{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"geml-spec-geml-integrations-dsh-plugin","slug":"geml-spec-geml-integrations-dsh-plugin","rank":160,"url":"https://github.com/geml-spec/geml/tree/main/integrations/dsh-plugin","name":"geml-spec/geml#integrations/dsh-plugin","category":"tools","description":{"zh":"按块寻址的文档读写：MCP server 提供 geml_get / geml_set / geml_check 等工具，Agent 只取回或改写 Markdown、GEML 文档中的某一个块，而不是整篇文件。另带 GEML 写作技能，以及把项目调用图构建为 GEML codemap 并浏览的代码图谱技能。","en":"Block-addressed document editing: an MCP server exposing geml_get / geml_set / geml_check and friends, so an agent reads or rewrites one addressed block of a Markdown or GEML document instead of the whole file. Ships the GEML authoring skill and a code-graph skill that builds and navigates a project call graph as GEML codemaps."},"stars":24,"starsCheckedAt":"2026-08-21","repository":{"owner":"geml-spec","repo":"geml","requestedRef":"main","subpath":"integrations/dsh-plugin"},"npm":"@geml/dsh-plugin","downloads":33,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add @geml/dsh-plugin","tarball":null,"added":"2026-08-17","page":"https://awesome-dsh-plugin.com/p/geml-spec/geml--integrations-dsh-plugin/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"geml-spec-geml-integrations-dsh-plugin","slug":"geml-spec-geml-integrations-dsh-plugin","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:21:38.776Z","scanStatus":"static-complete","verdict":"caution","score":95,"commit":"c967aad7a200c220f2471392613dfe28d4b0664d","commitDate":"2026-08-21T15:07:29+08:00","artifactDigest":"sha256:75dea781b04c13570d0b5748fe19cbcf6dfb1566f370707278bccab897ec9ec1","downloadUrl":"https://github.com/geml-spec/geml/archive/c967aad7a200c220f2471392613dfe28d4b0664d.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add @geml/dsh-plugin","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"@geml/dsh-plugin","packageVersion":"1.0.1","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"@geml/dsh-plugin","manifestName":"@geml/dsh-plugin","nameMatch":true,"npm":{"name":"@geml/dsh-plugin","latestVersion":"1.0.1","publishedAt":"2026-08-20T06:26:55.004Z","createdAt":"2026-08-17T05:42:43.605Z","versionCount":2,"maintainers":1,"repository":"git+https://github.com/geml-spec/geml.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"mcp-geml","name":"@deepseek-ai/dsh-mcp-client","path":"cordis.patch.yml","disabled":false},{"id":"skill-geml","name":"@deepseek-ai/dsh-skill-filesystem","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":1,"clientPlatform":null,"parseErrors":[]},"capabilities":["host-bundle","mcp"],"outboundHosts":[],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":27,"evidence":"!!js \"process.getBuiltinModule('node:url').fileURLToPath(new URL('skills/', baseUrl))\"","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"83aa1dc736f75b2bf599d351"}],"counts":{"critical":0,"high":0,"medium":1,"low":0},"rawCounts":{"critical":0,"high":0,"medium":1,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":6,"bytesScanned":30306,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":4,"cordis":1,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:21:38.776Z","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:20:54.463Z","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:48:53.964Z","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:21:38.776Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:20:54.463Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"c967aad7a200c220f2471392613dfe28d4b0664d","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:48:53.964Z"}]}