{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"aks1st-model-usage-plugin","slug":"aks1st-model-usage-plugin","rank":390,"url":"https://github.com/AKS1st/model-usage-plugin","name":"AKS1st/model-usage-plugin","category":"usage","description":{"zh":"按模型统计 token 消耗并估算费用，同时显示 DeepSeek 账户余额，展示于设置面板「模型消耗」页签。","en":"Per-model token usage and cost estimation with DeepSeek account balance, shown in a Settings panel tab."},"stars":7,"starsCheckedAt":"2026-08-21","repository":{"owner":"AKS1st","repo":"model-usage-plugin","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:AKS1st/model-usage-plugin","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/AKS1st/model-usage-plugin/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"aks1st-model-usage-plugin","slug":"aks1st-model-usage-plugin","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:24:26.642Z","scanStatus":"static-complete","verdict":"caution","score":95,"commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","commitDate":"2026-08-17T21:01:11+08:00","artifactDigest":"sha256:2802adb29481620614c97bd75262f9508422078101d3d89dc7162653b785a07e","downloadUrl":"https://github.com/AKS1st/model-usage-plugin/archive/62b5c88f574f68623c8096ccdb0e2159452c1565.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:AKS1st/model-usage-plugin","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"model-usage-plugin","packageVersion":"0.3.2","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web"},"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"model-usage-plugin","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"model-usage-plugin","name":"model-usage-plugin","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["browser-ui","credentials","environment","filesystem","host-bundle","network","subprocess"],"outboundHosts":[{"host":"api.deepseek.com","count":2},{"host":"open.er-api.com","count":2},{"host":"api.frankfurter.app","count":1}],"findings":[{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"medium","confidence":"medium","layer":"static","path":"src/index.js","pathClass":"source","line":545,"evidence":"credential access at line 545 + outbound network at line 492","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"d51f0cedfc071572e6fa7205","review":{"verdict":"functional","reason":"credentials.resolve('DEEPSEEK_API_KEY') 取得的密钥仅用于向用户配置或默认的 DeepSeek 官方余额接口(/user/balance)发起请求，符合插件声明的余额查询功能。","model":"sonnet@p2","reviewedAt":"2026-08-21T11:24:46.307Z"}}],"counts":{"critical":0,"high":0,"medium":1,"low":0},"rawCounts":{"critical":0,"high":0,"medium":1,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":5,"bytesScanned":81525,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":1,"cordis":1,"manifest":1,"source":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:24:26.642Z","summary":null,"intentMatch":null,"findingsReviewed":1,"findingsCandidates":1,"fromCache":1,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:24:26.642Z","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:24:46.306Z","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:53:31.833Z","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:24:26.642Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:24:46.306Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"62b5c88f574f68623c8096ccdb0e2159452c1565","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:53:31.833Z"}]}