{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"juanwang-buaa-dsh-full-remote","slug":"juanwang-buaa-dsh-full-remote","rank":168,"url":"https://github.com/JUANWANG-BUAA/dsh-full-remote","name":"JUANWANG-BUAA/dsh-full-remote","category":"remote","description":{"zh":"远程访问 DeepSeek Harness 且服务端 API 完整：转发时改写 Host/Origin，恢复其他方案必定 403 的 settings.* / credentials.* / host.listDirectory。令牌门、按设备会话、可选首访审批。","en":"Remote DeepSeek Harness with full server-side API access (`settings.*` / `credentials.*` / `host.listDirectory`). Token-gated reverse proxy, per-device sessions, phone invite QR, fence self-check, optional approval / CIDR / idle timeout / local TLS, WebSocket/SSE."},"stars":21,"starsCheckedAt":"2026-08-21","repository":{"owner":"JUANWANG-BUAA","repo":"dsh-full-remote","requestedRef":null,"subpath":""},"npm":"dsh-full-remote","downloads":2186,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-full-remote","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/JUANWANG-BUAA/dsh-full-remote/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"juanwang-buaa-dsh-full-remote","slug":"juanwang-buaa-dsh-full-remote","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:21:44.031Z","scanStatus":"static-complete","verdict":"caution","score":89,"commit":"83d3957c9f2f1b61a51621af0ff4d82707155eb1","commitDate":"2026-08-21T19:53:46+08:00","artifactDigest":"sha256:01506893622a93dc092276c13f9973ecca3d9d73492c3a91591724a419b12035","downloadUrl":"https://github.com/JUANWANG-BUAA/dsh-full-remote/archive/83d3957c9f2f1b61a51621af0ff4d82707155eb1.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-full-remote","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-full-remote","packageVersion":"0.3.7","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-slots"]},"lifecycleScripts":{"prepare":"pnpm run build"},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-slots"]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-full-remote","manifestName":"dsh-full-remote","nameMatch":true,"npm":{"name":"dsh-full-remote","latestVersion":"0.3.6","publishedAt":"2026-08-21T07:06:38.247Z","createdAt":"2026-08-15T14:00:42.853Z","versionCount":13,"maintainers":1,"repository":"git+https://github.com/JUANWANG-BUAA/dsh-full-remote.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"attested","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"reverse-proxy","name":"dsh-full-remote","path":"cordis.patch.yml","disabled":false}],"overrides":[{"id":"directory-picker","tier":"normal","mode":"override","disabled":false,"replacesImplementation":false,"name":null,"keys":[],"path":"cordis.patch.yml"}],"jsExpressions":1,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","network","session","subprocess","telemetry"],"outboundHosts":[{"host":"your-tunnel.example","count":2}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":12,"evidence":"!!js process.env.DSH_FULL_REMOTE_USE_NATIVE_PICKER !== '1'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"d60baf52e8e9ba111993c77e"},{"id":"HT-INSTALL-002","title":"Git 安装会触发 prepare 构建脚本","severity":"medium","confidence":"low","layer":"supply-chain","path":"package.json","pathClass":"manifest","line":33,"evidence":"\"prepare\": \"pnpm run build\"","remediation":"发布预构建制品（npm 或 GitHub Release tarball），并记录源码与发布包的一致性证明。","note":"该插件以 npm/tarball 预构建方式分发，prepare 不在用户机器上执行","hash":"34d0fb2d8cc8e5494b8298cf"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/bootstrap.mjs","pathClass":"source","line":10,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"873e5dbfc966e7d149c1b8f0"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/bootstrap.mjs","pathClass":"source","line":10,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"7cbc4442f0c330549fec2c8b"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/capture-screenshots.ts","pathClass":"source","line":7,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"39ca7183a27987b143e051bf"},{"id":"HT-RUNTIME-001","title":"动态代码执行","severity":"high","confidence":"low","layer":"static","path":"scripts/repro-issue-9.mts","pathClass":"source","line":15,"evidence":"eval(","remediation":"使用静态模块和受约束的配置解析器，避免在宿主权限下执行动态字符串。","hash":"44f6409cca7aea3232e1fd3a","review":{"verdict":"placeholder","reason":"该 eval 位于 scripts/repro-issue-9.mts 复现脚本，仅用于本地测试 PAGE_BOOTSTRAP_SOURCE 与 Cordis Context Proxy 的交互，且未列入 package.json 的 files 字段，不会随包发布或在生产运行时执行。","model":"sonnet","reviewedAt":"2026-08-21T10:49:22.447Z"}},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/smoke.mjs","pathClass":"source","line":19,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"a2344ba2bd650cffa9943d69"},{"id":"HT-CLIENT-001","title":"浏览器端使用危险 HTML 注入点","severity":"medium","confidence":"medium","layer":"static","path":"src/client/RemoteSection.tsx","pathClass":"source","line":653,"evidence":"dangerouslySetInnerHTML","remediation":"使用安全 DOM API，并在不可避免时对不可信内容进行严格清洗。","hash":"d56f1e3033464614a43d5e08"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/tunnel.ts","pathClass":"source","line":15,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"0a3644df86e1c678da4ed8d4"},{"id":"HT-RUNTIME-001","title":"动态代码执行","severity":"high","confidence":"low","layer":"static","path":"tests/page-bootstrap.test.ts","pathClass":"test-example-docs","line":25,"evidence":"vm.runInContext(","remediation":"使用静态模块和受约束的配置解析器，避免在宿主权限下执行动态字符串。","note":"位于测试、示例或文档目录","hash":"e45144acb1deb7832844f778"},{"id":"HT-RUNTIME-001","title":"动态代码执行","severity":"high","confidence":"low","layer":"static","path":"tests/page-bootstrap.test.ts","pathClass":"test-example-docs","line":30,"evidence":"vm.runInContext(","remediation":"使用静态模块和受约束的配置解析器，避免在宿主权限下执行动态字符串。","note":"位于测试、示例或文档目录","hash":"e45144acb1deb7832844f778"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/tunnel.test.ts","pathClass":"test-example-docs","line":8,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"78d56406857b735b14a961e4"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/tunnel.test.ts","pathClass":"test-example-docs","line":162,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"78d56406857b735b14a961e4"}],"counts":{"critical":0,"high":0,"medium":2,"low":5},"rawCounts":{"critical":0,"high":3,"medium":3,"low":7},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":109,"bytesScanned":1019796,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":27,"markdown":28,"cordis":1,"source":48,"manifest":1,"yaml":2,"data":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:21:44.032Z","summary":null,"intentMatch":null,"findingsReviewed":1,"findingsCandidates":1,"fromCache":1,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:21:44.031Z","commit":"83d3957c9f2f1b61a51621af0ff4d82707155eb1","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:21:21.294Z","commit":"d7c912034693cfca52a346b8e8263ce7c21dfca4","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:49:22.447Z","commit":"d7c912034693cfca52a346b8e8263ce7c21dfca4","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"83d3957c9f2f1b61a51621af0ff4d82707155eb1","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:21:44.031Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"d7c912034693cfca52a346b8e8263ce7c21dfca4","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:21:21.294Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"d7c912034693cfca52a346b8e8263ce7c21dfca4","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:49:22.447Z"}]}