{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"linxichen-dsh-rigorquant","slug":"linxichen-dsh-rigorquant","rank":790,"url":"https://github.com/linxichen/dsh-rigorquant","name":"linxichen/dsh-rigorquant","category":"skill","description":{"zh":"RigorQuant 预设与技能包：面向实证与计算数学（经济学、金融、组合）的无人值守隔离多智能体研究，内置四重实现前校验与 jacobian/Lean 升级通道。","en":"RigorQuant preset + skill pack: unattended walled multi-agent research for empirical and computational mathematics (economics, finance, portfolio), with a four-part pre-implementation check battery and a jacobian/Lean escalation lane."},"stars":3,"starsCheckedAt":"2026-08-21","repository":{"owner":"linxichen","repo":"dsh-rigorquant","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:linxichen/dsh-rigorquant","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/linxichen/dsh-rigorquant/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"linxichen-dsh-rigorquant","slug":"linxichen-dsh-rigorquant","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:28:39.778Z","scanStatus":"static-complete","verdict":"caution","score":89,"commit":"ca70cecc682957f5563297afe3d56e98eabc2e39","commitDate":"2026-08-21T14:29:11-04:00","artifactDigest":"sha256:bd47c21f3c5a61c6e361e6a7173ca65768f38a8988a4abff12bcdb81ebaf32fd","downloadUrl":"https://github.com/linxichen/dsh-rigorquant/archive/ca70cecc682957f5563297afe3d56e98eabc2e39.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:linxichen/dsh-rigorquant","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-rigorquant","packageVersion":"0.3.1","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-ui-settings-plugins"],"platform":"web","immediately":true},"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-rigorquant","nameMatch":null,"npm":{"name":"dsh-rigorquant","latestVersion":"0.3.0","publishedAt":"2026-08-18T21:41:51.762Z","createdAt":"2026-08-14T21:02:55.162Z","versionCount":4,"maintainers":1,"repository":null,"hasInstallScripts":false,"deprecated":false},"repositoryMatch":"missing","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"skill-filesystem-rigorquant","name":"@deepseek-ai/dsh-skill-filesystem","path":"cordis.patch.yml","disabled":false},{"id":"rq-model-router","name":"dsh-rigorquant","path":"cordis.patch.yml","disabled":false}],"overrides":[{"id":"persona","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-persona","keys":["text"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"agent-instructions","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-agent-instructions","keys":["maxBytes"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-bash","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-bash","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-pwsh","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-pwsh","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-fs","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-fs","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-fs-search","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-fs-search","keys":["sampleOverCapGlobResults"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-jobs","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-jobs","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"skill-filesystem","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-skill-filesystem","keys":["customSkillDirs"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-skill","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-skill","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-goal","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-goal","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"planning","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"compaction","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0","1","2"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"delegation","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0","1","2","3","4","5","6","7","8","9","10","11"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-ask-user","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-ask-user","keys":[],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-todo","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-todo","keys":["allowParallelInProgress"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"tool-web","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-web","keys":["fetch","searchTimeoutMs"],"path":"agent-presets/rigorquant/agent.cordis.yml"},{"id":"mcp-jacobian","tier":"normal","mode":"override","disabled":true,"replacesImplementation":true,"name":"@deepseek-ai/dsh-mcp-client","keys":["serverName","transport","command","args","env","toolCallTimeoutMs"],"path":"agent-presets/rigorquant/agent.cordis.yml"}],"jsExpressions":6,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","environment","host-bundle","mcp","network","session","subprocess"],"outboundHosts":[{"host":"export.arxiv.org","count":3},{"host":"arxiv.org","count":3},{"host":"api.openalex.org","count":2},{"host":"api.unpaywall.org","count":1},{"host":"core.ac.uk","count":1},{"host":"a9.com","count":1}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"agent-presets/rigorquant/agent.cordis.yml","pathClass":"cordis","line":67,"evidence":"!!js process.platform === 'win32'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"0ef080654c7c6e1bfaca839e"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"agent-presets/rigorquant/agent.cordis.yml","pathClass":"cordis","line":71,"evidence":"!!js process.platform !== 'win32'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"5b3256bcea71ad9a546404b3"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"agent-presets/rigorquant/skills/rigorquant/scripts/rq_check.py","pathClass":"source","line":728,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1eac3b2c707ae771f8a750f8"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":28,"evidence":"!!js \"process.getBuiltinModule('node:url').fileURLToPath(new URL('agent-presets/rigorquant/skills/', baseUrl))\"","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"39c45ba044a98ddbf6edc6bc"},{"id":"HT-RUNTIME-001","title":"动态代码执行","severity":"high","confidence":"low","layer":"static","path":"tests/client_bundle_probe.cjs","pathClass":"test-example-docs","line":30,"evidence":"vm.runInContext(","remediation":"使用静态模块和受约束的配置解析器，避免在宿主权限下执行动态字符串。","note":"位于测试、示例或文档目录","hash":"ef60627a19b202b762ddb4cf"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/conftest.py","pathClass":"test-example-docs","line":270,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"2229e38b039ae55dc41b412e"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/test_client_bundle.py","pathClass":"test-example-docs","line":51,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"b99e325727691a63e74fda85"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/test_client_bundle.py","pathClass":"test-example-docs","line":69,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"b99e325727691a63e74fda85"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/test_integration.py","pathClass":"test-example-docs","line":133,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"183ce13257c3b96b519abfad"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/test_repo_consistency.py","pathClass":"test-example-docs","line":20,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"5ae130206cca56daac02f10a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"tests/test_retrieval_tiers.py","pathClass":"test-example-docs","line":23,"evidence":"subprocess.run","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"d445696520e14f3204b049fc"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":57,"evidence":"override: id=agent-instructions name=@deepseek-ai/dsh-agent-instructions config[maxBytes]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 Agent 指令（agent-instructions）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"a880405de51cbf176a35ef6b"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":64,"evidence":"override: id=tool-bash name=@deepseek-ai/dsh-tool-bash","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 Bash 工具（tool-bash）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"e28f159cf6220f7c2bc03ca8"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":68,"evidence":"override: id=tool-pwsh name=@deepseek-ai/dsh-tool-pwsh","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-pwsh；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"a0804d613d553d0589251905"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":74,"evidence":"override: id=tool-fs name=@deepseek-ai/dsh-tool-fs","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 文件工具（tool-fs）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"85e2f7ec032c26e227f44cf4"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":77,"evidence":"override: id=tool-fs-search name=@deepseek-ai/dsh-tool-fs-search config[sampleOverCapGlobResults]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-fs-search；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"3e1194846af5fd8fc12c8793"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":84,"evidence":"override: id=tool-jobs name=@deepseek-ai/dsh-tool-jobs","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-jobs；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"0f4cf7453082948b862442b5"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":94,"evidence":"override: id=skill-filesystem name=@deepseek-ai/dsh-skill-filesystem config[customSkillDirs]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 skill-filesystem；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"d7c7c44bf09cac6bbe942159"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"agent-presets/rigorquant/agent.cordis.yml","line":99,"evidence":"override: id=tool-skill name=@deepseek-ai/dsh-tool-skill","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-skill；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"1f18a3bdfd55ee332ed4e59e"}],"counts":{"critical":0,"high":0,"medium":11,"low":1},"rawCounts":{"critical":0,"high":1,"medium":11,"low":7},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":50,"bytesScanned":536179,"truncated":false,"lockfiles":[],"pathClasses":{"test-example-docs":14,"markdown":19,"cordis":2,"yaml":1,"source":5,"data":6,"script":2,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:28:39.778Z","commit":"ca70cecc682957f5563297afe3d56e98eabc2e39","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T13:17:09.619Z","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:30:35.391Z","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:59:40.073Z","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"commit-change","from":"b57f1eb57fddfbae28333057702d39c9a936c826","to":"ca70cecc682957f5563297afe3d56e98eabc2e39","commit":"ca70cecc682957f5563297afe3d56e98eabc2e39","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:28:39.778Z"},{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.2","at":"2026-08-21T13:17:09.619Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:30:35.391Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"b57f1eb57fddfbae28333057702d39c9a936c826","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:59:40.073Z"}]}