{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"jesse-njx-dsh-chatnode-wechat","slug":"jesse-njx-dsh-chatnode-wechat","rank":400,"url":"https://github.com/Jesse-njx/dsh-chatnode-wechat","name":"Jesse-njx/dsh-chatnode-wechat","category":"notify","description":{"zh":"通过 iLink 网关在微信里与 DSH agent 聊天、监控与审批：双向文本、会话切换、进度摘要与编号审批提示。","en":"Chat with, monitor, and approve your DSH agents from WeChat via the iLink gateway: text both ways, session targeting, digest heartbeats, and numbered approval prompts."},"stars":7,"starsCheckedAt":"2026-08-21","repository":{"owner":"Jesse-njx","repo":"dsh-chatnode-wechat","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:Jesse-njx/dsh-chatnode-wechat","tarball":null,"added":"2026-08-14","page":"https://awesome-dsh-plugin.com/p/Jesse-njx/dsh-chatnode-wechat/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"jesse-njx-dsh-chatnode-wechat","slug":"jesse-njx-dsh-chatnode-wechat","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:24:34.534Z","scanStatus":"static-complete","verdict":"caution","score":90,"commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","commitDate":"2026-08-14T00:55:36+08:00","artifactDigest":"sha256:3d82f068e2b4ba299155b2b5c17678c9dc5eee1f1e240f95602780bc3d8ebb02","downloadUrl":"https://github.com/Jesse-njx/dsh-chatnode-wechat/archive/a724da34b5c78a9b9ab4a5de79f5d2a05fac1745.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:Jesse-njx/dsh-chatnode-wechat","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"@dsh-cowork/chatnode-wechat","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{"prepare":"pnpm build"},"peerDependencies":[]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"@dsh-cowork/chatnode-wechat","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"dsh-chatnode-wechat","name":"@dsh-cowork/chatnode-wechat","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","host-bundle","network","session"],"outboundHosts":[{"host":"ilinkai.weixin.qq.com","count":3},{"host":"novac2c.cdn.weixin.qq.com","count":3}],"findings":[{"id":"HT-INSTALL-002","title":"Git 安装会触发 prepare 构建脚本","severity":"medium","confidence":"medium","layer":"supply-chain","path":"package.json","pathClass":"manifest","line":40,"evidence":"\"prepare\": \"pnpm build\"","remediation":"发布预构建制品（npm 或 GitHub Release tarball），并记录源码与发布包的一致性证明。","note":"源码安装需用户在 allowBuilds 中授权，此脚本会在安装期于用户机器执行","hash":"619d136d2740ac49e3552764"},{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"medium","confidence":"medium","layer":"static","path":"lib/gateway/index.d.ts","pathClass":"source","line":220,"evidence":"credential access at line 220 + outbound network at line 93","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"fe53b0479cc0c0d309c0005b","review":{"verdict":"functional","reason":"网关模块持有微信登录凭据(token/accountId)并通过sendText等方法向配置的baseUrl网关发消息，是iLink微信网关插件的核心功能，非泄露到用户未配置目的地。","model":"sonnet@p2","reviewedAt":"2026-08-21T11:26:27.566Z"}},{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"medium","confidence":"medium","layer":"static","path":"src/gateway/index.ts","pathClass":"source","line":253,"evidence":"credential access at line 253 + outbound network at line 127","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"cfa79e110ca4e62ff53494a7","review":{"verdict":"functional","reason":"loginQr获取的凭据经ctx.credentials存储，sendText用同一凭据向this.c.baseUrl(微信iLink网关)发消息，属于插件声明的微信收发功能，未见凭据外泄第三方。","model":"sonnet@p2","reviewedAt":"2026-08-21T11:26:27.566Z"}}],"counts":{"critical":0,"high":0,"medium":3,"low":0},"rawCounts":{"critical":0,"high":0,"medium":3,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":47,"bytesScanned":297190,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":4,"markdown":2,"cordis":1,"source":35,"manifest":1,"yaml":2,"html":1,"data":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:24:34.535Z","summary":null,"intentMatch":null,"findingsReviewed":2,"findingsCandidates":2,"fromCache":2,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:24:34.534Z","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:26:27.566Z","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:55:15.358Z","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:24:34.534Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:26:27.566Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"a724da34b5c78a9b9ab4a5de79f5d2a05fac1745","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:55:15.358Z"}]}