{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"katsos-dsh-claude-cli","slug":"katsos-dsh-claude-cli","rank":526,"url":"https://github.com/katsos/dsh-claude-cli","name":"katsos/dsh-claude-cli","category":"model","description":{"zh":"LLM 供应商：把本机已安装的 Claude Code CLI 作为模型后端，请求走已订阅的 Claude 账号，无需按量计费的 API key；原生工具调用经 MCP 桥接。","en":"LLM provider that runs the locally installed Claude Code CLI as the model backend, so requests go through an existing Claude subscription instead of a metered API key; native tool calls are bridged over MCP."},"stars":5,"starsCheckedAt":"2026-08-21","repository":{"owner":"katsos","repo":"dsh-claude-cli","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:katsos/dsh-claude-cli","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/katsos/dsh-claude-cli/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"katsos-dsh-claude-cli","slug":"katsos-dsh-claude-cli","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-21T13:17:04.584Z","scanStatus":"static-complete","verdict":"caution","score":89,"commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","commitDate":"2026-08-15T19:03:07+03:00","artifactDigest":"sha256:d6c18a520768e9c57112ccdc94f71eca60dcebe3748f96ce7757596a9c944d70","downloadUrl":"https://github.com/katsos/dsh-claude-cli/archive/3a3a57f22a3e748c9720a1b96ce64e015f0f9643.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:katsos/dsh-claude-cli","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-claude-cli","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{"prepare":"npm run build"},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-llm"]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-claude-cli","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"claude-cli","name":"dsh-claude-cli","path":"cordis.patch.yml","disabled":false},{"id":"claude-cli","name":"/absolute/path/to/dsh-claude-cli/src/index.ts","path":"cordis.yml","disabled":false}],"overrides":[{"id":"agent-default-model","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":false,"name":null,"keys":["provider","model"],"path":"cordis.yml"}],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","mcp","subprocess"],"outboundHosts":[],"findings":[{"id":"HT-INSTALL-002","title":"Git 安装会触发 prepare 构建脚本","severity":"medium","confidence":"medium","layer":"supply-chain","path":"package.json","pathClass":"manifest","line":41,"evidence":"\"prepare\": \"npm run build\"","remediation":"发布预构建制品（npm 或 GitHub Release tarball），并记录源码与发布包的一致性证明。","note":"源码安装需用户在 allowBuilds 中授权，此脚本会在安装期于用户机器执行","hash":"d28b218339321374f2793b3b"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/cli.ts","pathClass":"source","line":13,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"93b630cc391cd66bd8db8ef7"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/adapter.e2e.ts","pathClass":"test-example-docs","line":8,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"fa5ac4db3f51e7337a9501a9"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/adapter.e2e.ts","pathClass":"test-example-docs","line":8,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"6d114a73e7d3bd546733f5f6"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"cordis.yml","line":20,"evidence":"override: id=agent-default-model config[provider,model]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"改写配置 agent-default-model；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"8b0336d07895f9c0eaf2dd9a"}],"counts":{"critical":0,"high":0,"medium":2,"low":1},"rawCounts":{"critical":0,"high":0,"medium":2,"low":3},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":25,"bytesScanned":145805,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"test-example-docs":6,"markdown":1,"source":12,"cordis":2,"data":3,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-21T13:17:04.584Z","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:28:33.643Z","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:57:30.289Z","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.2","at":"2026-08-21T13:17:04.584Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:28:33.643Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"3a3a57f22a3e748c9720a1b96ce64e015f0f9643","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:57:30.289Z"}]}