{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"hongming-huang-dsh-file-upload","slug":"hongming-huang-dsh-file-upload","rank":229,"url":"https://github.com/HongMing-Huang/dsh-file-upload","name":"HongMing-Huang/dsh-file-upload","category":"ui","description":{"zh":"Claude 风格拖拽/回形针文件上传：内容嗅探、文档转 Markdown（微软 MarkItDown，内置 JS 兜底）、文本直插输入框、read_document 工具。","en":"Claude-style drag-and-drop/paperclip file upload with content sniffing, document-to-Markdown via Microsoft MarkItDown (built-in JS fallback), text inlining, and a read_document tool for agents."},"stars":13,"starsCheckedAt":"2026-08-21","repository":{"owner":"HongMing-Huang","repo":"dsh-file-upload","requestedRef":null,"subpath":""},"npm":"dsh-file-upload","downloads":2892,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-file-upload","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/HongMing-Huang/dsh-file-upload/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"hongming-huang-dsh-file-upload","slug":"hongming-huang-dsh-file-upload","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:22:31.183Z","scanStatus":"static-complete","verdict":"review","score":83,"commit":"ce4ca943da592be36a784a5648d36a600aeda136","commitDate":"2026-08-19T23:41:34+08:00","artifactDigest":"sha256:c68cfaa5aa1ef531158fcd20288a119b3d2d7bc763749b4b5135ffa174440a71","downloadUrl":"https://github.com/HongMing-Huang/dsh-file-upload/archive/ce4ca943da592be36a784a5648d36a600aeda136.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-file-upload","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-file-upload","packageVersion":"0.5.2","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-runtime"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-credentials","@deepseek-ai/dsh-fs","@deepseek-ai/dsh-tools","@deepseek-ai/schemastery"]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-file-upload","manifestName":"dsh-file-upload","nameMatch":true,"npm":{"name":"dsh-file-upload","latestVersion":"0.4.3","publishedAt":"2026-08-19T04:38:15.602Z","createdAt":"2026-08-15T09:08:31.533Z","versionCount":5,"maintainers":1,"repository":"git+https://github.com/HongMing-Huang/dsh-file-upload.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"file-upload","name":"dsh-file-upload","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","network","session","subprocess"],"outboundHosts":[{"host":"api.openai.com","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/convert.ts","pathClass":"source","line":18,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"fd246af9df854f89968a0150"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/index.ts","pathClass":"source","line":17,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"165497e2a6660ef29786eb22"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/integration.test.ts","pathClass":"test-example-docs","line":3,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"9aa8a33c765bb8d7a6694e78"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/integration.test.ts","pathClass":"test-example-docs","line":46,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"4d4b4c5ce232a0b6adb388cc"},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"sharp@0.34.5 GHSA-f88m-g3jw-g9cj fixed in 0.35.0","remediation":"升级 sharp 至 0.35.0 或更高版本。","layer":"vulnerability","hash":"5a4db0689a0f52165e1694de","review":{"verdict":"unclear","reason":"证据仅展示 pnpm-lock.yaml 头部（direct dependencies 列表），未见 sharp 及其解析版本 0.34.5 的实际记录，无法核实该传递依赖是否真的以此版本存在。","model":"sonnet","reviewedAt":"2026-08-21T10:50:29.873Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"pdfjs-dist@1.10.100 GHSA-wgrm-67xf-hhpq (CVE-2024-4367) fixed in 4.2.67","remediation":"升级 pdfjs-dist 至 4.2.67 或更高版本。","layer":"vulnerability","hash":"a8e68f1f1e72460a3385935e","review":{"verdict":"unclear","reason":"直接依赖 pdfjs-dist 已锁定为 4.10.38（高于修复版 4.2.67），与命中所称的 1.10.100 矛盾，且证据未展示该低版本在何处被解析引入，无法核实。","model":"sonnet","reviewedAt":"2026-08-21T10:50:29.873Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"braces@2.3.2 GHSA-grv7-fg5c-xmjg (CVE-2024-4068) fixed in 3.0.3","remediation":"升级 braces 至 3.0.3 或更高版本。","layer":"vulnerability","hash":"f5183aae198941c7bb0e7466","review":{"verdict":"unclear","reason":"证据只截断到直接依赖列表，未展示 braces@2.3.2 具体出现的传递依赖路径（可能来自 markitdown-node 的 webpack@4.47.0 构建链），无法确认其是否随包发布进入运行时。","model":"sonnet","reviewedAt":"2026-08-21T10:50:29.873Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"serialize-javascript@4.0.0 GHSA-5c6j-r48x-rmvq fixed in 7.0.3","remediation":"升级 serialize-javascript 至 7.0.3 或更高版本。","layer":"vulnerability","hash":"fac2ca8c731468cea4d1b8f1","review":{"verdict":"unclear","reason":"同上，serialize-javascript@4.0.0 通常为 webpack/terser 构建期依赖，证据未展示其在锁文件中的实际位置及是否参与运行时文档解析，无法判定风险是否可达。","model":"sonnet","reviewedAt":"2026-08-21T10:50:29.873Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"medium","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"micromatch@3.1.10 GHSA-952p-6rrq-rcjv (CVE-2024-4067) fixed in 4.0.8","remediation":"升级 micromatch 至 4.0.8 或更高版本。","layer":"vulnerability","hash":"f2aa3f863bba1619d1bb22fc"},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"medium","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"uuid@8.3.2 GHSA-w5hq-g745-h8pq (CVE-2026-41907) fixed in 11.1.1","remediation":"升级 uuid 至 11.1.1 或更高版本。","layer":"vulnerability","hash":"88c1749a1e248087951432b3"}],"counts":{"critical":0,"high":4,"medium":2,"low":2},"rawCounts":{"critical":0,"high":4,"medium":2,"low":4},"vulnerabilities":[{"id":"GHSA-f88m-g3jw-g9cj","aliases":[],"package":"sharp","version":"0.34.5","severity":"high","fixed":"0.35.0","summary":"sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591"},{"id":"GHSA-wgrm-67xf-hhpq","aliases":["CVE-2024-4367"],"package":"pdfjs-dist","version":"1.10.100","severity":"high","fixed":"4.2.67","summary":"PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF"},{"id":"GHSA-grv7-fg5c-xmjg","aliases":["CVE-2024-4068"],"package":"braces","version":"2.3.2","severity":"high","fixed":"3.0.3","summary":"Uncontrolled resource consumption in braces"},{"id":"GHSA-5c6j-r48x-rmvq","aliases":[],"package":"serialize-javascript","version":"4.0.0","severity":"high","fixed":"7.0.3","summary":"Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()"},{"id":"GHSA-952p-6rrq-rcjv","aliases":["CVE-2024-4067"],"package":"micromatch","version":"3.1.10","severity":"medium","fixed":"4.0.8","summary":"Regular Expression Denial of Service (ReDoS) in micromatch"},{"id":"GHSA-w5hq-g745-h8pq","aliases":["CVE-2026-41907","CVE-2026-41988"],"package":"uuid","version":"8.3.2","severity":"medium","fixed":"11.1.1","summary":"uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided"},{"id":"GHSA-848j-6mx2-7j84","aliases":["CVE-2025-14505"],"package":"elliptic","version":"6.6.1","severity":"low","fixed":null,"summary":"Elliptic Uses a Cryptographic Primitive with a Risky Implementation"}],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":25,"bytesScanned":304256,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":6,"data":3,"markdown":5,"source":8,"cordis":1,"manifest":1,"yaml":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:22:31.183Z","summary":null,"intentMatch":null,"findingsReviewed":4,"findingsCandidates":4,"fromCache":4,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:22:31.183Z","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.2","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T11:22:04.656Z","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.1","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T10:50:29.873Z","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.0","verdict":"review","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:22:31.183Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:22:04.656Z"},{"kind":"first-scan","from":null,"to":"review","commit":"ce4ca943da592be36a784a5648d36a600aeda136","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:50:29.873Z"}]}