{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"kw78-dsh-office-tools","slug":"kw78-dsh-office-tools","rank":496,"url":"https://github.com/kw78/dsh-office-tools","name":"kw78/dsh-office-tools","category":"docs","description":{"zh":"面向 agent 的工作区安全 Office 工具集：创建/读取 Word、创建/读取/更新 Excel、创建/读取 PowerPoint，并支持 PNG/JPG/GIF 图片排版。","en":"Workspace-safe Office tools for agents: create/read Word, create/read/update Excel, and create/read PowerPoint decks with PNG/JPG/GIF image placement."},"stars":5,"starsCheckedAt":"2026-08-21","repository":{"owner":"kw78","repo":"dsh-office-tools","requestedRef":null,"subpath":""},"npm":"dsh-office-tools","downloads":856,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-office-tools","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/kw78/dsh-office-tools/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"kw78-dsh-office-tools","slug":"kw78-dsh-office-tools","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:25:31.731Z","scanStatus":"static-complete","verdict":"review","score":83,"commit":"d9b6923ba14a803c331111d7447846d6a6796550","commitDate":"2026-08-15T15:29:45+08:00","artifactDigest":"sha256:6d8daaba443b2f21613ef418f11b53c40bfd29ea51330c617ca04cc760608edf","downloadUrl":"https://github.com/kw78/dsh-office-tools/archive/d9b6923ba14a803c331111d7447846d6a6796550.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-office-tools","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-office-tools","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-agent","@deepseek-ai/dsh-llm","@deepseek-ai/dsh-session","@deepseek-ai/dsh-tools"]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-office-tools","manifestName":"dsh-office-tools","nameMatch":true,"npm":{"name":"dsh-office-tools","latestVersion":"0.1.0","publishedAt":"2026-08-15T07:04:24.517Z","createdAt":"2026-08-15T07:04:24.169Z","versionCount":1,"maintainers":1,"repository":"git+https://github.com/kw78/dsh-office-tools.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"dsh-office-tools","name":"dsh-office-tools","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","filesystem","host-bundle","subprocess","telemetry"],"outboundHosts":[],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"build.mjs","pathClass":"source","line":19,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"12683165c26a59ed187f7b26"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"build.mjs","pathClass":"source","line":19,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"b10cec21ffbcfa15144ca3c2"},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-jf85-cpcp-j695 (CVE-2019-10744) fixed in 4.17.12","remediation":"升级 lodash 至 4.17.12 或更高版本。","layer":"vulnerability","hash":"d8f9108ff3cac0fd59c3d6a7","review":{"verdict":"unclear","reason":"给出的pnpm-lock.yaml片段仅含importers顶层直接依赖(1-41行)，未见packages区块中lodash@3.2.0的实际锁定条目，无法验证该传递依赖是否真实存在。","model":"sonnet","reviewedAt":"2026-08-21T10:49:53.375Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"high","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"xlsx@0.18.5 GHSA-4r6h-8v6p-xvw6 (CVE-2023-30533)","remediation":"关注 GHSA-4r6h-8v6p-xvw6 的修复进展，并评估该依赖是否可移除。","layer":"vulnerability","hash":"00496324e4e00fd9303ed498","review":{"verdict":"confirmed","reason":"pnpm-lock.yaml 显示 xlsx 版本锁定为 0.18.5，该版本存在原型污染漏洞 CVE-2023-30533，且未见任何补丁或版本覆盖。","model":"sonnet","reviewedAt":"2026-08-21T10:55:43.654Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"high","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"xlsx@0.18.5 GHSA-5pgg-2g8v-p4x9 (CVE-2024-22363)","remediation":"关注 GHSA-5pgg-2g8v-p4x9 的修复进展，并评估该依赖是否可移除。","layer":"vulnerability","hash":"5739092583b18e9dc18a010b","review":{"verdict":"confirmed","reason":"同一 xlsx@0.18.5 依赖同时受 CVE-2024-22363（ReDoS）影响，锁文件未做版本升级或 patch 缓解。","model":"sonnet","reviewedAt":"2026-08-21T10:55:43.654Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"image-size@1.2.1 GHSA-5p2g-fcmc-qvqq (CVE-2025-71329)","remediation":"关注 GHSA-5p2g-fcmc-qvqq 的修复进展，并评估该依赖是否可移除。","layer":"vulnerability","hash":"0974f77c8f7fd6a396abc592","review":{"verdict":"unclear","reason":"lockfile被截断未显示image-size@1.2.1具体挂靠于哪个上层依赖及是否被插件运行时代码实际调用，无法判断CVE-2025-71329是否可达。","model":"sonnet","reviewedAt":"2026-08-21T10:48:05.925Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"image-size@1.2.1 GHSA-w3rx-r6r6-pgpr (CVE-2025-71330)","remediation":"关注 GHSA-w3rx-r6r6-pgpr 的修复进展，并评估该依赖是否可移除。","layer":"vulnerability","hash":"0ede662304adbbf23ce6cb74","review":{"verdict":"unclear","reason":"同一image-size@1.2.1，命中内容仅为pnpm-lock.yaml顶部截断片段，未见其具体依赖路径或使用位置，无法确认CVE-2025-71330是否被实际触发。","model":"sonnet","reviewedAt":"2026-08-21T10:48:05.925Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-35jh-r3h4-6jhm (CVE-2021-23337) fixed in 4.17.21","remediation":"升级 lodash 至 4.17.21 或更高版本。","layer":"vulnerability","hash":"b2d1dd15951c04e08403c5ec","review":{"verdict":"unclear","reason":"同上，命中引用的lockfile内容未展示lodash相关行，无法确认该CVE对应的lodash@3.2.0是否确为解析后的依赖版本。","model":"sonnet","reviewedAt":"2026-08-21T10:49:53.375Z"}}],"counts":{"critical":0,"high":6,"medium":0,"low":2},"rawCounts":{"critical":0,"high":6,"medium":0,"low":2},"vulnerabilities":[{"id":"GHSA-jf85-cpcp-j695","aliases":["CVE-2019-10744"],"package":"lodash","version":"3.2.0","severity":"critical","fixed":"4.17.12","summary":"Prototype Pollution in lodash"},{"id":"GHSA-4r6h-8v6p-xvw6","aliases":["CVE-2023-30533"],"package":"xlsx","version":"0.18.5","severity":"high","fixed":null,"summary":"Prototype Pollution in sheetJS"},{"id":"GHSA-5pgg-2g8v-p4x9","aliases":["CVE-2024-22363"],"package":"xlsx","version":"0.18.5","severity":"high","fixed":null,"summary":"SheetJS Regular Expression Denial of Service (ReDoS)"},{"id":"GHSA-5p2g-fcmc-qvqq","aliases":["CVE-2025-71329"],"package":"image-size","version":"1.2.1","severity":"high","fixed":null,"summary":"image-size: JXL and HEIF parsers allow denial of service through infinite loops"},{"id":"GHSA-w3rx-r6r6-pgpr","aliases":["CVE-2025-71330"],"package":"image-size","version":"1.2.1","severity":"high","fixed":null,"summary":"image-size: ICNS parser allows denial of service through an infinite loop"},{"id":"GHSA-35jh-r3h4-6jhm","aliases":["CVE-2021-23337","CVE-2026-4800","GHSA-r5fr-rjxr-66jc"],"package":"lodash","version":"3.2.0","severity":"high","fixed":"4.17.21","summary":"Command Injection in lodash"},{"id":"GHSA-4xc9-xhrj-v574","aliases":["CVE-2018-16487"],"package":"lodash","version":"3.2.0","severity":"high","fixed":"4.17.11","summary":"Prototype Pollution in lodash"},{"id":"GHSA-f23m-r3pf-42rh","aliases":["CVE-2025-13465","CVE-2026-2950","GHSA-xxjr-mmjv-4gpg"],"package":"lodash","version":"3.2.0","severity":"medium","fixed":"4.18.0","summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`"},{"id":"GHSA-fvqr-27wr-82fm","aliases":["CVE-2018-3721"],"package":"lodash","version":"3.2.0","severity":"medium","fixed":"4.17.5","summary":"Prototype Pollution in lodash"}],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":29,"bytesScanned":158127,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":2,"markdown":5,"source":16,"cordis":1,"data":2,"manifest":1,"yaml":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:25:31.731Z","summary":null,"intentMatch":null,"findingsReviewed":6,"findingsCandidates":6,"fromCache":6,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:25:31.731Z","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.2","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T11:26:51.012Z","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.1","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T10:55:43.654Z","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.0","verdict":"review","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:25:31.731Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:26:51.012Z"},{"kind":"first-scan","from":null,"to":"review","commit":"d9b6923ba14a803c331111d7447846d6a6796550","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:55:43.654Z"}]}