{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"johnxu22786-worktree-mgr","slug":"johnxu22786-worktree-mgr","rank":974,"url":"https://github.com/JohnXu22786/worktree-mgr","name":"JohnXu22786/worktree-mgr","category":"git","description":{"zh":"按任务隔离的 git worktree 工作区，覆盖创建/同步/收尾全生命周期：任务名自动派生分支、合并目标双重校验、内置批量清理——全程零手工 git 操作。","en":"Per-task isolated git worktrees with a full create/sync/finish lifecycle: task names auto-derive branches, merge targets are double-checked, and batch cleanup is built in — zero manual git operations."},"stars":2,"starsCheckedAt":"2026-08-21","repository":{"owner":"JohnXu22786","repo":"worktree-mgr","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:JohnXu22786/worktree-mgr","tarball":null,"added":"2026-08-16","page":"https://awesome-dsh-plugin.com/p/JohnXu22786/worktree-mgr/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"johnxu22786-worktree-mgr","slug":"johnxu22786-worktree-mgr","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:30:26.895Z","scanStatus":"static-complete","verdict":"caution","score":94,"commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","commitDate":"2026-08-17T09:33:18+08:00","artifactDigest":"sha256:afc05c64cb27063f41d332a3fce672b0ab1dbea25acc4a13fd9ce263bf19482e","downloadUrl":"https://github.com/JohnXu22786/worktree-mgr/archive/63a457e23eb367cd629f21a65eee5d539d571ca0.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:JohnXu22786/worktree-mgr","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"worktree-mgr","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"worktree-mgr","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"worktree-mgr","name":"worktree-mgr","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":1,"clientPlatform":null,"parseErrors":[]},"capabilities":["environment","filesystem","host-bundle","subprocess"],"outboundHosts":[],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":15,"evidence":"!!js process.cwd()","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"25b8f7566df9792e79fb48d5"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/git.js","pathClass":"source","line":9,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"25a4c64931e754359328d7c1"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/git.js","pathClass":"source","line":9,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"30203eb50053b9f6062ea240"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/triggers.js","pathClass":"source","line":9,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1c8d10ed4727404ca711d242"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/integration.test.js","pathClass":"test-example-docs","line":6,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"a004bf709820ae0c6ded42f0"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/integration.test.js","pathClass":"test-example-docs","line":6,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"d680e6bfcf0a2706b6974252"}],"counts":{"critical":0,"high":0,"medium":1,"low":3},"rawCounts":{"critical":0,"high":0,"medium":1,"low":5},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":24,"bytesScanned":199703,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"markdown":2,"source":9,"cordis":1,"test-example-docs":9,"data":2,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:30:26.895Z","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:33:37.063Z","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:02:28.317Z","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:30:26.895Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:33:37.063Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"63a457e23eb367cd629f21a65eee5d539d571ca0","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T11:02:28.317Z"}]}