{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"q00-ouroboros-integrations-dsh-plugin","slug":"q00-ouroboros-integrations-dsh-plugin","rank":5,"url":"https://github.com/Q00/ouroboros/tree/main/integrations/dsh-plugin","name":"Q00/ouroboros#integrations/dsh-plugin","category":"workflow","description":{"zh":"通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包，在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。","en":"Config-only bundle that mounts Ouroboros through the DSH MCP client, exposing 36 interview, Seed, execution, evaluation, and evolution workflow tools in DSH."},"stars":5611,"starsCheckedAt":"2026-08-21","repository":{"owner":"Q00","repo":"ouroboros","requestedRef":"main","subpath":"integrations/dsh-plugin"},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:Q00/ouroboros#path:/integrations/dsh-plugin","tarball":null,"added":"2026-08-17","page":"https://awesome-dsh-plugin.com/p/Q00/ouroboros--integrations-dsh-plugin/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"q00-ouroboros-integrations-dsh-plugin","slug":"q00-ouroboros-integrations-dsh-plugin","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:19:28.756Z","scanStatus":"static-complete","verdict":"caution","score":95,"commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","commitDate":"2026-08-21T15:04:26+09:00","artifactDigest":"sha256:fe05fbf0ac820a399b9bb5f2baa2796b685b40a6c9a476eacaeca31b511fbb78","downloadUrl":"https://github.com/Q00/ouroboros/archive/645a2f04adc1a8b3ab961cb8856bec06ff3b8325.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:Q00/ouroboros#path:/integrations/dsh-plugin","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-ouroboros","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-ouroboros","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"mcp-ouroboros","name":"@deepseek-ai/dsh-mcp-client","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":6,"clientPlatform":null,"parseErrors":[]},"capabilities":["credentials","environment","host-bundle","mcp"],"outboundHosts":[{"host":"astral.sh","count":1}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":74,"evidence":"!!js process.env.OUROBOROS_LLM_BACKEND ?? ''","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"257d02181f5a023f90403bf9"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":75,"evidence":"!!js process.env.OUROBOROS_AGENT_RUNTIME ?? ''","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"7cf15325fa684483279142b5"}],"counts":{"critical":0,"high":0,"medium":2,"low":0},"rawCounts":{"critical":0,"high":0,"medium":2,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":3,"bytesScanned":12629,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":1,"cordis":1,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:19:28.756Z","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:17:15.420Z","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:43:35.176Z","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:19:28.756Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:17:15.420Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"645a2f04adc1a8b3ab961cb8856bec06ff3b8325","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:43:35.176Z"}]}