{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"springbrand-lab-dsh-plugin-market","slug":"springbrand-lab-dsh-plugin-market","rank":328,"url":"https://github.com/springbrand-lab/dsh-plugin-market","name":"springbrand-lab/dsh-plugin-market","category":"market","description":{"zh":"设置页里的插件市场，可操作本机任意 profile 而不只是当前运行的那个：在 web、headless 及其他 profile 上安装、更新、卸载，带安装脚本风险提示，已装视图同时覆盖目录之外的 profile 依赖，改动当前 profile 时自动重启 DSH。","en":"Plugin marketplace in Settings that targets any local profile, not just the running one: install, update and remove across web, headless and other profiles, with install-script warnings, an installed view that also covers non-catalog profile dependencies, and an automatic DSH restart when the current profile changes."},"stars":8,"starsCheckedAt":"2026-08-21","repository":{"owner":"springbrand-lab","repo":"dsh-plugin-market","requestedRef":null,"subpath":""},"npm":"@springbrand/dsh-plugin-marketplace","downloads":1497,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add @springbrand/dsh-plugin-marketplace","tarball":null,"added":"2026-08-17","page":"https://awesome-dsh-plugin.com/p/springbrand-lab/dsh-plugin-market/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"springbrand-lab-dsh-plugin-market","slug":"springbrand-lab-dsh-plugin-market","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:23:47.041Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","commitDate":"2026-08-18T20:07:40+08:00","artifactDigest":"sha256:1b8bb171edc932e7105b59a2f75cfee12af0f9d93ed2271f1801d6d6cf1c5027","downloadUrl":"https://github.com/springbrand-lab/dsh-plugin-market/archive/183527a7c700ed2fb2f2698197756fec9227a6d4.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add @springbrand/dsh-plugin-marketplace","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"@springbrand/dsh-plugin-marketplace","packageVersion":"1.0.8","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-settings"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis"]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"@springbrand/dsh-plugin-marketplace","manifestName":"@springbrand/dsh-plugin-marketplace","nameMatch":true,"npm":{"name":"@springbrand/dsh-plugin-marketplace","latestVersion":"1.0.8","publishedAt":"2026-08-18T12:07:58.184Z","createdAt":"2026-08-16T16:22:09.258Z","versionCount":8,"maintainers":1,"repository":"git+https://github.com/springbrand-lab/dsh-plugin-market.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"springbrand-plugin-marketplace","name":"@springbrand/dsh-plugin-marketplace","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["browser-ui","environment","filesystem","host-bundle","mcp","network","subprocess"],"outboundHosts":[{"host":"dshplugin.market","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/command.ts","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"a31448e91f1263e185f99382"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/restart.ts","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1ef327e3a97e753d03add69e"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/restart.ts","pathClass":"source","line":4,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"1ef327e3a97e753d03add69e"}],"counts":{"critical":0,"high":0,"medium":0,"low":3},"rawCounts":{"critical":0,"high":0,"medium":0,"low":3},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":30,"bytesScanned":233816,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"test-example-docs":7,"markdown":2,"source":16,"cordis":1,"data":3,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:23:47.041Z","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:23:32.743Z","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:52:14.612Z","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:23:47.041Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:23:32.743Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"183527a7c700ed2fb2f2698197756fec9227a6d4","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:52:14.612Z"}]}