{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"saya-ch-dsh-mobile","slug":"saya-ch-dsh-mobile","rank":64,"url":"https://github.com/saya-ch/dsh-mobile","name":"saya-ch/dsh-mobile","category":"remote","description":{"zh":"在手机上通过受保护的局域网使用 DeepSeek Harness：专属移动界面、安全 HTTPS 配对，以及 /mobile 对话定制。","en":"Use DeepSeek Harness from your phone over a protected LAN: a dedicated mobile UI, secure HTTPS pairing, and /mobile conversation customization."},"stars":97,"starsCheckedAt":"2026-08-21","repository":{"owner":"saya-ch","repo":"dsh-mobile","requestedRef":null,"subpath":""},"npm":"dsh-mobile","downloads":5660,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-mobile","tarball":null,"added":"2026-08-19","page":"https://awesome-dsh-plugin.com/p/saya-ch/dsh-mobile/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"saya-ch-dsh-mobile","slug":"saya-ch-dsh-mobile","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:20:22.049Z","scanStatus":"static-complete","verdict":"pass","score":98,"commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","commitDate":"2026-08-19T12:56:23+08:00","artifactDigest":"sha256:b086b2565c6eba813342d7f682d0ef111c37f88d0a110f8e8eb0d5b766f67eed","downloadUrl":"https://github.com/saya-ch/dsh-mobile/archive/218cd8b470cdbd43fc44db2219fd950ab3d743b9.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-mobile","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-mobile","packageVersion":"0.1.0-alpha.36","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-sidebar"],"immediately":true},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-commands","@deepseek-ai/dsh-host-webserver","@deepseek-ai/dsh-llm"]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-mobile","manifestName":"dsh-mobile","nameMatch":true,"npm":{"name":"dsh-mobile","latestVersion":"0.1.0-alpha.24","publishedAt":"2026-08-17T18:03:51.176Z","createdAt":"2026-08-15T06:45:44.973Z","versionCount":36,"maintainers":1,"repository":"git+https://github.com/saya-ch/dsh-mobile.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"directory-picker-mobile-host","name":"@deepseek-ai/dsh-host-directory-picker-browse","path":"cordis.patch.yml","disabled":false},{"id":"directory-picker-mobile-surface","name":"@deepseek-ai/dsh-client-ui-directory-picker-browse","path":"cordis.patch.yml","disabled":false},{"id":"mobile-access","name":"dsh-mobile","path":"cordis.patch.yml","disabled":false}],"overrides":[{"id":"directory-picker","tier":"normal","mode":"override","disabled":true,"replacesImplementation":true,"name":"@deepseek-ai/dsh-host-directory-picker-auto","keys":[],"path":"cordis.patch.yml"}],"jsExpressions":5,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","environment","filesystem","host-bundle","network","subprocess","telemetry"],"outboundHosts":[{"host":"gateway.invalid","count":1}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"low","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":18,"evidence":"!!js dshHomePath('mobile-access/setup.json')","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","hash":"917975af60156ae09e70653d"},{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"low","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":19,"evidence":"!!js dshHomePath('mobile-access/devices.json')","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","hash":"07dc5edfb650f93d501d8b24"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/cli.ts","pathClass":"source","line":2,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"93b630cc391cd66bd8db8ef7"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/managed-setup.ts","pathClass":"source","line":6,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"acf98c98a2f6ebd0ea98e9c0"},{"id":"HT-RUNTIME-001","title":"动态代码执行","severity":"high","confidence":"low","layer":"static","path":"tests/gateway.test.ts","pathClass":"test-example-docs","line":724,"evidence":"new Function(","remediation":"使用静态模块和受约束的配置解析器，避免在宿主权限下执行动态字符串。","note":"位于测试、示例或文档目录","hash":"c50649e8d20821097d08bb5e"}],"counts":{"critical":0,"high":0,"medium":0,"low":4},"rawCounts":{"critical":0,"high":1,"medium":0,"low":4},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":52,"bytesScanned":556522,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"test-example-docs":16,"markdown":7,"data":3,"cordis":1,"manifest":1,"source":24}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:20:22.049Z","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:19:19.717Z","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:47:05.483Z","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:20:22.049Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:19:19.717Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"218cd8b470cdbd43fc44db2219fd950ab3d743b9","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:47:05.483Z"}]}