material, and decisions."},"safety":{"risk":"medium","zh":"中风险：插件会持久化本地 SQLite 与笔记文件，回答后可再次调用当前模型做知识提取；远程模式会向配置的中央库发送内容，write/admin 权限还能修改或删除知识与笔记。默认使用本地后端、远程 API 关闭；远程地址强制 HTTPS（回环除外），令牌仅存摘要，AI 笔记操作要求当前用户直接指令并使用会话签名句柄，被引用笔记受删除保护。静态审查未发现 install/postinstall、Shell 执行或独立遥测。建议先用本地模式、保持 DSH 仅受信访问，并在授予远程 write/admin 前做好备份。","en":"Medium risk: the plugin persists local SQLite and note files, and may call the active model after a response to extract knowledge. Remote mode sends content to the configured central store, while write/admin permissions can modify or delete knowledge and notes. The default backend is local with the remote API disabled; remote URLs require HTTPS except on loopback, tokens are stored as hashes, AI note actions require a direct current-turn request and session-signed handles, and referenced notes are deletion-protected. Static review found no install/postinstall hook, shell execution, or independent telemetry. Start in local mode, keep DSH access trusted, back up data, and grant remote write/admin only when needed."}}},{"id":"rongyishuaige7/dsh-stats","order":204,"name":"dsh-stats","owner":"rongyishuaige7","repo":"rongyishuaige7/dsh-stats","url":"https://github.com/rongyishuaige7/dsh-stats","category":"ui","description":{"zh":"在 DSH Web 里按项目、日期和模型查看 Token、开发时长与估算费用，并查询多个模型平台的余额或套餐额度。","en":"Adds a DSH Web dashboard for project-, date-, and model-level token usage, development time, estimated cost, and provider balance or plan quota."},"added":"2026-08-27","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-27T16:31:56.411Z","lastSeenAt":"2026-08-27T16:31:56.411Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-27T16:31:56.411Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"rongyishuaige7/dsh-stats","pickedAt":"2026-08-27T16:31:56.411Z","reviewedCommit":"01690e81af7f1924ec2812f809bc28143f107c02","category":"ui","summary":{"zh":"在 DSH Web 里按项目、日期和模型查看 Token、开发时长与估算费用，并查询多个模型平台的余额或套餐额度。","en":"Adds a DSH Web dashboard for project-, date-, and model-level token usage, development time, estimated cost, and provider balance or plan quota."},"reason":{"zh":"v0.3.0 重做宿主聚合、模型计价与账户查询，peer 范围覆盖本机 DSH 0.1.0-rc.6；发布标签、40 位提交与 npm gitHead 一致，16 个发布文件逐字节匹配，npm 包有签名且只有 zod 一个运行依赖。仓库还提供 DSH 0.1.1-rc.2 浏览器冒烟证据。","en":"v0.3.0 rebuilds host-side aggregation, model pricing, and account queries, with a peer range covering the local DSH 0.1.0-rc.6. The release tag, immutable commit, and npm gitHead match; all 16 published files match byte-for-byte, the npm tarball is signed, and zod is the only runtime dependency. The repository also documents a DSH 0.1.1-rc.2 browser smoke run."},"safety":{"risk":"medium","zh":"中风险：会读取本地会话日志、项目与模型元数据，并可把统计导出为 CSV/JSON；余额查询通过宿主 credentials 解析密钥，再发往官方或用户配置的同源 HTTPS 账户端点。自定义账户模板允许把密钥放入请求头或请求体。未发现遥测、Shell、install/postinstall；建议只在可信的环回 Web 使用，先核对自定义 Provider 的账户模板，导出前检查项目标识。","en":"Medium risk: it reads local session logs, project identity, and model metadata and can export statistics as CSV or JSON. Balance checks resolve secrets through the host credentials service and send them to official or user-configured same-origin HTTPS account endpoints; custom account templates may place keys in headers or bodies. No telemetry, shell execution, install, or postinstall hook was found. Keep the Web UI on trusted loopback, review custom provider account templates, and inspect project identity before exporting."}}},{"id":"sirilee/dsh-rewind","order":205,"name":"dsh-rewind","owner":"sirilee","repo":"sirilee/dsh-rewind","url":"https://github.com/sirilee/dsh-rewind","category":"session","description":{"zh":"把当前会话回退到任意更早的用户消息，并可连同已跟踪的工作区文件一起恢复；v0.4.2 加入原子检查点和日志化文件还原。","en":"Rewinds the current session to any earlier user message and can restore tracked workspace files with it; v0.4.2 adds atomic checkpoints and journaled file restores."},"added":"2026-08-27","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-27T10:07:28.673Z","lastSeenAt":"2026-08-27T10:07:28.673Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-27T10:07:28.673Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"sirilee/dsh-rewind","pickedAt":"2026-08-27T10:07:28.673Z","reviewedCommit":"64c78c3898a969a777b243c64d515fb5c30e269c","category":"session","summary":{"zh":"把当前会话回退到任意更早的用户消息，并可连同已跟踪的工作区文件一起恢复；v0.4.2 加入原子检查点和日志化文件还原。","en":"Rewinds the current session to any earlier user message and can restore tracked workspace files with it; v0.4.2 adds atomic checkpoints and journaled file restores."},"reason":{"zh":"它补上了 DSH 实用的 /rewind 体验：先看文件影响，再确认仅回退对话或同时还原代码。0.4.2 的 npm 发布包有 provenance、零运行时依赖，兼容本机 DSH rc.6，源码含崩溃恢复与重启场景测试。","en":"It adds a practical /rewind flow to DSH: preview file impact, then confirm a conversation-only rewind or restore code too. The 0.4.2 npm artifact has provenance, zero runtime dependencies, supports the local DSH rc.6, and includes crash-recovery and restart tests."},"safety":{"risk":"medium","zh":"中风险：both 模式会覆盖或删除已跟踪文件，并把文件原文备份到 ~/.dsh/rewind-snapshots；执行前展示影响清单并二次确认，跳过软链接和硬链接，0.4.2 使用原子写入与恢复日志。运行包无外部联网、遥测、密钥读取、Shell 执行或运行时依赖。崩溃后的继续/回滚能力目前只暴露为程序接口，尚无用户界面。","en":"Medium risk: both mode overwrites or deletes tracked files and stores their original contents under ~/.dsh/rewind-snapshots. It previews the impact and requires confirmation, skips symlinks and hard links, and uses atomic writes plus restore journals in 0.4.2. The runtime has no external network access, telemetry, credential reads, shell execution, or runtime dependencies. Continue/rollback after a crash is currently exposed only as a programmatic API, with no user-facing UI."}}},{"id":"icearia0219/dsh-memory-spaces","order":206,"name":"dsh-memory-spaces","owner":"icearia0219","repo":"icearia0219/dsh-memory-spaces","url":"https://github.com/icearia0219/dsh-memory-spaces","category":"session","description":{"zh":"让用户把指定会话明确连接到命名记忆空间，按来源、使用者和注入模式控制跨会话共享。","en":"Adds explicitly governed cross-session memory spaces with separate source, consumer, and injection controls."},"added":"2026-08-26","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-26T10:06:58.123Z","lastSeenAt":"2026-08-26T10:06:58.123Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-26T10:06:58.123Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"icearia0219/dsh-memory-spaces","pickedAt":"2026-08-26T10:06:58.123Z","reviewedCommit":"5944dd403e0a184e68d2116db2a3f3919e4042e3","category":"session","summary":{"zh":"让用户把指定会话明确连接到命名记忆空间，按来源、使用者和注入模式控制跨会话共享。","en":"Adds explicitly governed cross-session memory spaces with separate source, consumer, and injection controls."},"reason":{"zh":"适合长期项目在调研、架构和编码会话间复用已确认约束；本地 Profile 级 SQLite、发送前预览、来源与版本记录让共享边界可检查。","en":"Useful for long-running projects that reuse verified constraints across research, architecture, and coding sessions; profile-local SQLite, pre-send previews, provenance, and versioning keep sharing inspectable."},"safety":{"risk":"medium","zh":"中风险：记忆与快照以未加密 SQLite 存在本机，逻辑删除不保证物理擦除；注入内容仍有 Prompt Injection 风险。快照链接是可过期 Bearer 凭证，可经浏览器历史、日志或剪贴板泄漏；可选历史摘要会把所选内容发送给当前模型服务。数据库在非 Windows 设为 0600，旧 schema 迁移备份仍需用户保护。","en":"Medium risk: memories and snapshots remain in unencrypted local SQLite, and logical deletion is not secure erasure; injected content can still carry prompt injection. Expiring bearer snapshot URLs may leak through browser history, logs, or clipboard history, and optional history summaries send selected content to the active model provider. The database is chmod 0600 on non-Windows; legacy-schema migration backups still require user protection."}}},{"id":"yangbobo2021/relay-dsh-plugin-codex","order":207,"name":"relay-dsh-plugin-codex","owner":"yangbobo2021","repo":"yangbobo2021/relay-dsh-plugin-codex","url":"https://github.com/yangbobo2021/relay-dsh-plugin-codex","category":"workflow","description":{"zh":"把官方 Codex App Server 接入 DSH 会话模式，保留流式输出、审批、提问、图片和历史续聊。","en":"Adds the official Codex App Server as a native DSH conversation mode with streaming, approvals, questions, images, and resumable history."},"added":"2026-08-26","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-26T04:06:02.849Z","lastSeenAt":"2026-08-26T04:06:02.849Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-26T04:06:02.849Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"yangbobo2021/relay-dsh-plugin-codex","pickedAt":"2026-08-26T04:06:02.849Z","reviewedCommit":"5fff6c6c825f8d817fc640c5b89f799786ecc045","category":"workflow","summary":{"zh":"把官方 Codex App Server 接入 DSH 会话模式，保留流式输出、审批、提问、图片和历史续聊。","en":"Adds the official Codex App Server as a native DSH conversation mode with streaming, approvals, questions, images, and resumable history."},"reason":{"zh":"适合把现有 Codex 登录与会话历史带进 DSH；0.1.2 固定官方运行时版本，本机 Node 22 与 DSH rc.6 满足其声明范围，CI 和 npm 发布来源可核验。","en":"A practical bridge for bringing existing Codex authentication and conversation history into DSH; v0.1.2 pins the official runtime, matches the local Node 22 and DSH rc.6 ranges, and has verifiable CI and npm provenance."},"safety":{"risk":"medium","zh":"中风险：会启动官方 Codex 子进程，并把提示词和所选文件交给 Codex 服务；默认 workspace-write 与按需审批，Workspace 沙盒禁网。远程导入需要 Bearer Token，本机 loopback 路由对本地进程开放；App Server 以 analytics 默认启用参数启动。","en":"Medium risk: it spawns the official Codex runtime and sends prompts and selected files to the Codex service. Defaults are workspace-write, on-request approvals, and no network in the workspace sandbox. Remote import requires a bearer token, loopback routes remain callable by local processes, and App Server starts with analytics enabled by default."}}},{"id":"tyeclipse/dsh-netdoctor","order":208,"name":"dsh-netdoctor","owner":"tyeclipse","repo":"tyeclipse/dsh-netdoctor","url":"https://github.com/tyeclipse/dsh-netdoctor","category":"tools","description":{"zh":"给 DSH Agent 增加 DNS、Ping、端口、TLS、路由、公网 IP 与 WHOIS 七种结构化网络诊断工具。","en":"Adds seven structured network diagnostics to DSH agents: DNS, ping, TCP port, TLS, traceroute, public IP, and WHOIS."},"added":"2026-08-25","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-25T22:04:54.042Z","lastSeenAt":"2026-08-25T22:04:54.042Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-25T22:04:54.042Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"tyeclipse/dsh-netdoctor","pickedAt":"2026-08-25T22:04:54.042Z","reviewedCommit":"289f3df178a07fa48b2578ae4072cb656232461b","category":"tools","summary":{"zh":"给 DSH Agent 增加 DNS、Ping、端口、TLS、路由、公网 IP 与 WHOIS 七种结构化网络诊断工具。","en":"Adds seven structured network diagnostics to DSH agents: DNS, ping, TCP port, TLS, traceroute, public IP, and WHOIS."},"reason":{"zh":"零运行时依赖、兼容本机 DSH rc.6，源码与 v0.2.0 发布完整；固定参数调用系统工具并设硬超时，适合稳定排查连通性、DNS 与证书问题。","en":"It has zero runtime dependencies, supports the local DSH rc.6 line, and ships complete source plus a tagged v0.2.0 release. Fixed argument arrays and hard timeouts make connectivity, DNS, and certificate checks predictable."},"safety":{"risk":"medium","zh":"中风险：工具不会写文件或修改系统，外部命令不经 Shell；但 Agent 可探测公网、局域网和本机端口，my_ip 默认会向 ip-api.com（HTTP）或 ipify 外发公网 IP，WHOIS 会向注册局发送查询目标。建议仅在可信会话启用，并将 includeGeo 设为 false。","en":"Medium risk: the tools do not write files or change system state, and subprocesses never use a shell. However, an agent can probe public, LAN, and loopback targets; my_ip sends the public IP to ip-api.com over HTTP or to ipify by default, and WHOIS sends the queried target to registries. Enable it only in trusted sessions and set includeGeo to false."}}},{"id":"tqsy114514/dsh-ui-appearance","order":209,"name":"dsh-ui-appearance","owner":"tqsy114514","repo":"tqsy114514/dsh-ui-appearance","url":"https://github.com/tqsy114514/dsh-ui-appearance","category":"ui","description":{"zh":"在 DSH Web 设置中实时调整主题色、壁纸或视频背景、透明度与模糊效果，并支持导入导出配色。","en":"Adds live theme colors, image or video wallpapers, opacity and blur controls, plus theme import and export to DSH Web settings."},"added":"2026-08-24","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-24T10:01:19.989Z","lastSeenAt":"2026-08-24T10:01:19.989Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-24T10:01:19.989Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"tqsy114514/dsh-ui-appearance","pickedAt":"2026-08-24T10:01:19.989Z","reviewedCommit":"c947e0f24a36802d660f9979d1b0e506590d4216","category":"ui","summary":{"zh":"在 DSH Web 设置中实时调整主题色、壁纸或视频背景、透明度与模糊效果，并支持导入导出配色。","en":"Adds live theme colors, image or video wallpapers, opacity and blur controls, plus theme import and export to DSH Web settings."},"reason":{"zh":"v0.1.5 有正式 GitHub Release 与签名 npm 包；发布包 source map 中 12 个源码文件与对应 Git 标签逐字一致，CI 的构建、97 项测试和 CodeQL 均通过，本机 rc.6 已具备它依赖的主题覆写与设置插槽接口。","en":"Version 0.1.5 has a formal GitHub release and a signed npm package. All 12 source files embedded in the published source map match the Git tag byte for byte, CI passes its build, 97 tests, and CodeQL, and the local rc.6 already exposes the theme override and settings slot APIs it uses."},"safety":{"risk":"medium","zh":"代码仅在浏览器侧修改主题与保存本地外观数据，没有遥测、密钥读取或宿主文件访问，生产依赖审计为零漏洞。插件仍拥有 DSH 同源页面执行权限；使用远程壁纸 URL 会向目标站点发起请求，Windows 一键脚本还会修改 profile。建议固定安装 npm 版本 dsh-ui-appearance@0.1.5，优先上传本地壁纸，并避免执行 main 分支上的可变安装脚本。","en":"The code only changes browser-side theme state and stores local appearance data, with no telemetry, credential access, or host file access; the production dependency audit reports zero vulnerabilities. It still executes in the DSH same-origin page, remote wallpaper URLs contact the chosen host, and the Windows helper edits the profile. Pin dsh-ui-appearance@0.1.5, prefer local wallpaper uploads, and avoid the mutable installer script from main."}}},{"id":"saya-ch/dsh-mobile","order":210,"name":"dsh-mobile","owner":"saya-ch","repo":"saya-ch/dsh-mobile","url":"https://github.com/saya-ch/dsh-mobile","category":"ui","description":{"zh":"让 Android App 或手机浏览器通过配对 HTTPS 网关继续使用同一份 DSH 会话、工作区、消息与工具，并支持局域网及可选远程通道。","en":"Lets an Android app or mobile browser use the same DSH sessions, workspaces, messages, and tools through a paired HTTPS gateway, with LAN and optional remote access."},"added":"2026-08-24","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-24T04:01:16.734Z","lastSeenAt":"2026-08-24T04:01:16.734Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-24T04:01:16.734Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"saya-ch/dsh-mobile","pickedAt":"2026-08-24T04:01:16.734Z","reviewedCommit":"e1f72c5130d97cc38dca8fa398f42487caad0cdc","category":"ui","summary":{"zh":"让 Android App 或手机浏览器通过配对 HTTPS 网关继续使用同一份 DSH 会话、工作区、消息与工具，并支持局域网及可选远程通道。","en":"Lets an Android app or mobile browser use the same DSH sessions, workspaces, messages, and tools through a paired HTTPS gateway, with LAN and optional remote access."},"reason":{"zh":"v0.2.0 兼容本机 DSH rc.6，GitHub Release 与 npm 包哈希一致，CI 覆盖网关、Android 和当前 DSH 前端契约；配对、设备撤销与移动布局完成度高。","en":"Version 0.2.0 supports the local DSH rc.6; its GitHub release and npm package hashes match, and CI covers the gateway, Android app, and current DSH frontend contract. Pairing, revocation, and the mobile layout are unusually complete."},"safety":{"risk":"high","zh":"配对设备等同完整 DSH 操作者；可选远程通道、兼容 DSH 所需的宽松脚本 CSP、mobile.js 以及未沙箱化的 host.mjs 会扩大攻击面。默认局域网与远程访问关闭，设备凭据只持久化摘要并限制文件权限，同时具备 CSRF、短会话、CIDR、撤销和速率限制。首试应只用可信局域网，并关闭远程和自定义扩展。","en":"A paired device is a fully trusted DSH operator. Optional remote tunnels, the permissive script CSP required by DSH, mobile.js, and unsandboxed host.mjs extensions expand the attack surface. LAN and remote access are off by default; only device-token digests are persisted with restricted permissions, and CSRF, short sessions, CIDR checks, revocation, and rate limits are enforced. First trials should stay on a trusted LAN with remote access and custom extensions disabled."}}},{"id":"hytime/dsh-client-ui-shortcuts","order":211,"name":"dsh-client-ui-shortcuts","owner":"hytime","repo":"hytime/dsh-client-ui-shortcuts","url":"https://github.com/hytime/dsh-client-ui-shortcuts","category":"ui","description":{"zh":"为 DSH Web 增加平台感知、可配置的键盘操作，可直接处理提问与审批，并快速切换会话和工作区。","en":"Adds platform-aware, configurable keyboard controls to DSH Web for questions, approvals, sessions, and workspaces."},"added":"2026-08-23","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-23T22:00:55.425Z","lastSeenAt":"2026-08-23T22:00:55.425Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-23T22:00:55.425Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"hytime/dsh-client-ui-shortcuts","pickedAt":"2026-08-23T22:00:55.425Z","reviewedCommit":"98d7de1790024f1f17c64a52ebdf8ff7e29fb303","category":"ui","summary":{"zh":"为 DSH Web 增加平台感知、可配置的键盘操作，可直接处理提问与审批，并快速切换会话和工作区。","en":"Adds platform-aware, configurable keyboard controls to DSH Web for questions, approvals, sessions, and workspaces."},"reason":{"zh":"v0.1.12 同时有 GitHub Release、npm 签名包和对应源码标签；浏览器端实现覆盖高频交互，能明显减少鼠标操作。","en":"Version 0.1.12 has a GitHub release, a signed npm package, and a matching source tag; its browser-side implementation covers the highest-frequency DSH interactions."},"safety":{"risk":"medium","zh":"未发现遥测、外部网络请求、安装生命周期脚本或本地文件访问。插件可提交提问答案、允许一次工具审批、取消任务以及创建或切换会话，需防范回车快捷键误操作；要求 DSH 0.1.0-rc.8 或更高版本。","en":"No telemetry, external network requests, install lifecycle scripts, or local file access were found. The plugin can submit answers, allow a tool once, cancel tasks, and create or switch sessions, so Enter-key mistakes remain possible; DSH 0.1.0-rc.8 or newer is required."}}},{"id":"may3rr/dsh-tool-result-guard","order":216,"name":"dsh-tool-result-guard","owner":"may3rr","repo":"may3rr/dsh-tool-result-guard","url":"https://github.com/may3rr/dsh-tool-result-guard","category":"tools","description":{"zh":"把超过阈值的纯文本工具结果先完整落盘，再以首尾预览、精确省略区间和可恢复路径返回给模型，补齐 DSH 中等长度输出在压缩时缺少取回入口的空档。","en":"Spills oversized plain-text tool results before pruning, then returns a bounded head/tail preview with exact omitted offsets and a recovery locator, closing DSH recoverability gaps for mid-sized outputs."},"added":"2026-08-22","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-22T16:10:46.007Z","lastSeenAt":"2026-08-22T16:10:46.007Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-22T16:10:46.007Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"may3rr/dsh-tool-result-guard","pickedAt":"2026-08-22T16:10:46.007Z","reviewedCommit":"45313fed7dfb8063930457fdcd68f54f6ce4f449","category":"tools","summary":{"zh":"把超过阈值的纯文本工具结果先完整落盘，再以首尾预览、精确省略区间和可恢复路径返回给模型，补齐 DSH 中等长度输出在压缩时缺少取回入口的空档。","en":"Spills oversized plain-text tool results before pruning, then returns a bounded head/tail preview with exact omitted offsets and a recovery locator, closing DSH recoverability gaps for mid-sized outputs."},"reason":{"zh":"官方 rc.2 的压缩剪枝器默认在 8192 字符后仅保留首尾，而 spill policy 到 50000 字节才触发；该插件以零运行依赖和单命令安装提供可回读中段，适合经常跑构建、测试和日志分析的本地工作流。","en":"In official rc.2, the compaction pruner keeps only head and tail after 8,192 characters while spill policy starts at 50,000 bytes. This zero-runtime-dependency plugin gives build, test, and log-heavy workflows a recoverable middle through one-command installation."},"safety":{"risk":"medium","zh":"中风险：核心包无运行依赖、无生命周期脚本、无网络或遥测；它会把长工具输出写入权限为 0700 的目录和 0600 的文件，回退临时文件没有内建清理期限，输出可能含密钥或业务数据，建议沿用 Harness spillStore 并定期清理。","en":"Medium risk: the core package has no runtime dependencies, lifecycle scripts, network calls, or telemetry. It writes long tool output to 0700 directories and 0600 files; fallback temp files have no built-in retention deadline and may contain secrets or business data, so prefer the Harness spillStore and clean up regularly."}}},{"id":"liznee/dsh-file-resource","order":217,"name":"dsh-file-resource","owner":"liznee","repo":"liznee/dsh-file-resource","url":"https://github.com/liznee/dsh-file-resource","category":"tools","description":{"zh":"把图片、PDF、Word、Excel、PPT、ODF、EPUB 与常见代码文件统一接入 DSH Web 的 + 菜单；文档在本机解析，模型按页、工作表、幻灯片或文本块按需读取。","en":"Adds one attachment entry to the DSH Web + menu for images, PDF, Office, ODF, EPUB, and common code files; documents are parsed locally and read by the model on demand by page, sheet, slide, or bounded text chunk."},"added":"2026-08-22","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-22T04:05:48.052Z","lastSeenAt":"2026-08-22T04:05:48.052Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-22T04:05:48.052Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"liznee/dsh-file-resource","pickedAt":"2026-08-22T04:05:48.052Z","reviewedCommit":"a3a4f49151ebf4cb7c7134b61cc65ee4fa6374a8","category":"tools","summary":{"zh":"把图片、PDF、Word、Excel、PPT、ODF、EPUB 与常见代码文件统一接入 DSH Web 的 + 菜单；文档在本机解析，模型按页、工作表、幻灯片或文本块按需读取。","en":"Adds one attachment entry to the DSH Web + menu for images, PDF, Office, ODF, EPUB, and common code files; documents are parsed locally and read by the model on demand by page, sheet, slide, or bounded text chunk."},"reason":{"zh":"v0.1.0 把文档附件做成顺手的原生交互，避免把全文一次性塞进上下文。发布标签对应 npm gitHead，npm 签名与 tarball 完整性已核对，发布包和标签源码逐文件一致；Node 22/24 CI 通过，生产依赖审计为 0 个漏洞，安装与卸载命令完整。","en":"v0.1.0 makes document attachments feel native and avoids injecting entire files into context. The release tag matches the npm gitHead, the npm signature and tarball integrity were verified, and the published package matches the tagged source file for file. Node 22/24 CI passed, the production dependency audit reports zero vulnerabilities, and install and removal paths are documented."},"safety":{"risk":"medium","zh":"中风险：无遥测、无第三方上传、无安装期生命周期脚本；原文件与派生文本以 0600 文件权限保存在 DSH_HOME 下，会话绑定与同源检查限制读取，单次读取硬上限 24000 字符。风险来自敏感文档会在模型实际调用读取工具后进入当前模型提供方，以及 PDF/ZIP/Office 解析器的攻击面；只选择愿意交给当前模型提供方处理的文件，并保持插件与 pdfjs-dist 更新。","en":"Medium risk: there is no telemetry, third-party upload, or install-time lifecycle script. Original and derived files are stored under DSH_HOME with mode 0600, while session binding and same-origin checks restrict reads and each tool response is capped at 24,000 characters. Sensitive content reaches the configured model provider after the model invokes the read tool, and PDF/ZIP/Office parsers retain an attack surface; attach only files suitable for that provider and keep the plugin and pdfjs-dist updated."}}},{"id":"alloevil/dsh-xray","order":231,"name":"dsh-xray","owner":"alloevil","repo":"alloevil/dsh-xray","url":"https://github.com/alloevil/dsh-xray","category":"tools","description":{"zh":"给 DSH 组合树做只读诊断：追踪插件来源、配置冲突、依赖级联、运行健康与上下文成本，并提供 CLI、Web 面板和 Agent 自省工具。","en":"Provides read-only diagnostics for the DSH composition tree: plugin provenance, configuration conflicts, dependency cascades, runtime health, and context cost through a CLI, Web panel, and agent introspection tool."},"added":"2026-08-21","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-21T04:00:13.727Z","lastSeenAt":"2026-08-21T04:00:13.727Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-21T04:00:13.727Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"alloevil/dsh-xray","pickedAt":"2026-08-21T04:00:13.727Z","reviewedCommit":"ae44549c9290b1d6c8a7f48463f606377cd12ad9","category":"tools","summary":{"zh":"给 DSH 组合树做只读诊断：追踪插件来源、配置冲突、依赖级联、运行健康与上下文成本，并提供 CLI、Web 面板和 Agent 自省工具。","en":"Provides read-only diagnostics for the DSH composition tree: plugin provenance, configuration conflicts, dependency cascades, runtime health, and context cost through a CLI, Web panel, and agent introspection tool."},"reason":{"zh":"v0.6.0 能在 DSH 启动失败时用静态 CLI 定位孤立 patch 和配置冲突，挂载后还能查看实时依赖、健康与成本；对插件较多的本机和插件 Hub 复核流程都很有价值。审核的发布提交与 npm gitHead 一致，Node 22/24 CI 通过，npm 包带 SLSA provenance，生产依赖审计为 0 个漏洞。","en":"v0.6.0 can use static CLI analysis to find orphaned patches and configuration conflicts even when DSH cannot start, then adds live dependency, health, and cost views when mounted. It is useful for plugin-heavy local setups and Hub review workflows. The reviewed release commit matches the npm gitHead, Node 22/24 CI passed, the npm package carries SLSA provenance, and the production dependency audit reports zero vulnerabilities."},"safety":{"risk":"medium","zh":"中风险：无遥测和外部网络请求，安装无生命周期脚本；但 CLI 会读取 DSH profile、patch 和第三方插件源码，diff 会通过 execFile 启动本机 dsh --dump-config。挂载后会把插件与服务信息、fiber 错误、工具 schema 的名称/描述/参数、prompt section 名称和 token 估算写入 $DSH_HOME/xray/runtime.json，并通过同一 DSH 服务的 /xray 暴露诊断元数据；不会采集会话正文、prompt section 正文或凭据。仅在回环地址或有认证的反向代理后启用；v0.6.0 Git 标签未签名。","en":"Medium risk: there is no telemetry or external network request and installation has no lifecycle scripts, but the CLI reads DSH profiles, patches, and third-party plugin source, while diff starts the local dsh --dump-config command through execFile. When mounted, it writes plugin and service data, fiber errors, tool-schema names/descriptions/parameters, prompt-section names, and token estimates to $DSH_HOME/xray/runtime.json and exposes diagnostic metadata at /xray on the same DSH server; it does not collect conversation text, prompt-section bodies, or credentials. Enable it only on loopback or behind an authenticated reverse proxy; the v0.6.0 Git tag is unsigned."}}},{"id":"mantonlove/dsh-conversation-landmarks","order":242,"name":"dsh-conversation-landmarks","owner":"mantonlove","repo":"mantonlove/dsh-conversation-landmarks","url":"https://github.com/mantonlove/dsh-conversation-landmarks","category":"ui","description":{"zh":"在 DSH Web 长会话左侧增加任务地标轨，悬停预览请求与最近回答，点击后自动加载旧历史并跳到对应消息。","en":"Adds a task landmark rail to long DSH Web conversations, with request and latest-answer previews plus automatic older-history loading and exact-message jumps."},"added":"2026-08-20","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-20T20:41:37.185Z","lastSeenAt":"2026-08-20T20:41:37.185Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-20T20:41:37.185Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"mantonlove/dsh-conversation-landmarks","pickedAt":"2026-08-20T20:41:37.185Z","reviewedCommit":"d9d7e974181c3b095a557c92b12ddf46fd03406a","category":"ui","summary":{"zh":"在 DSH Web 长会话左侧增加任务地标轨，悬停预览请求与最近回答，点击后自动加载旧历史并跳到对应消息。","en":"Adds a task landmark rail to long DSH Web conversations, with request and latest-answer previews plus automatic older-history loading and exact-message jumps."},"reason":{"zh":"它只索引直接用户任务，使用官方 session projection 与 client slot 扩展点，不改 DSH 源码。v0.1.0 已提交预构建产物，安装不触发构建脚本；静态核对源码与 lib 未发现网络、遥测、Shell 或文件写入，生产依赖审计为 0 个漏洞。适合经常在长会话里回找需求与答案的人。","en":"It indexes direct user tasks through the official session projection and client slot extension points without patching DSH. v0.1.0 commits prebuilt artifacts so installation runs no build hook; static review of source and lib found no network, telemetry, shell, or file writes, and the production dependency audit reports zero vulnerabilities. It suits users who often revisit requests and answers in long sessions."},"safety":{"risk":"low","zh":"低风险：会读取会话中的用户请求与最近一条助手文本，并在当前 Web 页面显示最多 320 字预览；不会外发、持久化或读取凭据。点击地标会调用官方分页接口加载更早的本地历史。共享屏幕或多人可访问 Web UI 时，预览可能暴露会话内容；v0.1.0 标签未签名且没有公开 CI，升级前应重新核对提交。","en":"Low risk: it reads user requests and the latest assistant text from the active session and shows previews of up to 320 characters in the current Web page; it does not transmit, persist, or access credentials. Clicking a landmark uses the official paging API to load older local history. Previews can expose session content during screen sharing or multi-user Web access; the v0.1.0 tag is unsigned and has no public CI, so re-check the commit before upgrading."}}},{"id":"armywas/dsh-plugin-reducer","order":243,"name":"dsh-plugin-reducer","owner":"armywas","repo":"armywas/dsh-plugin-reducer","url":"https://github.com/armywas/dsh-plugin-reducer","category":"dev","description":{"zh":"在真实 Profile 外部自动缩减插件组合，找出能稳定复现启动或命令故障的 1-最小 bundle 集，并输出脱敏 JSON 证据。","en":"Reduces plugin combinations outside the live Profile to find a 1-minimal bundle set that reproduces startup or command failures, with redacted JSON evidence."},"added":"2026-08-20","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-20T18:41:06.642Z","lastSeenAt":"2026-08-20T18:41:06.642Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-20T18:41:06.642Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"armywas/dsh-plugin-reducer","pickedAt":"2026-08-20T18:41:06.642Z","reviewedCommit":"a17be6e0369ca775aef07e1346c9db71f50e52d1","category":"dev","summary":{"zh":"在真实 Profile 外部自动缩减插件组合，找出能稳定复现启动或命令故障的 1-最小 bundle 集，并输出脱敏 JSON 证据。","en":"Reduces plugin combinations outside the live Profile to find a 1-minimal bundle set that reproduces startup or command failures, with redacted JSON evidence."},"reason":{"zh":"它能处理 A、B 单独正常但组合后故障的插件冲突。v0.3.0 提供版本化 JSON 与 Schema，运行时零依赖；核实提交与 Release 一致，发布资产 SHA-256 匹配，38 项测试以及 Windows、macOS、Linux 的 Node 22.19/24 CI 全部通过。每次探针使用新的影子 DSH_HOME，并校验源 Profile 指纹未变。","en":"It diagnoses interaction failures where plugins A and B work alone but fail together. v0.3.0 adds versioned JSON and schemas with zero runtime dependencies. The reviewed commit matches the release, the asset SHA-256 verifies, and 38 tests pass across Windows, macOS, and Linux on Node 22.19 and 24. Every probe uses a fresh shadow DSH_HOME and verifies that the source Profile fingerprint is unchanged."},"safety":{"risk":"medium","zh":"中风险：会读取 Profile manifest、patch 和 settings，链接现有 node_modules，并以当前用户权限重复运行已安装插件或用户明确提供的探针；影子 DSH_HOME 只隔离配置，不提供文件、进程、环境变量或网络沙箱。它不复制凭据库、会话或工作区文件，不安装包，也没有安装生命周期脚本，报告会尽力脱敏。仅用于可信插件和探针，分享报告前人工复核，敏感配置场景不要保留影子目录。","en":"Medium risk: it reads Profile manifests, patches, and settings, links existing node_modules, and repeatedly runs installed plugins or an explicitly supplied probe with the current user permissions. The shadow DSH_HOME isolates configuration only; it is not a filesystem, process, environment, or network sandbox. It does not copy credential stores, sessions, or workspace files, installs no packages, has no install lifecycle scripts, and applies best-effort report redaction. Use trusted plugins and probes only, review reports before sharing, and avoid keeping the shadow lab when configuration is sensitive."}}},{"id":"liustack/modsearch","order":113,"name":"modsearch","owner":"liustack","repo":"liustack/modsearch","url":"https://github.com/liustack/modsearch","category":"tools","description":{"en":"Web search bridge for text-only agents: ask the web or X, get structured JSON evidence (search, fetch, citations).","zh":"纯文本 agent 的联网搜索桥：搜索网页与 X，返回结构化 JSON 证据（search/fetch/引用）。"},"added":"2026-08-14","curated":true,"topic":true,"stars":76,"forks":4,"openIssues":2,"watchers":76,"pushedAt":"2026-08-13T21:49:49Z","updatedAt":"2026-08-14T06:19:35Z","createdAt":"2026-02-22T07:12:53Z","license":"MIT","language":"TypeScript","homepage":"https://liustack.dev","archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle"],"packageName":"@liustack/modsearch","version":"5.3.0","lifecycleScripts":[],"runtimeDependencies":2,"declaredPaths":["cordis.patch.yml","dsh/index.js"],"invalidDeclaredPaths":[]},"installCommand":null,"discovery":{"source":"curated","firstSeenAt":"2026-08-14","lastSeenAt":"2026-08-14T08:18:12.622Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-14T08:18:12.622Z","findings":[],"filesInspected":["package.json"],"checks":{"manifest":true,"license":true,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"clear","reasons":[]},"screenedCommit":null,"codexPick":{"repo":"liustack/modsearch","pickedAt":"2026-08-20T16:39:06.221Z","reviewedCommit":"515313ee5f5629dc3955f73ad5012163969e142f","category":"tools","summary":{"zh":"给 DSH 原生 web_search 接入可回退的多引擎检索链，并新增 X 搜索、单页抓取和 Web 设置卡。","en":"Adds a fallback-capable multi-engine chain behind DSH web_search, plus X search, focused page reading, and a Web settings card."},"reason":{"zh":"v5.7.0 让 DSH Web 用户可以直接配置搜索引擎和密钥；Release tag、npm gitHead 与核实提交一致，包带 SLSA provenance，Ubuntu、macOS、Windows 的 Node 22/24 测试与 lint 全部通过。适合需要联网查证、X 检索和页面阅读的人。","en":"v5.7.0 lets DSH Web users configure search engines and keys directly. The release tag and npm gitHead match the reviewed commit, the package has SLSA provenance, and lint plus Node 22/24 tests pass on Ubuntu, macOS, and Windows. It suits users who need sourced web research, X search, and page reading."},"safety":{"risk":"medium","zh":"中风险：默认 Firecrawl 会接收查询和公开 URL；Tavily、Exa、Firecrawl 自定义端点会接收查询与对应密钥，可选 Antigravity 和 Grok 路线会启动本机 CLI。设置路由仅接受同源回环请求，浏览器拿不到已保存密钥，配置按 0600 原子写入；本地抓取默认拦截私网并固定 DNS 解析。可选 Antigravity 文档含 curl 管道脚本，运行还使用跳过权限检查参数，未经单独审计不要启用；先用 Firecrawl 或 local，避免提交敏感查询。","en":"Medium risk: default Firecrawl receives queries and public URLs; custom Tavily, Exa, and Firecrawl endpoints receive queries and their keys, while optional Antigravity and Grok routes spawn local CLIs. The settings route accepts same-origin loopback requests only, the browser never receives saved keys, config is atomically written as 0600, and local fetch blocks private networks with DNS pinning by default. Antigravity docs include a curl pipeline installer and its runtime uses a skip-permissions flag, so do not enable it without a separate audit; start with Firecrawl or local and avoid sensitive queries."}}},{"id":"nickhelion/dsh-qwen-token-plan-cn-responses","order":244,"name":"dsh-qwen-token-plan-cn-responses","owner":"nickhelion","repo":"nickhelion/dsh-qwen-token-plan-cn-responses","url":"https://github.com/nickhelion/dsh-qwen-token-plan-cn-responses","category":"tools","description":{"zh":"为 DSH 接入千问 Token Plan 个人版 Responses API，同时保留本地函数工具，并按官方文档同步模型与内置搜索、代码解释器等能力。","en":"Adds Qwen Token Plan Personal Responses API support to DSH while preserving local function tools and syncing model plus built-in search and code-interpreter capabilities from official documentation."},"added":"2026-08-20","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-20T14:38:05.763Z","lastSeenAt":"2026-08-20T14:38:05.763Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-20T14:38:05.763Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"nickhelion/dsh-qwen-token-plan-cn-responses","pickedAt":"2026-08-20T14:38:05.763Z","reviewedCommit":"4b5dc07a446e9c8d03234d4f6b953db952344560","category":"tools","summary":{"zh":"为 DSH 接入千问 Token Plan 个人版 Responses API，同时保留本地函数工具，并按官方文档同步模型与内置搜索、代码解释器等能力。","en":"Adds Qwen Token Plan Personal Responses API support to DSH while preserving local function tools and syncing model plus built-in search and code-interpreter capabilities from official documentation."},"reason":{"zh":"v0.1.0 提供独立 LlmAdapter、图片输入、Responses SSE 映射和原子目录缓存；Release tag 绑定核实提交，CI 的语法、测试与打包检查通过，安装路径明确。适合已订阅千问 Token Plan 个人版、想在 DSH 使用服务端内置工具的人小范围试用。","en":"v0.1.0 ships a dedicated LlmAdapter, image input, Responses SSE mapping, and atomic catalog caching. The release tag resolves to the reviewed commit, and CI passes syntax, tests, and package checks with a clear install path. It is ready for limited trials by Qwen Token Plan Personal subscribers who want server-side tools in DSH."},"safety":{"risk":"medium","zh":"中风险：每次请求会把完整对话、所选图片、工具声明和工具结果发送到千问北京 Responses 端点，并可启用联网搜索、代码解释器和网页抓取；目录同步还会读取四份千问官方 Markdown，并把公开目录缓存到本机 0600 文件。静态审查未发现遥测、安装生命周期脚本或运行时 Shell，Key 逐请求从 DSH 凭据服务解析且不会写入缓存；端点和文档 URL 可配置，修改时必须防止把 Key 或内容转发到不可信地址。项目刚发布，维护历史很短，建议固定 v0.1.0 并先用非敏感会话。","en":"Medium risk: every request sends the full conversation, selected images, tool declarations, and tool outputs to the Qwen Beijing Responses endpoint and may enable web search, code interpreter, and page extraction. Catalog sync reads four official Qwen Markdown files and stores public metadata in a local mode-0600 cache. Static review found no telemetry, install lifecycle hook, or runtime shell execution; the key is resolved per request through DSH credentials and is not cached. Because endpoint and documentation URLs are configurable, changes must not redirect secrets or content to untrusted hosts. The project is newly released with a very short maintenance history, so pin v0.1.0 and start with non-sensitive sessions."}}},{"id":"omdsh-dev/dsh-llm-fallbacks","order":491,"name":"dsh-llm-fallbacks","owner":"omdsh-dev","repo":"omdsh-dev/dsh-llm-fallbacks","url":"https://github.com/omdsh-dev/dsh-llm-fallbacks","category":"dev","description":{"zh":"An dsh plugin for role-based LLM retry&fallback strategy. 基于角色的模型重试备用策略插件","en":"An dsh plugin for role-based LLM retry&fallback strategy. 基于角色的模型重试备用策略插件"},"added":"2026-08-14","curated":false,"topic":true,"stars":5,"forks":1,"openIssues":0,"watchers":5,"pushedAt":"2026-08-15T23:30:03Z","updatedAt":"2026-08-15T23:29:27Z","createdAt":"2026-08-07T16:53:10Z","license":"MIT","language":"TypeScript","homepage":null,"archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"dsh-llm-fallbacks","version":"0.1.6","lifecycleScripts":["prepare"],"runtimeDependencies":0,"declaredPaths":["bundle/cordis.patch.yml","dist/index.js","dist/client/index.js"],"invalidDeclaredPaths":[]},"screenedCommit":"e81a5622429a0d1866e67da7dbc7635e59b74bc8","installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-14","lastSeenAt":"2026-08-15T23:30:06.827Z"},"screening":{"version":1,"scope":"source","state":"review","risk":"medium","checkedAt":"2026-08-15T23:30:11.658Z","findings":[{"id":"lifecycle-script","severity":"medium","label":{"zh":"发现安装生命周期脚本：prepare","en":"Install lifecycle scripts found: prepare"},"files":["package.json"]},{"id":"lockfile-missing","severity":"medium","label":{"zh":"仓库根目录未发现依赖锁文件","en":"No root dependency lockfile found"},"files":[]}],"filesInspected":["package.json","bundle/cordis.patch.yml"],"checks":{"manifest":true,"license":true,"readme":true,"lockfile":false,"source":true,"securityDisclosure":true}},"attention":{"level":"review","reasons":["发现安装生命周期脚本：prepare","仓库根目录未发现依赖锁文件"]},"codexPick":{"repo":"omdsh-dev/dsh-llm-fallbacks","pickedAt":"2026-08-20T12:37:35.138Z","reviewedCommit":"b6c2bccd869999b0319d902c27a25680a3b384ab","category":"workflow","summary":{"zh":"在 LLM 重试耗尽、鉴权、额度或限流失败时，按角色和时段切换到备用 provider/model，让当前步骤继续运行；v0.3.2 补齐 dsh-tui 的可写 /settings 配置。","en":"Switches to backup provider/model routes by role and time slot after exhausted retries, auth, quota, or rate-limit failures so the current step can continue; v0.3.2 adds writable /settings parity for dsh-tui."},"reason":{"zh":"v0.3.2 的 npm 包带 provenance，gitHead 与已核实提交一致；CI 的测试和构建均通过，registry 包预构建 dist，只有一个运行时依赖。新版还支持模型 ID 中包含斜杠，并提供预置角色恢复命令。","en":"The v0.3.2 npm package carries provenance and its gitHead matches the verified commit; CI tests and build pass, the registry package ships prebuilt dist, and it has one runtime dependency. This release also accepts model IDs containing slashes and adds a seeded-role revert command."},"safety":{"risk":"medium","zh":"中风险：插件会拦截请求失败并把当前任务透明切换到另一家已配置模型服务，提示词和代码可能因此流向备用供应商；角色自动匹配还会发起一次受限模型判断，并且 Web/TUI 都能改写回退设置。运行时代码未发现直接网络请求、凭据读取、遥测或 Shell；仓库里的会话日志修复脚本不会由插件自动执行，必须显式使用 --apply --backup。建议只把可信供应商放进链，并限制自动切换范围。","en":"Medium risk: the plugin intercepts request failures and transparently reroutes the current task to another configured model service, so prompts and code may reach fallback providers; role auto-match can issue one bounded model judgment, and both Web and TUI can rewrite fallback settings. Runtime code contains no direct network call, credential read, telemetry, or shell execution. The repository repair script is not run by the plugin and requires explicit --apply --backup. Keep only trusted providers in chains and constrain automatic switching."}}},{"id":"goodandready/dsh-fal-image-gen","order":245,"name":"dsh-fal-image-gen","owner":"goodandready","repo":"goodandready/dsh-fal-image-gen","url":"https://github.com/goodandready/dsh-fal-image-gen","category":"fun","description":{"zh":"给 DSH 增加 generate_image 工具，支持 FAL 队列和 OpenAI 兼容图像 API；生成结果可在对话中显示，并保存到当前会话工作区。","en":"Adds a generate_image tool to DSH with support for the FAL queue and OpenAI-compatible image APIs; results render in the conversation and are saved in the active session workspace."},"added":"2026-08-20","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-20T10:36:04.694Z","lastSeenAt":"2026-08-20T10:36:04.694Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-20T10:36:04.694Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"goodandready/dsh-fal-image-gen","pickedAt":"2026-08-20T10:36:04.694Z","reviewedCommit":"af40a36842ba5a13de1e384ad5686fee720a10b5","category":"fun","summary":{"zh":"给 DSH 增加 generate_image 工具，支持 FAL 队列和 OpenAI 兼容图像 API；生成结果可在对话中显示，并保存到当前会话工作区。","en":"Adds a generate_image tool to DSH with support for the FAL queue and OpenAI-compatible image APIs; results render in the conversation and are saved in the active session workspace."},"reason":{"zh":"v0.5.1 的 npm 包绑定已核实的 Git 提交，没有运行时依赖和安装生命周期脚本；本地 12 项 provider 测试全部通过。v0.5.0 抽出了统一 provider 层，v0.5.1 修复设置卡片因 Host 注册竞态而长期缺失的问题。","en":"The v0.5.1 npm package is bound to the verified Git commit and has no runtime dependencies or install lifecycle hooks; all 12 provider tests passed locally. v0.5.0 introduced a shared provider layer, and v0.5.1 fixes a Host registration race that could leave the settings card missing."},"safety":{"risk":"medium","zh":"中风险：提示词和 API 凭据会发送给用户选择的 FAL 或自定义端点，插件还会下载 provider 返回的图片 URL，并把结果写入会话工作区或用户配置的绝对目录。静态检查未发现 Shell 执行、遥测、额外运行时依赖或安装脚本；建议只使用可信端点、保持 Web UI 监听在本机，并保留相对 outputDir。","en":"Medium risk: prompts and API credentials are sent to the selected FAL or custom endpoint, the plugin downloads image URLs returned by that provider, and it writes results to the session workspace or a user-configured absolute directory. Static review found no shell execution, telemetry, extra runtime dependencies, or install hooks; use trusted endpoints, keep the Web UI on loopback, and retain a relative outputDir."}}},{"id":"totoro-qaq/dsh-plugin-bridge","order":246,"name":"dsh-plugin-bridge","owner":"totoro-qaq","repo":"totoro-qaq/dsh-plugin-bridge","url":"https://github.com/totoro-qaq/dsh-plugin-bridge","category":"workflow","description":{"zh":"把已有内容的 DSH 会话通过可预览、可编辑的固定五段交接摘要迁到另一套 Agent Preset，原会话保持不动；v0.2.3 支持单轮复述并继续工作。","en":"Migrates a non-empty DSH session to another Agent Preset through a previewable, editable five-section handoff while leaving the source session untouched; v0.2.3 can restate and continue in one target turn."},"added":"2026-08-20","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-20T08:34:02.981Z","lastSeenAt":"2026-08-20T08:34:02.981Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-20T08:34:02.981Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"totoro-qaq/dsh-plugin-bridge","pickedAt":"2026-08-20T08:34:02.981Z","reviewedCommit":"34777d9b532404b016831577d729fe23973c633d","category":"workflow","summary":{"zh":"把已有内容的 DSH 会话通过可预览、可编辑的固定五段交接摘要迁到另一套 Agent Preset，原会话保持不动；v0.2.3 支持单轮复述并继续工作。","en":"Migrates a non-empty DSH session to another Agent Preset through a previewable, editable five-section handoff while leaving the source session untouched; v0.2.3 can restate and continue in one target turn."},"reason":{"zh":"安装路径绑定 Git tag，仓库提交预构建 lib，无安装脚本；Node 22/24 的 111 项测试、包内容检查和 CodeQL 均通过。默认先预览，目标 goal 在 kickoff 前暂停，暂停失败会停止自动启动。","en":"The Git-tag install carries committed prebuilt lib files and no install lifecycle hook; 111 tests on Node 22/24, package checks, and CodeQL pass. Preview is the default, the target goal is paused before kickoff, and pause failure cancels automatic startup."},"safety":{"risk":"medium","zh":"中风险：插件会读取源会话历史并交给当前配置的工作模型生成摘要，敏感内容会进入该模型供应商；它还能创建和重命名会话、创建及暂停 goal、归档临时工人，并在系统临时目录写入可编辑摘要。静态检查未发现 Shell 执行、遥测、独立外联服务或凭据读取；建议先预览，敏感会话使用可信模型端点。","en":"Medium risk: the plugin reads source-session history and sends it to the configured worker model for summarization, so sensitive content reaches that model provider. It can also create and rename sessions, create and pause goals, archive temporary workers, and write editable summaries under the OS temp directory. Static review found no shell execution, telemetry, independent remote service, or credential access; preview first and use a trusted model endpoint for sensitive sessions."}}},{"id":"sirilee/dsh-edit-approval","order":261,"name":"dsh-edit-approval","owner":"sirilee","repo":"sirilee/dsh-edit-approval","url":"https://github.com/sirilee/dsh-edit-approval","category":"tools","description":{"zh":"在 Agent 写文件前展示红绿行级 diff，让用户逐次批准或拒绝 write、edit 与 str_replace_editor；v0.2.1 新增长 diff 折叠。","en":"Shows a red and green line-level diff before agent file edits, allowing per-call approval or rejection for write, edit, and str_replace_editor; v0.2.1 adds collapsible long diffs."},"added":"2026-08-19","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-19T08:31:35.214Z","lastSeenAt":"2026-08-19T08:31:35.214Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-19T08:31:35.214Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"sirilee/dsh-edit-approval","pickedAt":"2026-08-19T08:31:35.214Z","reviewedCommit":"d50ae758f415986437748abb22afdfb15f4470b0","category":"tools","summary":{"zh":"在 Agent 写文件前展示红绿行级 diff，让用户逐次批准或拒绝 write、edit 与 str_replace_editor；v0.2.1 新增长 diff 折叠。","en":"Shows a red and green line-level diff before agent file edits, allowing per-call approval or rejection for write, edit, and str_replace_editor; v0.2.1 adds collapsible long diffs."},"reason":{"zh":"它把文件修改审批放在真正落盘前，直接补足 Web 工作流的安全感。v0.2.1 已发布至 npm，包带 OIDC/SLSA provenance，发布校验通过；源码包含 54 项测试，折叠功能另有 jsdom 测试。","en":"It places file-edit approval before disk writes, adding a useful safety gate to the Web workflow. v0.2.1 is published on npm with OIDC/SLSA provenance and passing release checks; the source includes 54 tests plus dedicated jsdom coverage for collapse behavior."},"safety":{"risk":"medium","zh":"中风险：插件会读取目标文件内容、重建拟写入结果并拦截写工具，因此可见工作区代码，也可能因误判阻塞编辑。静态审查未发现网络外发、遥测、Shell 或凭据访问；bash/pwsh 内的文件修改不受保护。registry 安装使用预构建包，GitHub 源码安装会触发 prepare 构建并需显式放行。","en":"Medium risk: the plugin reads target files, reconstructs proposed content, and intercepts write tools, so it can see workspace code and may block edits on false positives. Static review found no network egress, telemetry, shell execution, or credential access; file changes inside bash or pwsh are not covered. Registry installs use the prebuilt package, while GitHub source installs trigger the prepare build and require explicit approval."}}},{"id":"toolclub/dsh-agent-team-gui","order":361,"name":"dsh-agent-team-gui","owner":"toolclub","repo":"toolclub/dsh-agent-team-gui","url":"https://github.com/toolclub/dsh-agent-team-gui","category":"workflow","description":{"zh":"DeepSeek Harness multi-agent squad GUI with per-agent provider/model routes, tool policies, and serial/parallel spawn/fork/chain orchestration.","en":"DeepSeek Harness multi-agent squad GUI with per-agent provider/model routes, tool policies, and serial/parallel spawn/fork/chain orchestration."},"added":"2026-08-15","curated":false,"topic":true,"stars":1,"forks":0,"openIssues":0,"watchers":1,"pushedAt":"2026-08-15T06:29:30Z","updatedAt":"2026-08-15T06:29:39Z","createdAt":"2026-08-15T03:40:19Z","license":"MIT","language":"TypeScript","homepage":"https://github.com/toolclub/agent_team_gui#readme","archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"dsh-agent-team-gui","version":"0.1.0","lifecycleScripts":["prepare"],"runtimeDependencies":2,"declaredPaths":["cordis.patch.yml","lib/index.js","lib/client.js"],"invalidDeclaredPaths":[]},"screenedCommit":"bd1b779fee002e5b3b0babed0200749fb9133acf","installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-15","lastSeenAt":"2026-08-15T06:30:06.827Z"},"screening":{"version":1,"scope":"source","state":"review","risk":"medium","checkedAt":"2026-08-15T06:30:14.647Z","findings":[{"id":"lifecycle-script","severity":"medium","label":{"zh":"发现安装生命周期脚本：prepare","en":"Install lifecycle scripts found: prepare"},"files":["package.json"]},{"id":"lockfile-missing","severity":"medium","label":{"zh":"仓库根目录未发现依赖锁文件","en":"No root dependency lockfile found"},"files":[]}],"filesInspected":["package.json","cordis.patch.yml"],"checks":{"manifest":true,"license":true,"readme":true,"lockfile":false,"source":true,"securityDisclosure":true}},"attention":{"level":"review","reasons":["发现安装生命周期脚本：prepare","仓库根目录未发现依赖锁文件"]},"codexPick":{"repo":"toolclub/dsh-agent-team-gui","pickedAt":"2026-08-19T04:28:13.605Z","reviewedCommit":"3b56aa4dbe20cc128d710928d20c80404ec7fff6","category":"workflow","summary":{"zh":"在 DSH Web 中编排可持久化的多模型 Agent 团队，支持 DAG、并发、质量审查、后台运行和 Token 统计。","en":"Orchestrate persistent multi-model agent teams in DSH Web with DAGs, concurrency, quality review, background runs, and token metering."},"reason":{"zh":"v1.0.0 已具备按成员限制工具、Token 预算、崩溃恢复、质量修复循环和结构化复盘；发布 CI 验证了固定 Git revision 安装、浏览器冒烟测试及 Node 22/24。","en":"v1.0.0 combines per-member tool restrictions, token budgets, crash recovery, quality repair loops, and structured retrospectives; release CI validates pinned Git installation, browser smoke, and Node 22/24."},"safety":{"risk":"medium","zh":"插件不保存 provider 凭据，团队定义、任务、输出、错误和用量会写入本地 DSH 存储。成员可执行其获准的 DSH 工具，多模型并发可能增加费用；Git 安装会运行已审查的 prepare 构建，建议固定 v1.0.0 或完整 SHA，并只授权本包的 allowBuilds。","en":"The plugin does not store provider credentials; team definitions, tasks, outputs, errors, and usage are persisted in local DSH storage. Members can execute their allowed DSH tools and concurrent models can increase cost. Git installation runs the reviewed prepare build, so pin v1.0.0 or a full SHA and authorize allowBuilds only for this package."}}},{"id":"cc19990113/dsh-plugin-codegraph","order":271,"name":"dsh-plugin-codegraph","owner":"cc19990113","repo":"cc19990113/dsh-plugin-codegraph","url":"https://github.com/cc19990113/dsh-plugin-codegraph","category":"tools","description":{"zh":"用本地 Tree-sitter 代码图给 DSH Agent 提供声明、调用者、影响范围、调用路径和任务上下文查询，并支持自动刷新索引。","en":"Adds a local Tree-sitter code graph to DSH for declaration, caller, impact, trace, and task-context queries, with automatic index refresh."},"added":"2026-08-18","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-18T06:08:30.452Z","lastSeenAt":"2026-08-18T06:08:30.452Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-18T06:08:30.452Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"cc19990113/dsh-plugin-codegraph","pickedAt":"2026-08-18T06:08:30.452Z","reviewedCommit":"213651b48be765936ead1ef706cd4b6cfb1ad9b2","category":"tools","summary":{"zh":"用本地 Tree-sitter 代码图给 DSH Agent 提供声明、调用者、影响范围、调用路径和任务上下文查询，并支持自动刷新索引。","en":"Adds a local Tree-sitter code graph to DSH for declaration, caller, impact, trace, and task-context queries, with automatic index refresh."},"reason":{"zh":"v0.1.1 已发布 GitHub Release 与五个 npm 包，修复监听自身数据库导致的无限重建及 macOS/Windows 忽略 .gitignore，并将文件监听设为默认开启。发布提交绑定完整 SHA，类型检查、覆盖率测试、构建和发布 CI 均通过；运行包无生命周期脚本，索引格式兼容 codegraph CLI。","en":"v0.1.1 is published as a GitHub Release and five npm packages. It fixes self-triggered rebuild loops and ignored .gitignore rules on macOS and Windows, then enables watching by default. The release is pinned to the reviewed SHA; typecheck, coverage tests, build, and publish CI pass. Runtime packages have no lifecycle scripts and use the codegraph CLI-compatible index format."},"safety":{"risk":"medium","zh":"中风险：索引器会递归读取工作区源码，在项目中写入 .codegraph/codegraph.db，并默认常驻监听文件变化后全量重建；查询工具还可通过宿主 fs 读取相关源码片段。未发现网络外发、遥测或自动 Shell；Git 探测和 Hook 安装仅作为库 API 导出，插件加载时不会调用。项目和发布都很新，大仓库建议先关闭 watch 或限制 languages、exclude 与 maxFiles。","en":"Medium risk: the indexer recursively reads workspace source, writes .codegraph/codegraph.db, and by default keeps a watcher that performs full rebuilds after changes; query tools can also read relevant source snippets through the host fs service. No network egress, telemetry, or automatic shell execution was found. Git probing and hook installation are exported library APIs and are not invoked at plugin load. The project and release are very new; on large repositories, disable watch or constrain languages, exclude, and maxFiles."}}},{"id":"mars-sea/dsh-commandcode-provider","order":272,"name":"dsh-commandcode-provider","owner":"mars-sea","repo":"mars-sea/dsh-commandcode-provider","url":"https://github.com/mars-sea/dsh-commandcode-provider","category":"tools","description":{"zh":"把 Command Code 的实时模型目录接入 DSH，支持套餐过滤、推理强度、图片输入与账户用量面板；v0.4.1 已同步 GPT-5.6 Sol。","en":"Connects the live Command Code model catalog to DSH with plan filtering, reasoning effort, image input, and account usage; v0.4.1 adds GPT-5.6 Sol support."},"added":"2026-08-18","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-18T02:06:21.906Z","lastSeenAt":"2026-08-18T02:06:21.906Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-18T02:06:21.906Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"mars-sea/dsh-commandcode-provider","pickedAt":"2026-08-18T02:06:21.906Z","reviewedCommit":"1c55773f678ba9ea6604932b646a060c696e7dce","category":"tools","summary":{"zh":"把 Command Code 的实时模型目录接入 DSH，支持套餐过滤、推理强度、图片输入与账户用量面板；v0.4.1 已同步 GPT-5.6 Sol。","en":"Connects the live Command Code model catalog to DSH with plan filtering, reasoning effort, image input, and account usage; v0.4.1 adds GPT-5.6 Sol support."},"reason":{"zh":"v0.4.1 已发布到 npm 和 GitHub Release，绑定同一提交；同步官方 command-code@1.27.1，将 GPT-5.6 Sol 正确归入 GOAT 套餐。插件无运行时依赖，CI、类型检查、测试、构建、npm audit、CodeQL 与 gitleaks 均通过。","en":"v0.4.1 is published on npm and as a GitHub Release at the reviewed commit. It syncs command-code@1.27.1 and correctly exposes GPT-5.6 Sol to GOAT plans. The plugin has no runtime dependencies, and CI, typecheck, tests, build, npm audit, CodeQL, and gitleaks all pass."},"safety":{"risk":"medium","zh":"中风险：生成请求会把消息、系统提示、工具定义、图片、工作目录及运行环境元数据发送到 api.commandcode.ai，并用 API key 查询账户和账单接口；还会读取 ~/.commandcode/auth.json 作为凭据回退并写模型缓存。默认无遥测和 Shell 执行，建议只处理可发送给 Command Code 的项目数据，并固定 0.4.1。","en":"Medium risk: generation sends messages, system prompts, tool schemas, images, working-directory and runtime metadata to api.commandcode.ai, and uses the API key for account and billing calls. It also reads ~/.commandcode/auth.json as a credential fallback and writes a model cache. There is no default telemetry or shell execution; only use it with project data acceptable for Command Code and pin 0.4.1."}}},{"id":"nwflower/dsh-chat-import","order":51,"name":"dsh-chat-import","owner":"Nwflower","repo":"Nwflower/dsh-chat-import","url":"https://github.com/Nwflower/dsh-chat-import","category":"session","description":{"en":"Import Claude Code / Codex / ChatGPT / Cursor / Gemini / Reasonix / opencode chat histories as resumable DeepSeek Harness sessions.","zh":"把 Claude Code / Codex / ChatGPT / Cursor / Gemini / Reasonix / opencode 的聊天记录全保真导入为可续聊的 DSH 会话。"},"added":"2026-08-13","curated":true,"topic":true,"stars":14,"forks":2,"openIssues":1,"watchers":14,"pushedAt":"2026-08-14T07:02:55Z","updatedAt":"2026-08-14T07:54:38Z","createdAt":"2026-08-13T14:21:58Z","license":"MIT","language":"JavaScript","homepage":null,"archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle"],"packageName":"dsh-chat-import","version":"0.2.0","lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":["cordis.patch.yml","index.mjs"],"invalidDeclaredPaths":[]},"installCommand":null,"discovery":{"source":"curated","firstSeenAt":"2026-08-13","lastSeenAt":"2026-08-14T08:18:12.622Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-14T08:18:12.622Z","findings":[],"filesInspected":["package.json"],"checks":{"manifest":true,"license":true,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"clear","reasons":[]},"screenedCommit":null,"codexPick":{"repo":"nwflower/dsh-chat-import","pickedAt":"2026-08-17T10:16:37.463Z","reviewedCommit":"f2a1abfde467596821c7e73b53e1124e2ec77f32","category":"session","summary":{"zh":"把 Claude Code、Codex、ChatGPT、Cursor、Gemini、Qoder 等 15 类 Agent 会话导入 DSH 继续对话，并支持导出、增量同步和跨机器 bundle。","en":"Imports histories from 15 agent ecosystems including Claude Code, Codex, ChatGPT, Cursor, Gemini, and Qoder into resumable DSH sessions, with export, incremental sync, and portable bundles."},"reason":{"zh":"v0.6.0 新增 Qoder CLI、Codex 资产迁移、doctor、MCP 镜像建议和哈希校验；发布包移除运行时 child_process，只有 fzstd 一个依赖。GitHub Release 与 npm 包内容一致，526 项测试和真实 DSH headless 冒烟 CI 通过。","en":"v0.6.0 adds Qoder CLI, Codex asset migration, doctor checks, MCP mirroring suggestions, and hash validation. The package removes runtime child_process and has one dependency, fzstd. GitHub Release and npm package contents match, with 526 tests and a real DSH headless smoke check passing in CI."},"safety":{"risk":"medium","zh":"中风险：会读取本机多种 Agent 历史并把内容写入 DSH，会话可能含密钥；导出和同步还能写回 Claude、Codex、Grok 路径，双向同步默认关闭。运行包无 install、postinstall、外部网络、遥测或 Shell，Web 路由自身未做认证或同源校验。建议仅在环回地址使用，先 preview 或 dry-run，备份源会话后再开启写回。","en":"Medium risk: it reads local histories from multiple agents and writes them into DSH, where transcripts may contain secrets; export and sync can also write back to Claude, Codex, and Grok paths, while bidirectional sync is off by default. The runtime package has no install or postinstall hook, external network egress, telemetry, or shell execution, but its Web routes add no authentication or same-origin check. Keep DSH on loopback, preview first, and back up source sessions before enabling write-back."}}},{"id":"ysr666/dsh-vision-router","order":529,"name":"dsh-vision-router","owner":"ysr666","repo":"ysr666/dsh-vision-router","url":"https://github.com/ysr666/dsh-vision-router","category":"workflow","description":{"zh":"Eyes for text-only DeepSeek Harness agents: built-in free vision chain (no key) + pixel-level vision tools (Q&A, grounding, crop, pixel diff, colors, OCR, SVG trace, cutout, screenshots). One-command install, no Python, image turns work like ordinary tool-calling turns.","en":"Eyes for text-only DeepSeek Harness agents: built-in free vision chain (no key) + pixel-level vision tools (Q&A, grounding, crop, pixel diff, colors, OCR, SVG trace, cutout, screenshots). One-command install, no Python, image turns work like ordinary tool-calling turns."},"added":"2026-08-14","curated":false,"topic":true,"stars":283,"forks":16,"openIssues":3,"watchers":283,"pushedAt":"2026-08-16T10:00:49Z","updatedAt":"2026-08-16T10:00:50Z","createdAt":"2026-08-13T18:57:47Z","license":"MIT","language":"JavaScript","homepage":"https://github.com/ysr666/dsh-vision-router","archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"dsh-vision-router","version":"1.3.0","lifecycleScripts":[],"runtimeDependencies":4,"declaredPaths":["cordis.patch.yml","entry.js","lib/client.js"],"invalidDeclaredPaths":[]},"screenedCommit":"5ad9556e8630555944e1f47106e0ee97cba1ffc1","installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-14","lastSeenAt":"2026-08-16T10:01:11.592Z"},"screening":{"version":1,"scope":"source","state":"review","risk":"medium","checkedAt":"2026-08-16T10:01:11.592Z","findings":[{"id":"inspection-incomplete","severity":"medium","label":{"zh":"部分公开文件超过静态检查读取上限，需人工复核","en":"Some public files exceeded the static inspection limit and need manual review"},"files":["lib/client.js"]}],"filesInspected":["package.json","entry.js","cordis.patch.yml"],"checks":{"manifest":true,"license":true,"readme":true,"lockfile":true,"source":true,"securityDisclosure":true}},"attention":{"level":"review","reasons":["部分公开文件超过静态检查读取上限，需人工复核"]},"passport":{"evidenceId":"ysr666/dsh-vision-router@5ad9556e8630555944e1f47106e0ee97cba1ffc1#scan-2","versionCount":1,"latestCommit":"5ad9556e8630555944e1f47106e0ee97cba1ffc1","latestCheckedAt":"2026-08-16T10:01:11.592Z","diffSeverity":"baseline","verificationScore":7,"verificationPossible":7},"codexPick":{"repo":"ysr666/dsh-vision-router","pickedAt":"2026-08-17T07:16:06.689Z","reviewedCommit":"511aacce61c737f443a8bc8786c71e3cc8607750","category":"tools","summary":{"zh":"让纯文本 DSH Agent 通过视觉模型链与 11 个像素级工具完成图片问答、定位、OCR、裁剪和像素对比；v1.4.5 新增默认关闭的 1+x 结构化预识别。","en":"Gives text-only DSH agents a vision-model chain and 11 pixel-level tools for image Q&A, grounding, OCR, crop, and pixel diff; v1.4.5 adds an opt-in structured 1+x pre-scan."},"reason":{"zh":"默认免 Key、无 Python；图片轮由主模型按需调用工具。v1.4.5 已发布到 npm，核对的包内关键文件与 Release tag 一致，Node 22/24 与三平台 CI 均通过。","en":"Keyless and Python-free by default, with the main model invoking vision tools on demand. v1.4.5 is published on npm, reviewed package files match the release tag, and Node 22/24 plus three-platform CI pass."},"safety":{"risk":"medium","zh":"识图会把图片与提示发送至默认 OVHcloud 匿名端点，也可改用自有端点；插件可读取宿主 fs 允许的图片、在工作区写 artifacts，并在 ~/.dsh 写脱敏轮转日志。无 install/prepare 脚本；发布提交未签名、npm 无 provenance，依赖审计还有 1 个 potrace→jimp→phin 中风险。敏感图片建议使用私有端点。","en":"Vision sends images and prompts to the default anonymous OVHcloud endpoint unless a private endpoint is configured; the plugin can read images allowed by the host fs, write workspace artifacts, and keep redacted rotating logs under ~/.dsh. It has no install/prepare script; the release commit is unsigned, npm lacks provenance, and audit reports one moderate potrace-to-jimp-to-phin issue. Use a private endpoint for sensitive images."}}},{"id":"dsh-market/dsh-market","order":96,"name":"dsh-market","owner":"dsh-market","repo":"dsh-market/dsh-market","url":"https://github.com/dsh-market/dsh-market","category":"tools","description":{"en":"The plugin market inside DSH: a Settings page to browse and search the full community catalog by category, with confirmed one-click installs and an installed-plugins view.","zh":"装在 DSH 里的插件市场：设置页内逛/搜全部社区插件，按分类筛选，确认后一键安装，已装插件一目了然。"},"added":"2026-08-14","curated":true,"topic":true,"stars":43,"forks":7,"openIssues":10,"watchers":43,"pushedAt":"2026-08-14T17:59:35Z","updatedAt":"2026-08-14T17:59:42Z","createdAt":"2026-08-14T04:58:15Z","license":null,"language":"TypeScript","homepage":"https://dshmarket.com","archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"dshmarket","version":"1.2.1","lifecycleScripts":["prepare"],"runtimeDependencies":0,"declaredPaths":["cordis.patch.yml","lib/index.js","client/client.js"],"invalidDeclaredPaths":[]},"installCommand":null,"discovery":{"source":"curated","firstSeenAt":"2026-08-14","lastSeenAt":"2026-08-14T18:00:45.438Z"},"screening":{"version":1,"scope":"source","state":"review","risk":"medium","checkedAt":"2026-08-14T18:00:52.457Z","findings":[{"id":"license-missing","severity":"medium","label":{"zh":"仓库未声明可识别许可证","en":"No recognized repository license"},"files":[]},{"id":"lifecycle-script","severity":"medium","label":{"zh":"发现安装生命周期脚本：prepare","en":"Install lifecycle scripts found: prepare"},"files":["package.json"]},{"id":"lockfile-missing","severity":"medium","label":{"zh":"仓库根目录未发现依赖锁文件","en":"No root dependency lockfile found"},"files":[]},{"id":"network-egress","severity":"medium","label":{"zh":"发现主动网络请求能力","en":"Outbound network capability signal found"},"files":["client/client.js"]},{"id":"html-execution","severity":"medium","label":{"zh":"发现 HTML 或 SVG 主动内容处理能力","en":"Active HTML or SVG handling signal found"},"files":["client/client.js"]}],"filesInspected":["package.json","client/client.js","cordis.patch.yml"],"checks":{"manifest":true,"license":false,"readme":true,"lockfile":false,"source":true,"securityDisclosure":true}},"attention":{"level":"review","reasons":["仓库未声明可识别许可证","发现安装生命周期脚本：prepare","仓库根目录未发现依赖锁文件","发现主动网络请求能力","发现 HTML 或 SVG 主动内容处理能力"]},"screenedCommit":null,"codexPick":{"repo":"dsh-market/dsh-market","pickedAt":"2026-08-17T04:13:05.964Z","reviewedCommit":"805d1a716aaa3ea09d111b150645fd88b3e8b51d","category":"tools","summary":{"zh":"在 DeepSeek Harness 设置页内浏览、安装、更新、启停和备份插件；v1.11.0 新增加载层诊断与持久化热启停。","en":"Browse, install, update, toggle, and back up plugins inside DeepSeek Harness Settings; v1.11.0 adds loading-layer diagnostics and persistent hot toggles."},"reason":{"zh":"新版让插件实际加载状态更透明：以 loader inventory 为准，检查错误的宿主共享依赖，并通过官方 user patch 层热启停；npm 包带 provenance，Ubuntu、Windows、Web E2E 和 pnpm 兼容 CI 全部通过。","en":"The release makes real plugin state more transparent by prioritizing loader inventory, diagnosing misplaced shared host dependencies, and toggling through the official user patch layer; the npm package has provenance and its Ubuntu, Windows, Web E2E, and pnpm compatibility CI all pass."},"safety":{"risk":"medium","zh":"中风险：它是插件控制面，可调用 dsh/pnpm 安装、更新和卸载，改写 Profile user patch，配置 pnpm，重启 DSH，并导出、恢复或经 WebDAV 上传可能含凭据的 Profile 备份。安装源限于精选注册表，构建脚本默认拦截并需显式放行；变更接口校验同源，重启和备份下载进一步限制为环回请求，日志会脱敏。上传备份前仍应人工检查内容与目标。","en":"Medium risk: this is a plugin control plane that can invoke dsh/pnpm installs, updates, and removals, edit the Profile user patch, provision pnpm, restart DSH, and export, restore, or upload Profile backups that may contain credentials. Sources are limited to the curated registry, build scripts are blocked by default until explicitly approved, mutating routes enforce same origin, restart and backup downloads are loopback-restricted, and logs are redacted. Review backup contents and destination before WebDAV upload."}}},{"id":"ccch1mneyyy/dsh-tui","order":29,"name":"dsh-TUI","owner":"ccch1mneyyy","repo":"ccch1mneyyy/dsh-TUI","url":"https://github.com/ccch1mneyyy/dsh-TUI","category":"ui","description":{"en":"Claude Code-style full-screen terminal UI: pixel-whale header, live status line, and streaming thought expansion.","zh":"Claude Code 风格全屏终端 UI：像素鲸鱼顶栏、实时工作状态行、思考流式展开。"},"added":"2026-08-14","curated":true,"topic":true,"stars":1440,"forks":59,"openIssues":43,"watchers":1440,"pushedAt":"2026-08-16T11:59:26Z","updatedAt":"2026-08-16T11:59:07Z","createdAt":"2026-08-13T12:49:31Z","license":"MIT","language":"TypeScript","homepage":"https://dshtui.com/","archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle"],"packageName":"@deepseek-harness-tui/dsh-tui","version":"0.7.2","lifecycleScripts":["prepare"],"runtimeDependencies":48,"declaredPaths":["cordis.patch.yml","lib/types/index.js"],"invalidDeclaredPaths":[]},"screenedCommit":"f7300836647093ef447a6850e10f5443a9d4c3c2","installCommand":"dsh plugin --profile web add github:ccch1mneyyy/dsh-TUI#f7300836647093ef447a6850e10f5443a9d4c3c2","discovery":{"source":"curated","firstSeenAt":"2026-08-14","lastSeenAt":"2026-08-16T12:01:15.314Z"},"screening":{"version":1,"scope":"source","state":"review","risk":"medium","checkedAt":"2026-08-16T12:01:15.314Z","findings":[{"id":"lifecycle-script","severity":"medium","label":{"zh":"发现安装生命周期脚本：prepare","en":"Install lifecycle scripts found: prepare"},"files":["package.json"]},{"id":"credential-access","severity":"medium","label":{"zh":"发现环境变量、密钥或凭据访问线索","en":"Environment, secret, or credential access signal found"},"files":["cordis.patch.yml"]},{"id":"telemetry","severity":"medium","label":{"zh":"发现遥测或分析服务线索","en":"Telemetry or analytics signal found"},"files":["cordis.patch.yml"]}],"filesInspected":["package.json","cordis.patch.yml","src/index.ts"],"checks":{"manifest":true,"license":true,"readme":true,"lockfile":true,"source":true,"securityDisclosure":true}},"attention":{"level":"review","reasons":["发现安装生命周期脚本：prepare","发现环境变量、密钥或凭据访问线索","发现遥测或分析服务线索"]},"passport":{"evidenceId":"ccch1mneyyy/dsh-tui@f7300836647093ef447a6850e10f5443a9d4c3c2#scan-2","versionCount":2,"latestCommit":"f7300836647093ef447a6850e10f5443a9d4c3c2","latestCheckedAt":"2026-08-16T12:01:15.314Z","diffSeverity":"low","verificationScore":7,"verificationPossible":7},"codexPick":{"repo":"ccch1mneyyy/dsh-tui","pickedAt":"2026-08-17T02:10:05.381Z","reviewedCommit":"9ac578f1db308214ced63ecc0b5d7cd19bbe8ffa","category":"ui","summary":{"zh":"为 DeepSeek Harness 提供成熟的终端界面，覆盖流式对话、会话恢复、工具审批、上下文指标和双栏 diff。","en":"A mature terminal interface for DeepSeek Harness with streaming chat, session resume, tool approvals, context metrics, and split diffs."},"reason":{"zh":"v0.8.0 新增宽屏双栏 diff、词级与语法高亮、可切换 diff 布局和插件设置屏；发布提交已签名，构建与 npm 发布 CI 通过。","en":"v0.8.0 adds wide-terminal split diffs, word and syntax highlighting, selectable diff layouts, and a plugin settings screen; the release commit is signed and its build and npm publish CI passed."},"safety":{"risk":"medium","zh":"中风险：它作为完整 TUI 读取共享会话与工作区、调用系统剪贴板工具，并可通过 /update 修改 dsh-tui Profile；运行时仅额外访问配置的 npm registry 检查更新，未发现独立遥测。macOS/Linux 默认 workspace-write + ask；Windows 默认 danger-full-access + never，Windows 用户应先收紧 Profile。","en":"Medium risk: as a full TUI it reads shared sessions and workspace state, invokes OS clipboard helpers, and can update the dsh-tui Profile through /update; the only additional runtime network access found is update checks against the configured npm registry, with no independent telemetry found. macOS/Linux default to workspace-write + ask, while Windows defaults to danger-full-access + never and should be tightened before use."}}},{"id":"anionex/dsh-vision-toolkit","order":68,"name":"dsh-vision-toolkit","owner":"Anionex","repo":"Anionex/dsh-vision-toolkit","url":"https://github.com/Anionex/dsh-vision-toolkit","category":"tools","description":{"en":"Vision tasks for text-only models: intent-aware image Q&A, long-screenshot OCR, UI reproduction, grounding, and pixel diff.","zh":"让纯文本模型更好地做视觉任务：带意图的图片问答、长截图 OCR、UI 还原等。"},"added":"2026-08-13","curated":true,"topic":true,"stars":267,"forks":17,"openIssues":3,"watchers":267,"pushedAt":"2026-08-14T07:14:24Z","updatedAt":"2026-08-14T08:13:46Z","createdAt":"2026-08-13T12:36:34Z","license":"MIT","language":"TypeScript","homepage":null,"archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"@dsh-external/dsh-vision-toolkit","version":"0.1.2","lifecycleScripts":[],"runtimeDependencies":1,"declaredPaths":["cordis.patch.yml","lib/index.js","lib/client.js"],"invalidDeclaredPaths":[]},"installCommand":null,"discovery":{"source":"curated","firstSeenAt":"2026-08-13","lastSeenAt":"2026-08-14T08:18:12.622Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-14T08:18:12.622Z","findings":[],"filesInspected":["package.json"],"checks":{"manifest":true,"license":true,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"clear","reasons":[]},"screenedCommit":null,"codexPick":{"repo":"anionex/dsh-vision-toolkit","pickedAt":"2026-08-16T21:59:08.679Z","reviewedCommit":"e50bb8d9da6022e993a1b00859d22afdc5621a7e","category":"tools","summary":{"zh":"为纯文本 DSH 模型补充图片问答、长图 OCR、目标定位、UI 还原和像素对比等视觉工作流。","en":"Adds image Q&A, long-screenshot OCR, grounding, UI restoration, and pixel-diff workflows to text-only DSH models."},"reason":{"zh":"Web 可直接粘贴图片并自动切换视觉变体，十个工具覆盖远程理解与本地处理；发布绑定源码、固定上游快照，并通过 Node 22/24、Worker 与 Profile 验收 CI。","en":"Supports direct image paste with automatic vision variants and ten remote/local tools; releases pin source and upstream snapshots and pass Node 22/24, Worker, and Profile acceptance CI."},"safety":{"risk":"medium","zh":"在线理解会把所选图片和任务提示发送至 vision.anionex.me，再转发给 Groq；首次运行会创建 Python 环境并安装固定版本依赖，确认更新时可调用 pnpm 修改当前 Profile。包无安装生命周期脚本，本地裁剪、描摹和像素对比不上传。敏感图片建议改用自有视觉端点。","en":"Remote understanding sends selected image bytes and task prompts to vision.anionex.me, which forwards them to Groq; first run creates a Python environment with pinned dependencies, and confirmed updates may invoke pnpm against the current Profile. The package has no install lifecycle scripts, while local crop, trace, and pixel diff stay on-device. Use a private vision endpoint for sensitive images."}}},{"id":"bowenliang123/dsh-context","order":292,"name":"dsh-context","owner":"bowenliang123","repo":"bowenliang123/dsh-context","url":"https://github.com/bowenliang123/dsh-context","category":"session","description":{"zh":"把会话上下文组成、消耗趋势、压缩与裁剪事件做成可视面板，并新增纯前端 /context 弹窗。","en":"Visualizes session context composition, usage trends, compaction and pruning events, with a client-only /context modal."},"added":"2026-08-16","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-16T15:47:47.350Z","lastSeenAt":"2026-08-16T15:47:47.350Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-16T15:47:47.350Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"bowenliang123/dsh-context","pickedAt":"2026-08-16T15:47:47.350Z","reviewedCommit":"1c6fe29021f0c126c1cb529c02e311ba24f038d4","category":"session","summary":{"zh":"把会话上下文组成、消耗趋势、压缩与裁剪事件做成可视面板，并新增纯前端 /context 弹窗。","en":"Visualizes session context composition, usage trends, compaction and pruning events, with a client-only /context modal."},"reason":{"zh":"v0.10.0 的 Git 标签、npm 包与 OIDC 构建来源均绑定同一提交；宿主侧采用纯会话投影，没有自定义 RPC、网络请求或额外持久化，源码和测试完整。","en":"The v0.10.0 Git tag, npm package and OIDC provenance resolve to the same commit. Its host side is a pure session projection with no custom RPC, network request or extra persistence, backed by complete source and tests."},"safety":{"risk":"medium","zh":"中风险：会读取并在本地 Web UI 展示模型可见消息、系统提示和工具结构，可能含敏感内容；静态审查未发现网络外发、Shell、文件写入、遥测或凭据访问。package.json 声明了 Husky prepare 脚本，但没有 install/postinstall；npm 包带 SLSA provenance。建议仅在可信界面使用。","en":"Medium risk: it reads and renders model-visible messages, system-prompt metrics and tool schemas in the local Web UI, which may contain sensitive material. Static review found no network egress, shell execution, file writes, telemetry or credential access. package.json declares a Husky prepare script but no install/postinstall, and the npm package carries SLSA provenance. Use only on a trusted UI."}}},{"id":"ayahunter/dsh-plugin-clinic","order":293,"name":"dsh-plugin-clinic","owner":"ayahunter","repo":"ayahunter/dsh-plugin-clinic","url":"https://github.com/ayahunter/dsh-plugin-clinic","category":"dev","description":{"zh":"只读体检已安装的 DSH 插件，检查加载、依赖、兼容性、安装脚本和 patch 完整性。","en":"Read-only health checks for installed DSH plugins, covering loading, dependencies, compatibility, install scripts, and patch integrity."},"added":"2026-08-16","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-16T13:40:36.283Z","lastSeenAt":"2026-08-16T13:40:36.283Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-16T13:40:36.283Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"ayahunter/dsh-plugin-clinic","pickedAt":"2026-08-16T13:40:36.283Z","reviewedCommit":"c62b8136a4f71eeb6e2084e907d9e5010ab4d011","category":"dev","summary":{"zh":"只读体检已安装的 DSH 插件，检查加载、依赖、兼容性、安装脚本和 patch 完整性。","en":"Read-only health checks for installed DSH plugins, covering loading, dependencies, compatibility, install scripts, and patch integrity."},"reason":{"zh":"提供模型工具、Web 面板和稳定 JSON 报告；离线检查引擎不会执行被检插件，也不会修改配置。","en":"Provides a model tool, Web dashboard, and stable JSON report; the offline engine does not execute inspected plugins or change configuration."},"safety":{"risk":"medium","zh":"会读取 ~/.dsh 下的 profile、package.json 与 patch 文件，并通过本地 /clinic 路由展示报告；路由仅做 Host 限制且没有认证，远程暴露 DSH 时需检查反向代理。","en":"Reads profiles, package.json, and patch files under ~/.dsh and serves reports on local /clinic routes; the route uses Host filtering without authentication, so review reverse-proxy exposure when DSH is remotely reachable."}}},{"id":"uckkk/dsh-license-guard","order":294,"name":"dsh-license-guard","owner":"uckkk","repo":"uckkk/dsh-license-guard","url":"https://github.com/uckkk/dsh-license-guard","category":"dev","description":{"zh":"扫描 node_modules 许可证并做发布前合规门禁。","en":"Scans dependency licenses and adds a pre-release compliance gate."},"added":"2026-08-16","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-16T10:39:31.618Z","lastSeenAt":"2026-08-16T10:39:31.618Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-16T10:39:31.618Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"uckkk/dsh-license-guard","pickedAt":"2026-08-16T10:39:31.618Z","reviewedCommit":"2ad466ac10b725730ddc400f73b8aee68cf66f0e","category":"dev","summary":{"zh":"扫描 node_modules 许可证并做发布前合规门禁。","en":"Scans dependency licenses and adds a pre-release compliance gate."},"reason":{"zh":"零运行依赖、无网络与 Shell，适合在开源或商业发布前快速排查许可证风险。","en":"Zero runtime dependencies, no network or shell access, and useful before open-source or commercial releases."},"safety":{"risk":"low","zh":"只读取 node_modules 中的 package.json；结果属于启发式筛查，仍需法律复核。","en":"Reads package.json files under node_modules only; findings remain heuristic and need legal review."}}},{"id":"luoyuejun9/dsh-project-memory","order":295,"name":"dsh-project-memory","owner":"luoyuejun9","repo":"luoyuejun9/dsh-project-memory","url":"https://github.com/luoyuejun9/dsh-project-memory","category":"session","description":{"zh":"把项目决策、约束和经验保存成带证据、可校验的长期记忆。","en":"Stores project decisions, constraints, and lessons as evidence-backed, verifiable memory."},"added":"2026-08-16","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-16T09:38:31.473Z","lastSeenAt":"2026-08-16T09:38:31.473Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-16T09:38:31.473Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"luoyuejun9/dsh-project-memory","pickedAt":"2026-08-16T09:38:31.473Z","reviewedCommit":"05215420d6853a1a0f9effcf3a96290cedcc85ed","category":"session","summary":{"zh":"把项目决策、约束和经验保存成带证据、可校验的长期记忆。","en":"Stores project decisions, constraints, and lessons as evidence-backed, verifiable memory."},"reason":{"zh":"模型只能提出候选，必须由人通过命令批准；记录可进 Git，证据变化后能检测失效。","en":"The model can only propose candidates; human approval is required, records are Git-friendly, and stale evidence is detectable."},"safety":{"risk":"medium","zh":"会在项目 .dsh 目录写入候选与记忆；不使用云数据库、向量服务或后台进程。","en":"Writes candidates and memory under the project .dsh directory; no cloud database, embeddings service, or background daemon."}}},{"id":"luoyuejun9/dsh-workstate","order":296,"name":"dsh-workstate","owner":"luoyuejun9","repo":"luoyuejun9/dsh-workstate","url":"https://github.com/luoyuejun9/dsh-workstate","category":"workflow","description":{"zh":"用结构化检查点保存任务进度、决策、失败和下一步，方便跨 Agent 接力。","en":"Captures structured task checkpoints for safe handoffs between coding agents."},"added":"2026-08-16","curated":false,"topic":false,"stars":null,"forks":null,"openIssues":null,"watchers":null,"pushedAt":null,"updatedAt":null,"createdAt":null,"license":null,"language":null,"homepage":null,"archived":false,"defaultBranch":null,"maintenance":"unknown","manifest":{"state":"missing","branch":null,"kinds":[],"packageName":null,"version":null,"lifecycleScripts":[],"runtimeDependencies":0,"declaredPaths":[],"invalidDeclaredPaths":[]},"screenedCommit":null,"installCommand":null,"discovery":{"source":"topic","firstSeenAt":"2026-08-16T09:38:31.473Z","lastSeenAt":"2026-08-16T09:38:31.473Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-16T09:38:31.473Z","findings":[],"filesInspected":[],"checks":{"manifest":false,"license":false,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"review","reasons":["等待定时源码检查"]},"codexPick":{"repo":"luoyuejun9/dsh-workstate","pickedAt":"2026-08-16T09:38:31.473Z","reviewedCommit":"0b1b1477f3f23aeebaed6d0c08b2ce3b96cf74b7","category":"workflow","summary":{"zh":"用结构化检查点保存任务进度、决策、失败和下一步，方便跨 Agent 接力。","en":"Captures structured task checkpoints for safe handoffs between coding agents."},"reason":{"zh":"交接包记录路径与哈希，不复制文件内容；恢复前会校验 Git 与工作区是否发生漂移。","en":"Handoff packets store paths and hashes without file contents, and validate Git and workspace drift before resume."},"safety":{"risk":"medium","zh":"会写入 .dsh/workstate；恢复只注入状态，不执行 checkout、reset、stash、commit 或 push。","en":"Writes under .dsh/workstate; resume injects state without checkout, reset, stash, commit, or push."}}},{"id":"omdsh-dev/dsh-at-file","order":2,"name":"dsh-at-file","owner":"omdsh-dev","repo":"omdsh-dev/dsh-at-file","url":"https://github.com/omdsh-dev/dsh-at-file","category":"ui","description":{"en":"Codex-style `@file` mentions: search workspace files in the composer and attach their contents to prompts.","zh":"Codex 风格的 `@file` 文件引用，输入框里直接搜索并引用工作区文件。"},"added":"2026-08-13","curated":true,"topic":true,"stars":89,"forks":3,"openIssues":0,"watchers":89,"pushedAt":"2026-08-14T07:27:34Z","updatedAt":"2026-08-14T08:15:23Z","createdAt":"2026-08-13T12:00:09Z","license":"MIT","language":"JavaScript","homepage":null,"archived":false,"defaultBranch":"main","maintenance":"active","manifest":{"state":"verified","branch":"main","kinds":["bundle","client"],"packageName":"dsh-at-file","version":"0.4.0","lifecycleScripts":[],"runtimeDependencies":1,"declaredPaths":["cordis.patch.yml","lib/index.js","lib/client.js"],"invalidDeclaredPaths":[]},"installCommand":null,"discovery":{"source":"curated","firstSeenAt":"2026-08-13","lastSeenAt":"2026-08-14T08:18:12.622Z"},"screening":{"version":1,"scope":"manifest","state":"pending","risk":"unknown","checkedAt":"2026-08-14T08:18:12.622Z","findings":[],"filesInspected":["package.json"],"checks":{"manifest":true,"license":true,"readme":false,"lockfile":false,"source":false,"securityDisclosure":false}},"attention":{"level":"clear","reasons":[]},"screenedCommit":null,"codexPick":{"repo":"omdsh-dev/dsh-at-file","pickedAt":"2026-08-14T03:10:26.926Z","reviewedCommit":"2c5653ebc3240626cdad41a9c01d15d22471aed2","category":"ui","summary":{"zh":"在 DSH 输入框中用 @ 搜索并引用当前工作区的文件或目录路径。","en":"Adds Codex-style @path search and references to the DSH composer."},"reason":{"zh":"交互直接、使用频率高；当前版本只注入工作区相对路径，由 Agent 按需读取文件。","en":"A frequent, direct workflow improvement; current releases inject a workspace-relative path and let the agent read on demand."},"safety":{"risk":"medium","zh":"会索引工作区路径名并提供打开路径能力；符号链接与越界路径会被拒绝。","en":"Indexes workspace path names and can open selected paths; symlinks and paths outside the workspace are rejected."}}}]}