{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"jiezeng2004-design-dsh-chatgpt-bridge","slug":"jiezeng2004-design-dsh-chatgpt-bridge","rank":306,"url":"https://github.com/jiezeng2004-design/dsh-chatgpt-bridge","name":"jiezeng2004-design/dsh-chatgpt-bridge","category":"notify","description":{"zh":"通过 MCP 让 ChatGPT Web 创建、查看、继续和监督 DeepSeek Harness Agent 会话与 Goal，同时保留 DSH 原生的审批、沙箱与工作区安全模型。","en":"MCP bridge that lets ChatGPT Web create, view, continue, and supervise DeepSeek Harness agent sessions and goals while preserving DSH's native approval, sandbox, and workspace security model."},"stars":9,"starsCheckedAt":"2026-08-21","repository":{"owner":"jiezeng2004-design","repo":"dsh-chatgpt-bridge","requestedRef":null,"subpath":""},"npm":"dsh-chatgpt-bridge","downloads":282,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-chatgpt-bridge","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/jiezeng2004-design/dsh-chatgpt-bridge/","screenshots":["https://raw.githubusercontent.com/jiezeng2004-design/dsh-chatgpt-bridge/main/assets/screenshots/01-human-in-the-loop.png","https://raw.githubusercontent.com/jiezeng2004-design/dsh-chatgpt-bridge/main/assets/screenshots/02-runtime-goal-update.png","https://raw.githubusercontent.com/jiezeng2004-design/dsh-chatgpt-bridge/main/assets/screenshots/03-native-dsh-execution.png","https://raw.githubusercontent.com/jiezeng2004-design/dsh-chatgpt-bridge/main/assets/screenshots/04-workspace-security.png"],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"jiezeng2004-design-dsh-chatgpt-bridge","slug":"jiezeng2004-design-dsh-chatgpt-bridge","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:23:27.195Z","scanStatus":"static-complete","verdict":"caution","score":93,"commit":"8c47538e3961a9df5abbd5df55424f8e97f360af","commitDate":"2026-08-22T09:53:07+08:00","artifactDigest":"sha256:21e107f3bc2c716688f7835f74e1c7b2551da21c9b5aba37489011c1913b2be9","downloadUrl":"https://github.com/jiezeng2004-design/dsh-chatgpt-bridge/archive/8c47538e3961a9df5abbd5df55424f8e97f360af.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-chatgpt-bridge","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-chatgpt-bridge","packageVersion":"0.4.1","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-slots","@deepseek-ai/dsh-client-ui-settings"]},"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-chatgpt-bridge","manifestName":"dsh-chatgpt-bridge","nameMatch":true,"npm":{"name":"dsh-chatgpt-bridge","latestVersion":"0.4.0","publishedAt":"2026-08-21T00:24:50.208Z","createdAt":"2026-08-14T11:57:37.987Z","versionCount":4,"maintainers":1,"repository":"git+https://github.com/jiezeng2004-design/dsh-chatgpt-bridge.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"storage","name":"@deepseek-ai/dsh-storage","path":"cordis.headless.patch.yml","disabled":false},{"id":"storage-json","name":"@deepseek-ai/dsh-storage-json","path":"cordis.headless.patch.yml","disabled":false},{"id":"storage-domain","name":"@deepseek-ai/dsh-storage-domain","path":"cordis.headless.patch.yml","disabled":false},{"id":"workspace","name":"@deepseek-ai/dsh-workspace","path":"cordis.headless.patch.yml","disabled":false},{"id":"session-projection-cache","name":"@deepseek-ai/dsh-session-projection-cache","path":"cordis.headless.patch.yml","disabled":false},{"id":"chatgpt-bridge","name":"dsh-chatgpt-bridge","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":1,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","mcp","network","session","subprocess"],"outboundHosts":[{"host":"api.openai.com","count":4}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"low","confidence":"high","layer":"dsh-semantics","path":"cordis.headless.patch.yml","pathClass":"cordis","line":11,"evidence":"!!js dshHomePath('storages')","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","hash":"59aa838cbaa85d4f51b18870"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/discover.js","pathClass":"source","line":21,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"18734ee34c33494ab5f08979"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/discover.js","pathClass":"source","line":21,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"3b49c6a271a3292454d421c0"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/process-identity.js","pathClass":"source","line":16,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"0f56a7adec1f8fb75c285eab"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/process-identity.js","pathClass":"source","line":16,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"9f62a378a146f20a88b618fe"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/process-tunnel-runtime.js","pathClass":"source","line":10,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"07d7c4344fcfac9ef439cf2f"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/control/process-tunnel-runtime.js","pathClass":"source","line":10,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"4b2435a484a8924877d071cf"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/temp-resources.js","pathClass":"source","line":7,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"6338aad7554c0b6f5790442e"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/temp-resources.js","pathClass":"source","line":7,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"465a885b602bfae8516426d4"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/types/control/process-tunnel-runtime.d.ts","pathClass":"source","line":10,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"04aff923a4bd927d1c1b882b"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/types/control/process-tunnel-runtime.d.ts","pathClass":"source","line":10,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"ae2714bc65858604680a9ad5"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/resume-test.mjs","pathClass":"source","line":8,"evidence":"child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"b263b0e7ff3b7d93dd9b7ef2"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/resume-test.mjs","pathClass":"source","line":15,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"0fa6a479bf83c07094c771f2"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/test.mjs","pathClass":"source","line":19,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"f882188317eea627e4aad40a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/test.mjs","pathClass":"source","line":19,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"d33ba8df7da276a27e5dc069"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/discover.ts","pathClass":"source","line":21,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"2fc1a171304ef9e0b99dc737"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/discover.ts","pathClass":"source","line":21,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"a5640ae69c4aed3a6c66fb62"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/process-identity.ts","pathClass":"source","line":16,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"b089f20d6fa20d7da32322cc"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/process-identity.ts","pathClass":"source","line":16,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"4df178ccadec62528481a87c"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/process-tunnel-runtime.ts","pathClass":"source","line":10,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"7e93b031cf082136ad9435fa"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/control/process-tunnel-runtime.ts","pathClass":"source","line":10,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"cf2b33d62907b5e467a5e438"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/temp-resources.ts","pathClass":"source","line":7,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"63a803ec9205b31d28133d4f"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/temp-resources.ts","pathClass":"source","line":7,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"55da24b201cb737e5e9e9166"},{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"medium","confidence":"medium","layer":"static","path":"scripts/dogfood.mjs","pathClass":"source","line":19,"evidence":"credential access at line 19 + outbound network at line 222","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"3b27e8f826ce6e345aac9ec7","review":{"verdict":"functional","reason":"脚本读取的是本地桥自身签发的 chatgpt-bridge.token，仅用于向同机 127.0.0.1:3456 的 MCP 端点认证，属于开发用 dogfood 自测脚本的正常本地闭环，无跨域凭据外泄。","model":"sonnet","reviewedAt":"2026-08-22T08:23:27.195Z"}}],"counts":{"critical":0,"high":0,"medium":1,"low":23},"rawCounts":{"critical":0,"high":0,"medium":1,"low":23},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":141,"bytesScanned":1310422,"truncated":false,"lockfiles":["pnpm-lock.yaml","package-lock.json"],"pathClasses":{"test-example-docs":27,"markdown":2,"cordis":2,"source":106,"data":2,"manifest":1,"yaml":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:23:27.195Z","summary":"该插件是 MCP 桥接器，让 ChatGPT Web 通过官方 MCP 协议驱动本地 DSH agent 会话，宣称保留 DSH 原生审批/沙箱/工作区安全模型；cordis.patch.yml 仅插入 chatgpt-bridge 一行配置（监听 127.0.0.1，token 鉴权），未覆盖 sandbox/approval 等安全行。本次命中的 dogfood.mjs 是开发自测脚本，读取本地 token 文件仅用于向同机 MCP 服务鉴权，未涉及外部网络或凭据外泄，代码行为与插件声明的“仅连接、不接管安全模型”一致。需用户注意的是该桥默认监听本地端口并用文件/环境变量存储 token，应确保 token 文件权限受控。","intentMatch":"consistent","findingsReviewed":1,"findingsCandidates":1,"fromCache":0,"usage":{"inputTokens":2,"outputTokens":847,"costUsd":0.022904,"durationMs":12903}}},"timeline":[{"scannedAt":"2026-08-22T08:23:27.195Z","commit":"8c47538e3961a9df5abbd5df55424f8e97f360af","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:23:13.757Z","commit":"7409719c2336ab23bb09587d66b558c4d06c97e4","policyVersion":"HT-DSH-0.2.1","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T10:51:58.086Z","commit":"7409719c2336ab23bb09587d66b558c4d06c97e4","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"verdict-change","from":"review","to":"caution","commit":"8c47538e3961a9df5abbd5df55424f8e97f360af","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:23:27.195Z"},{"kind":"verdict-change","from":"caution","to":"review","commit":"7409719c2336ab23bb09587d66b558c4d06c97e4","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:23:13.757Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"7409719c2336ab23bb09587d66b558c4d06c97e4","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:51:58.086Z"}]}