{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"omdsh-dev-dsh-mnemon","slug":"omdsh-dev-dsh-mnemon","rank":47,"url":"https://github.com/omdsh-dev/dsh-mnemon","name":"omdsh-dev/dsh-mnemon","category":"memory","description":{"zh":"由 Mnemon 驱动的 DeepSeek Harness（DSH）跨 Agent、本地优先的持久记忆插件。它可在支持 Mnemon 的 Agent 之间共享长期记忆，并提供运行时记忆、可检索项目档案、语义召回、知识图谱和 Sidebar UI。","en":"Cross-agent, local-first persistent memory plugin for DeepSeek Harness (DSH), powered by Mnemon. It shares long-term memory across Mnemon-enabled agents and adds runtime memory, searchable project documents, semantic recall, knowledge graph, and a Sidebar UI."},"stars":166,"starsCheckedAt":"2026-08-21","repository":{"owner":"omdsh-dev","repo":"dsh-mnemon","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:omdsh-dev/dsh-mnemon","tarball":null,"added":"2026-08-13","page":"https://awesome-dsh-plugin.com/p/omdsh-dev/dsh-mnemon/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"omdsh-dev-dsh-mnemon","slug":"omdsh-dev-dsh-mnemon","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:20:07.093Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"7def5b2bddd4ecb746f09b0c8dee8032e72c690d","commitDate":"2026-08-21T21:48:52+08:00","artifactDigest":"sha256:d5c28a5f199be644c12118dc47dcff158b6b46861fe28568dd269e5ff21ca984","downloadUrl":"https://github.com/omdsh-dev/dsh-mnemon/archive/7def5b2bddd4ecb746f09b0c8dee8032e72c690d.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:omdsh-dev/dsh-mnemon","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-mnemon","packageVersion":"0.2.15","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-client-ui-conversation","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-locale"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/dsh-client-ui-primitives"]},"identity":{"status":"published-unlisted","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-mnemon","nameMatch":null,"npm":{"name":"dsh-mnemon","latestVersion":"0.2.14","publishedAt":"2026-08-20T21:42:31.378Z","createdAt":"2026-08-13T19:28:45.151Z","versionCount":22,"maintainers":1,"repository":"git+https://github.com/omdsh-dev/dsh-mnemon.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"mnemon","name":"dsh-mnemon","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","mcp","network","session","subprocess","telemetry"],"outboundHosts":[{"host":"host.docker.internal","count":7},{"host":"api.honcho.dev","count":1},{"host":"api.mem0.ai","count":1},{"host":"api.hindsight.vectorize.io","count":1},{"host":"api.retaindb.com","count":1},{"host":"api.supermemory.ai","count":1},{"host":"api.github.com","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/verify-deterministic-build.mjs","pathClass":"source","line":4,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"f47fdf550ed09647ade1e8a8"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/verify-deterministic-build.mjs","pathClass":"source","line":4,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"03bb23d70f9298ebc6651786"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/verify-headless-profile.mjs","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"01b31f51b956eac310f0afed"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/verify-package-contents.mjs","pathClass":"source","line":1,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"9eb3c692d710dbb74e9b4d2f"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/verify-package-contents.mjs","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"4755a315c5578e4491aa911c"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/process.ts","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"f5d2b2f10893d8c20915968d"},{"id":"HT-CLIENT-001","title":"浏览器端使用危险 HTML 注入点","severity":"medium","confidence":"low","layer":"static","path":"tests/client-sidebar.spec.tsx","pathClass":"test-example-docs","line":37,"evidence":".innerHTML =","remediation":"使用安全 DOM API，并在不可避免时对不可信内容进行严格清洗。","note":"位于测试、示例或文档目录","hash":"632139af52dc5d4bcf122dd2"},{"id":"HT-CLIENT-001","title":"浏览器端使用危险 HTML 注入点","severity":"medium","confidence":"low","layer":"static","path":"tests/client-sidebar.spec.tsx","pathClass":"test-example-docs","line":186,"evidence":".innerHTML =","remediation":"使用安全 DOM API，并在不可避免时对不可信内容进行严格清洗。","note":"位于测试、示例或文档目录","hash":"632139af52dc5d4bcf122dd2"},{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"high","confidence":"low","layer":"static","path":"scripts/probe-provider-lab.mjs","pathClass":"source","line":4,"evidence":"credential access at line 4 + outbound network at line 16","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"21f8dd1cd15a10d71ed947ec","review":{"verdict":"placeholder","reason":"scripts/probe-provider-lab.mjs 是仅用于本地 provider-lab 健康检查的开发脚本，未列入 package.json 的 files 字段，不会随 npm 包分发；请求全部指向 127.0.0.1 本地服务，Authorization 使用环境变量或明确标注的 'dsh-provider-lab-local-only' 本地占位密钥。","model":"sonnet@p2","reviewedAt":"2026-08-21T11:18:43.327Z"}},{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"high","confidence":"low","layer":"static","path":"scripts/seed-provider-lab.mjs","pathClass":"source","line":16,"evidence":"credential access at line 16 + outbound network at line 103","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"9f70b545454de39dd72329d2","review":{"verdict":"placeholder","reason":"scripts/seed-provider-lab.mjs 同属未发布的本地测试脚手架（不在 files 列表中），供开发者在本机 docker 化的 openviking/honcho/mem0 等实例上播种数据，凭据来自 env 或为空字符串，网络目标均为 127.0.0.1，不涉及真实用户凭据外发。","model":"sonnet@p2","reviewedAt":"2026-08-21T11:18:43.327Z"}}],"counts":{"critical":0,"high":0,"medium":0,"low":6},"rawCounts":{"critical":0,"high":2,"medium":2,"low":6},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":203,"bytesScanned":2929365,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":50,"markdown":68,"cordis":1,"manifest":1,"yaml":3,"script":1,"source":77,"data":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:20:07.093Z","summary":null,"intentMatch":null,"findingsReviewed":2,"findingsCandidates":2,"fromCache":2,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:20:07.093Z","commit":"7def5b2bddd4ecb746f09b0c8dee8032e72c690d","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:18:43.327Z","commit":"97019cb91cdbda78b26b92d89ec59dd2b2138ca8","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:46:33.873Z","commit":"97019cb91cdbda78b26b92d89ec59dd2b2138ca8","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"7def5b2bddd4ecb746f09b0c8dee8032e72c690d","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:20:07.093Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"97019cb91cdbda78b26b92d89ec59dd2b2138ca8","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:18:43.327Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"97019cb91cdbda78b26b92d89ec59dd2b2138ca8","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:46:33.873Z"}]}