{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"linhut-gongwen-skill","slug":"linhut-gongwen-skill","rank":296,"url":"https://github.com/linhut/gongwen-skill","name":"linhut/gongwen-skill","category":"skill","description":{"zh":"中文公文全流程处理工具：GB/T 9704 格式检查、自动修复、内容修订（红色标注+删除线）、模板生成、Markdown 转公文、版头/版记/页码注入，覆盖通知/请示/报告/函/会议纪要等 24 类公文。","en":"Chinese government document processing toolkit: GB/T 9704 format check, auto-fix, content revision (red annotation + strikethrough), template generation, Markdown-to-docx, and document header/footer/page-number injection for 24 official document types."},"stars":9,"starsCheckedAt":"2026-08-21","repository":{"owner":"linhut","repo":"gongwen-skill","requestedRef":null,"subpath":""},"npm":"gongwen-skill","downloads":1047,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add gongwen-skill","tarball":null,"added":"2026-08-18","page":"https://awesome-dsh-plugin.com/p/linhut/gongwen-skill/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"linhut-gongwen-skill","slug":"linhut-gongwen-skill","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:23:21.022Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","commitDate":"2026-08-20T21:55:14+08:00","artifactDigest":"sha256:6e4bbc4dd83bc0d369997b41281cab1d981c92aaba1de405fe80462509b1684d","downloadUrl":"https://github.com/linhut/gongwen-skill/archive/a4d744768493aa242ccc1c16ececbdc4e722c37e.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add gongwen-skill","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"gongwen-skill","packageVersion":"2.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"gongwen-skill","manifestName":"gongwen-skill","nameMatch":true,"npm":{"name":"gongwen-skill","latestVersion":"2.1.0","publishedAt":"2026-08-20T13:56:28.240Z","createdAt":"2026-08-15T14:44:38.666Z","versionCount":8,"maintainers":1,"repository":"git+https://github.com/linhut/gongwen-skill.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"gongwen-skill","name":"gongwen-skill","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":null,"parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","mcp","network","subprocess"],"outboundHosts":[{"host":"www.linhut.cn","count":91},{"host":"www.baidu.com","count":1},{"host":"www.bing.com","count":1},{"host":"gitcode.com","count":1},{"host":"atomgit.com","count":1},{"host":"pypi.org","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"dsh/index.js","pathClass":"source","line":18,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"c4c2ec60434c7e25ebbdc257"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"engine/docx_to_image.py","pathClass":"source","line":44,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"46d3115cdca0ed762dba172a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"engine/docx_to_image.py","pathClass":"source","line":83,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"46d3115cdca0ed762dba172a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"gongwen/cli/doctor_cmds.py","pathClass":"source","line":67,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"85ed8338f9f4f237af92a187"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"gongwen/cli/doctor_cmds.py","pathClass":"source","line":239,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"85ed8338f9f4f237af92a187"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"gongwen/cli/font_cmds.py","pathClass":"source","line":202,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"85a6c0b80281667cb545e623"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"gongwen/cli/update_cmds.py","pathClass":"source","line":36,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"24f68ca50994f28257496782"}],"counts":{"critical":0,"high":0,"medium":0,"low":7},"rawCounts":{"critical":0,"high":0,"medium":0,"low":7},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":104,"bytesScanned":1429870,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":8,"test-example-docs":4,"cordis":1,"source":64,"data":1,"manifest":1,"yaml":25}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:23:21.022Z","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:23:37.891Z","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:52:22.535Z","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:23:21.022Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:23:37.891Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"a4d744768493aa242ccc1c16ececbdc4e722c37e","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:52:22.535Z"}]}