{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"icetomoyo-dsh-workflow","slug":"icetomoyo-dsh-workflow","rank":68,"url":"https://github.com/icetomoyo/dsh_workflow","name":"icetomoyo/dsh_workflow","category":"workflow","description":{"zh":"把 UltraCode 式多 Agent 调度带给 DSH：可生成、可保存、可治理、可观察、可恢复的 Workflow 层。","en":"UltraCode-style multi-agent orchestration: a generatable, savable, governable, observable, resumable workflow layer."},"stars":94,"starsCheckedAt":"2026-08-21","repository":{"owner":"icetomoyo","repo":"dsh_workflow","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:icetomoyo/dsh_workflow","tarball":null,"added":"2026-08-13","page":"https://awesome-dsh-plugin.com/p/icetomoyo/dsh_workflow/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"icetomoyo-dsh-workflow","slug":"icetomoyo-dsh-workflow","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:20:23.150Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","commitDate":"2026-08-13T12:20:40+08:00","artifactDigest":"sha256:9b27e01cf75d515b245f500c4d20e4374985d9d9e8ef7d0d8d0df7638a804e97","downloadUrl":"https://github.com/icetomoyo/dsh_workflow/archive/44b83c182aa02d1be8a0803e8446cb495f93cd8f.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:icetomoyo/dsh_workflow","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"@dsh-external/workflow","packageVersion":"0.1.2","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-agent","@deepseek-ai/dsh-commands","@deepseek-ai/dsh-jobs","@deepseek-ai/dsh-llm","@deepseek-ai/dsh-session","@deepseek-ai/dsh-subagent","@deepseek-ai/dsh-system-prompt","@deepseek-ai/dsh-tools","@deepseek-ai/dsh-user-approval","@deepseek-ai/dsh-user-questions","@deepseek-ai/dsh-workflow","@deepseek-ai/schemastery"]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"@dsh-external/workflow","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"dsh-external-workflow","name":"@dsh-external/workflow","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","environment","filesystem","host-bundle","network","session","subprocess","telemetry"],"outboundHosts":[],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/engine.js","pathClass":"source","line":5,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"705f1ab05b00ea3128f5a7a3"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/index.js","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"89dedaa9e6429e9e52b8af60"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/source-policy.js","pathClass":"source","line":15,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"9b3cc3c9ccf6095b5bf325c9"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/source-policy.js","pathClass":"source","line":15,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"9b3cc3c9ccf6095b5bf325c9"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/check-compatibility.mjs","pathClass":"source","line":1,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"8bd99458bcfa60996bb66ca5"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/check-compatibility.mjs","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"e68192c505bef81104c9703d"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/engine.ts","pathClass":"source","line":5,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"89d301c6132894d1f96be21e"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/index.ts","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"165497e2a6660ef29786eb22"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/source-policy.ts","pathClass":"source","line":18,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1bf4b626ae0edcceb2a669f7"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/source-policy.ts","pathClass":"source","line":18,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1bf4b626ae0edcceb2a669f7"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/engine.spec.ts","pathClass":"test-example-docs","line":396,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"f0a6b73cf2b5a3ca0b9dbbb2"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/engine.spec.ts","pathClass":"test-example-docs","line":396,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"cd5c95b3f426953a68affea7"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/plugin.spec.ts","pathClass":"test-example-docs","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"fa9167684c999a56621f246a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/source-policy.spec.ts","pathClass":"test-example-docs","line":10,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"228875f18096e68030bb0630"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/source-policy.spec.ts","pathClass":"test-example-docs","line":10,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"228875f18096e68030bb0630"}],"counts":{"critical":0,"high":0,"medium":0,"low":10},"rawCounts":{"critical":0,"high":0,"medium":0,"low":15},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":70,"bytesScanned":922989,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"markdown":11,"data":4,"cordis":1,"test-example-docs":12,"source":39,"manifest":1,"yaml":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:20:23.150Z","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:19:06.554Z","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:46:55.540Z","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:20:23.150Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:19:06.554Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"44b83c182aa02d1be8a0803e8446cb495f93cd8f","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:46:55.540Z"}]}