{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"didclawapp-ai-dsh-office","slug":"didclawapp-ai-dsh-office","rank":764,"url":"https://github.com/didclawapp-ai/DSH-Office","name":"didclawapp-ai/DSH-Office","category":"docs","description":{"zh":"通过本机 zagens-office CLI 读写编辑 PPTX / DOCX / XLSX / PDF，注册为 office_schema / office_write / office_edit / office_read。","en":"Create, read, and edit PPTX, DOCX, XLSX, and PDF via the local zagens-office CLI as office_schema / office_write / office_edit / office_read tools."},"stars":3,"starsCheckedAt":"2026-08-21","repository":{"owner":"didclawapp-ai","repo":"DSH-Office","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:didclawapp-ai/DSH-Office","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/didclawapp-ai/DSH-Office/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"didclawapp-ai-dsh-office","slug":"didclawapp-ai-dsh-office","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:28:22.274Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","commitDate":"2026-08-15T20:24:07+08:00","artifactDigest":"sha256:2e8e213e2244a6db394bc6ac133802bc785ad6e7b0914355598ed5df4af03d00","downloadUrl":"https://github.com/didclawapp-ai/DSH-Office/archive/d4569418d5123bec63bf6e843ae7c7de7b749ea7.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:didclawapp-ai/DSH-Office","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-zagens-office","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-zagens-office","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"zagens-office","name":"dsh-zagens-office","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","environment","filesystem","host-bundle","subprocess"],"outboundHosts":[{"host":"zagens.com","count":12}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/index.js","pathClass":"source","line":6,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"89dedaa9e6429e9e52b8af60"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/run.ts","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"d3a41013dd853507660195b8"}],"counts":{"critical":0,"high":0,"medium":0,"low":2},"rawCounts":{"critical":0,"high":0,"medium":0,"low":2},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":16,"bytesScanned":76111,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"markdown":1,"cordis":1,"source":9,"manifest":1,"yaml":1,"test-example-docs":3}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:28:22.274Z","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:30:19.163Z","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:59:23.132Z","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:28:22.274Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:30:19.163Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"d4569418d5123bec63bf6e843ae7c7de7b749ea7","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:59:23.132Z"}]}