Bundle
@mkaliezz/dsh-plugin-firewall
Offline-first static admission scanner for DeepSeek Harness plugins.
- Source
- MkaliezZ
- License
- MIT
- Updated
- Updated 14 days ago
Readme
# dsh-plugin-firewall Offline-first static admission scanner for DeepSeek Harness community plugins. `/plugin-firewall <path>` inspects a local plugin package before you trust it. v0.1 looks for package install scripts, git/URL dependencies, native addons, Cordis/profile patches, tool registration, process/network/filesystem/environment access indicators, and emits a deterministic risk receipt with a SHA-256 digest. ## v0.1 goals - no network calls or vulnerability database; - deterministic local analysis; - explicit LOW / MEDIUM / HIGH findings; - JSON-safe receipt with digest; - never executes the scanned plugin; - does not claim malware detection or complete supply-chain safety. ## Development ```bash npm install npm test ``` ## License MIT
Install
dsh plugin --profile web add github:MkaliezZ/dsh-plugin-firewall
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install mkaliezz-dsh-plugin-firewall from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.