Home / Plugin audits / dsh-security-audit

dsh-security-auditgithub.com/dsh-external/dsh-security-audit · v0.0.1

PENDINGDSH·PLUGIN·HUB

DSH local security audit tool: read-only scans of config, credential metadata, plugin provenance, session structure and network exposure; redacted, reproducible, locatable risk reports

dsh plugin --profile web add github:dsh-external/dsh-security-audit

Restart dsh after installing — no change before a restart is expected, not a broken install

AUDIT 2026-09-30

The four checks

Collected 2026-09-30 · refreshed daily
① Permissions Pending manual review · no network or exec dependency hints
Automated hintsNo network libraries (axios / node-fetch / ws …) or exec libraries (execa / shelljs …) among the dependencies.
Manual verdictQueued for review — once complete, the confirmed permission scope and review date appear here.
Why permissions are reviewed by hand: there's no reliable way to determine permission scope automatically, so only a human review produces a verdict. If a review is over 60 days old and the repo has changed since, the verdict drops back to Pending automatically.
② Maintenance Updated 20 days ago
last commit 2026-09-10
RuleLast commit ≤ 14 days green · ≤ 45 days amber · older (or archived) red.
③ dsh.bundle dsh.bundle declared — activates properly
Why this mattersPer the official docs, a package without a dsh.bundle declaration installs as a plain dependency and activates no layer — the most common reason a plugin "does nothing" after install.
④ Tests / CI Tests, no CI
TestsTest script or test directory found.
CINo CI workflows found.

Audit history

2026-09-30 · Latest audit (verdict: Pending); compatibility tracking updates with each daily run
See its scenario prescription → Spot an error? Send feedback Audit methodology