DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-plugin-trustlens

Read-only security auditor for DeepSeek Harness plugins combining static analysis and model semantic review.

Terminal & TUISecurity & PolicyRemote Execution
1GitHub Stars0ForksUpdated2026-08-27

Install

$ dsh plugin --profile web add github:Mengshang-spec/dsh-plugin-trustlens

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
dsh-plugin-trustlens is a DeepSeek Harness plugin designed to audit installed plugins before they are enabled or updated. It performs read-only static code scanning for risky patterns such as remote execution, persistence, and environment exfiltration, combined with semantic inspection powered by the active session model. It also checks for discrepancies between code and documentation while enforcing user confirmation gates before plugin activation.

Key Capabilities

  • Read-only static scanning for remote execution, persistence, and exfiltration patterns
  • Semantic code and behavior review using the currently active DSH session model
  • Detection of contradictions between code implementation and comments/README
  • Enforcement of user confirmation gates for enabling, updating, and quarantining plugins
  • Integration into DSH settings under AI review panel

Useful For

  • Auditing newly installed DSH plugins before enabling them in a workspace
  • Verifying plugin updates for suspicious code changes or hidden exfiltration logic
  • Analyzing plugin documentation claims against actual code structure

Who It Fits

  • DeepSeek Harness users vetting third-party plugins
  • Security-conscious developers building or managing DSH workspaces
  • DSH workspace administrators managing plugin permissions and isolation

Documented Limitations

  • Static scanning is conservative and may trigger false positives on security examples or regex patterns
  • Semantic analysis requires an active DSH model session and fails closed if credentials or models are unavailable
  • Operates strictly read-only and does not perform dynamic runtime sandbox execution

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
Mengshang-spec/dsh-plugin-trustlens
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
216787a · 2026-08-28

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
1GitHub stars
Forks
0
Open issues
0
Last commit
2026-08-27
Last release
No release detected
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app