{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"punky971210-dsh-punky-swarm-dsh-punky-swarm","slug":"punky971210-dsh-punky-swarm-dsh-punky-swarm","rank":1738,"url":"https://github.com/Punky971210/dsh-punky-swarm/tree/main/packages/dsh-punky-swarm","name":"Punky971210/dsh-punky-swarm#dsh-punky-swarm","category":"workflow","description":{"zh":"dsh 单机多子 Agent 集群治理引擎：wavePlan 三层 DAG + 引擎级门禁（Entry/L0/Exit/Complete）+ 状态机 + 锁/mailbox + 会话隔离，附蟛蜞模式预设与 jiufeng-team 角色指引。","en":"Single-machine multi-subagent swarm governance for DeepSeek Harness: fixed-semantics wavePlan (3-layer DAG), engine-enforced Tier3 gates (Entry/L0/Exit/Complete), state machine, locks/mailbox, session isolation, plus the Punky Mode preset and jiufeng-team role guide."},"stars":0,"starsCheckedAt":"2026-08-21","repository":{"owner":"Punky971210","repo":"dsh-punky-swarm","requestedRef":"main","subpath":"packages/dsh-punky-swarm"},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:Punky971210/dsh-punky-swarm#path:/packages/dsh-punky-swarm","tarball":null,"added":"2026-08-19","page":"https://awesome-dsh-plugin.com/p/Punky971210/dsh-punky-swarm--packages-dsh-punky-swarm/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"punky971210-dsh-punky-swarm-dsh-punky-swarm","slug":"punky971210-dsh-punky-swarm-dsh-punky-swarm","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:38:17.833Z","scanStatus":"static-complete","verdict":"caution","score":89,"commit":"86f4b53c59fddcd931f2db767d34fa2eb9399f84","commitDate":"2026-08-22T12:54:39+08:00","artifactDigest":"sha256:5b3922d9a4975f7928cbff7fdb561bdec1a6afb7705923df7f1429050bdde929","downloadUrl":"https://github.com/Punky971210/dsh-punky-swarm/archive/86f4b53c59fddcd931f2db767d34fa2eb9399f84.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:Punky971210/dsh-punky-swarm#path:/packages/dsh-punky-swarm","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-punky-swarm","packageVersion":"0.3.2","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-conversation"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-tools"]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-punky-swarm","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"dsh-punky-swarm","name":"dsh-punky-swarm","path":"cordis.patch.yml","disabled":false}],"overrides":[{"id":"persona","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-persona","keys":["text"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"agent-instructions","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-agent-instructions","keys":["maxBytes"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-bash","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-bash","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-pwsh","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-pwsh","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-fs","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-fs","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-fs-search","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-fs-search","keys":["sampleOverCapGlobResults"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-jobs","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-jobs","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"skill-filesystem","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-skill-filesystem","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-skill","tier":"sensitive","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-skill","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-goal","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-goal","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"planning","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"compaction","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0","1","2"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"delegation","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"cordis:group","keys":["0","1","2","3","4","5","6","7","8"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-ask-user","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-ask-user","keys":[],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-todo","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-todo","keys":["allowParallelInProgress"],"path":"presets/jiufeng/agent.cordis.yml"},{"id":"tool-web","tier":"normal","mode":"override","disabled":false,"replacesImplementation":true,"name":"@deepseek-ai/dsh-tool-web","keys":["fetch","searchTimeoutMs"],"path":"presets/jiufeng/agent.cordis.yml"}],"jsExpressions":2,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","environment","filesystem","host-bundle","network","subprocess"],"outboundHosts":[{"host":"www.gnu.org","count":45},{"host":"aip.openatom.tech","count":1},{"host":"www.bzchaxun.com","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/tools/lane-tools.js","pathClass":"source","line":46,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"696d0810fdb846b0407c2923"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/tools/lane-tools.js","pathClass":"source","line":46,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"b7d571fd4d64bda311327830"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/tools/merge-agent.js","pathClass":"source","line":29,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"f4877741aaeb5250c9ca82a8"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"lib/tools/merge-agent.js","pathClass":"source","line":29,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"dc334d1408ef8795f4fe7412"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"presets/jiufeng/agent.cordis.yml","pathClass":"cordis","line":70,"evidence":"!!js process.platform === 'win32'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"9be8b7f3427bdc5eed1a07dd"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"presets/jiufeng/agent.cordis.yml","pathClass":"cordis","line":74,"evidence":"!!js process.platform !== 'win32'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"24c04b1dea7cd8af48919892"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/merge-agent.test.js","pathClass":"test-example-docs","line":30,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"f86968401b218dc57aa93664"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/merge-agent.test.js","pathClass":"test-example-docs","line":30,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"43a545c5e107c51b2ba75344"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/worktree-tools.test.js","pathClass":"test-example-docs","line":30,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"2efad0923f1d00ed07505254"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"low","layer":"static","path":"test/worktree-tools.test.js","pathClass":"test-example-docs","line":30,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","note":"位于测试、示例或文档目录","hash":"5be2fabffc44fe345d6cfb2c"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":53,"evidence":"override: id=agent-instructions name=@deepseek-ai/dsh-agent-instructions config[maxBytes]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 Agent 指令（agent-instructions）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"f7af3f5f27e930492a3bb71a"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":68,"evidence":"override: id=tool-bash name=@deepseek-ai/dsh-tool-bash","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 Bash 工具（tool-bash）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"b2363a3014dcfee0ee77b51f"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":71,"evidence":"override: id=tool-pwsh name=@deepseek-ai/dsh-tool-pwsh","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-pwsh；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"ea09c41525cb84ca9f914094"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":80,"evidence":"override: id=tool-fs name=@deepseek-ai/dsh-tool-fs","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 文件工具（tool-fs）；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"a03be47c6dbab0d8a5d9f90b"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":82,"evidence":"override: id=tool-fs-search name=@deepseek-ai/dsh-tool-fs-search config[sampleOverCapGlobResults]","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-fs-search；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"96ebfeb7fe70babbd1730029"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":97,"evidence":"override: id=tool-jobs name=@deepseek-ai/dsh-tool-jobs","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-jobs；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"4e5d450e63ac7d44aa8af5d3"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":107,"evidence":"override: id=skill-filesystem name=@deepseek-ai/dsh-skill-filesystem","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 skill-filesystem；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"6e8ab3a6ac5fe65cc65a9035"},{"id":"HT-PERMISSION-002","title":"覆盖敏感宿主能力","severity":"medium","confidence":"medium","path":"presets/jiufeng/agent.cordis.yml","line":109,"evidence":"override: id=tool-skill name=@deepseek-ai/dsh-tool-skill","remediation":"安全关键 seam 的替换必须逐项解释、最小化，并接受人工复核；用户安装前应知晓该能力被谁接管。","note":"替换实现 tool-skill；该配置随包分发但未被 dsh.bundle 引用，只有用户手动应用时才生效","layer":"dsh-semantics","pathClass":"cordis","hash":"4c0d8fd4e1fd81d3a9cfda3f"}],"counts":{"critical":0,"high":0,"medium":10,"low":4},"rawCounts":{"critical":0,"high":0,"medium":10,"low":8},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":94,"bytesScanned":737311,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"markdown":17,"cordis":2,"source":44,"data":1,"manifest":1,"yaml":1,"test-example-docs":28}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:38:17.833Z","commit":"86f4b53c59fddcd931f2db767d34fa2eb9399f84","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T13:18:02.235Z","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:45:30.621Z","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:14:15.123Z","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"commit-change","from":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","to":"86f4b53c59fddcd931f2db767d34fa2eb9399f84","commit":"86f4b53c59fddcd931f2db767d34fa2eb9399f84","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:38:17.833Z"},{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.2","at":"2026-08-21T13:18:02.235Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:45:30.621Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"f1a775228aa53f23c0b606009bc9c85c2fdabba3","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T11:14:15.123Z"}]}