dsh-plugin-trustlens
Read-only security auditor for DeepSeek Harness plugins combining static analysis and model semantic review.
Install
$ dsh plugin --profile web add github:Mengshang-spec/dsh-plugin-trustlensPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Read-only static scanning for remote execution, persistence, and exfiltration patterns
- Semantic code and behavior review using the currently active DSH session model
- Detection of contradictions between code implementation and comments/README
- Enforcement of user confirmation gates for enabling, updating, and quarantining plugins
- Integration into DSH settings under AI review panel
Useful For
- Auditing newly installed DSH plugins before enabling them in a workspace
- Verifying plugin updates for suspicious code changes or hidden exfiltration logic
- Analyzing plugin documentation claims against actual code structure
Who It Fits
- DeepSeek Harness users vetting third-party plugins
- Security-conscious developers building or managing DSH workspaces
- DSH workspace administrators managing plugin permissions and isolation
Documented Limitations
- Static scanning is conservative and may trigger false positives on security examples or regex patterns
- Semantic analysis requires an active DSH model session and fails closed if credentials or models are unavailable
- Operates strictly read-only and does not perform dynamic runtime sandbox execution
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- Mengshang-spec/dsh-plugin-trustlens
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 216787a · 2026-08-28
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 1GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-08-27
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
DSH undo and crash-recovery plugin with snapshots, rollback, Safe Mode, and offline Windows tools.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →Native SQLite-backed local project taskboard plugin and UI for DeepSeek Harness with Agent claim and review flows.
View plugin →Sandbox-first automatic permission policy and intelligent risk classification for DeepSeek Harness.
View plugin →