Bundle
dsh-plugin-guard
DSH plugin gate + clinic: static audit before and after install, hash lock, peer search, mechanical detox. Never executes the target plugin.
- Source
- taxueseek
- stars
- 2 stars
- License
- MIT
- Updated
- Updated 15 hours ago
Readme
# dsh-plugin-guard One plugin, two surfaces. Static analysis only — never executes the target plugin. | Surface | Tool | Job | |---|---|---| | Gate | `plugin_audit` | Static audit before install | | Gate | `plugin_verify` | Hash + capability lock after install | | Clinic | `plugin_peers` | Local fingerprint peers; `query` searches GitHub `topic:dsh-plugin` | | Clinic | `plugin_detox` | Mechanical amputation, not an equivalent rewrite | `plugin_peers`: `path` stays local (profile bundles). `query` hits GitHub `topic:dsh-plugin` + the curated list; argo only if those are thin. Override with `remote`. Remote hits are `verdict=unknown` — audit before install. ## Install ```sh dsh plugin --profile web add github:taxueseek/dsh-plugin-guard # restart dsh web ``` ## Scoring Start at 100; P0 −40, P1 −12, P2 −3. Any P0 or score < 40 → `block`. Any P1 or score < 75 → `warn`. P0 is only auto-run + dangerous combo (`curl|bash`, secrets leaving the machine, eval of network content, install-script poison). `exec` inside a tool the model must click is P1. ## Not - Not output redaction - Not general SAST - Does not prove a plugin is safe - Detox does not keep the original behavior ## License MIT
Install
dsh plugin --profile web add github:taxueseek/dsh-plugin-guard
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-plugin-guard from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.