{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"taxueseek-dsh-files","slug":"taxueseek-dsh-files","rank":196,"url":"https://github.com/taxueseek/dsh-files","name":"taxueseek/dsh-files","category":"ui","description":{"zh":"文件上传（彩色附件卡片、会话隔离存储、sha256 去重、TTL 清扫）+ 内容嗅探的 read_document 文档读取（PDF/DOCX/XLSX/TXT）。","en":"File upload with color-coded attachment cards (session-isolated storage, sha256 dedup, TTL sweep) plus a content-sniffing read_document tool for PDF/DOCX/XLSX/TXT."},"stars":18,"starsCheckedAt":"2026-08-21","repository":{"owner":"taxueseek","repo":"dsh-files","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:taxueseek/dsh-files","tarball":null,"added":"2026-08-14","page":"https://awesome-dsh-plugin.com/p/taxueseek/dsh-files/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"taxueseek-dsh-files","slug":"taxueseek-dsh-files","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:22:08.144Z","scanStatus":"static-complete","verdict":"review","score":83,"commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","commitDate":"2026-08-19T17:20:52+08:00","artifactDigest":"sha256:63b59f274e4ce2d42fd8af20d964479ba5abfdfc567bbd8d10d7203f1419601e","downloadUrl":"https://github.com/taxueseek/dsh-files/archive/888b9ea8e7d86ffdc0054afdbc88704133f6c187.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:taxueseek/dsh-files","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-files","packageVersion":"0.2.0","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-runtime"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-fs","@deepseek-ai/dsh-tools","@deepseek-ai/schemastery"]},"identity":{"status":"found","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-files","nameMatch":null,"npm":{"name":"dsh-files","latestVersion":"0.0.1","publishedAt":"2026-08-19T07:03:34.210Z","createdAt":"2026-08-19T07:03:33.840Z","versionCount":1,"maintainers":1,"repository":"git+https://github.com/dushaobindoudou/dsh-files.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"mismatch","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"files-toolkit","name":"dsh-files","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","filesystem","host-bundle","network","session"],"outboundHosts":[],"findings":[{"id":"HT-IDENTITY-001","title":"npm 上存在同名包但指向其他仓库","severity":"low","confidence":"medium","path":"package.json","pathClass":"manifest","line":1,"evidence":"npm repository=git+https://github.com/dushaobindoudou/dsh-files.git ≠ taxueseek/dsh-files","remediation":"npm 上存在同名包但指向其它仓库；从源码安装时请使用 github: 引用并锁定 commit。","layer":"identity","hash":"e55a780913c18c69d66d92ce"},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-jf85-cpcp-j695 (CVE-2019-10744) fixed in 4.17.12","remediation":"升级 lodash 至 4.17.12 或更高版本。","layer":"vulnerability","hash":"d8f9108ff3cac0fd59c3d6a7","review":{"verdict":"unclear","reason":"给出的pnpm-lock.yaml片段仅含importers顶层直接依赖(1-41行)，未见packages区块中lodash@3.2.0的实际锁定条目，无法验证该传递依赖是否真实存在。","model":"sonnet","reviewedAt":"2026-08-21T10:49:53.375Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-35jh-r3h4-6jhm (CVE-2021-23337) fixed in 4.17.21","remediation":"升级 lodash 至 4.17.21 或更高版本。","layer":"vulnerability","hash":"b2d1dd15951c04e08403c5ec","review":{"verdict":"unclear","reason":"同上，命中引用的lockfile内容未展示lodash相关行，无法确认该CVE对应的lodash@3.2.0是否确为解析后的依赖版本。","model":"sonnet","reviewedAt":"2026-08-21T10:49:53.375Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"high","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-4xc9-xhrj-v574 (CVE-2018-16487) fixed in 4.17.11","remediation":"升级 lodash 至 4.17.11 或更高版本。","layer":"vulnerability","hash":"256ab9804951ee7c939ebe42","review":{"verdict":"unclear","reason":"三条finding均指向同一片段且均不含lodash字样，缺乏packages:锁定区证据，无法判断该传递依赖及其风险是否成立。","model":"sonnet","reviewedAt":"2026-08-21T10:49:53.375Z"}},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"medium","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-f23m-r3pf-42rh (CVE-2025-13465) fixed in 4.18.0","remediation":"升级 lodash 至 4.18.0 或更高版本。","layer":"vulnerability","hash":"8c6bbe005663088a4a2deefb"},{"id":"HT-VULN-001","title":"依赖存在已知漏洞","severity":"medium","confidence":"medium","path":"pnpm-lock.yaml","pathClass":"manifest","line":1,"evidence":"lodash@3.2.0 GHSA-fvqr-27wr-82fm (CVE-2018-3721) fixed in 4.17.5","remediation":"升级 lodash 至 4.17.5 或更高版本。","layer":"vulnerability","hash":"9edd28e36d0751c01f3b24e0"}],"counts":{"critical":0,"high":3,"medium":2,"low":1},"rawCounts":{"critical":0,"high":3,"medium":2,"low":1},"vulnerabilities":[{"id":"GHSA-jf85-cpcp-j695","aliases":["CVE-2019-10744"],"package":"lodash","version":"3.2.0","severity":"critical","fixed":"4.17.12","summary":"Prototype Pollution in lodash"},{"id":"GHSA-35jh-r3h4-6jhm","aliases":["CVE-2021-23337","CVE-2026-4800","GHSA-r5fr-rjxr-66jc"],"package":"lodash","version":"3.2.0","severity":"high","fixed":"4.17.21","summary":"Command Injection in lodash"},{"id":"GHSA-4xc9-xhrj-v574","aliases":["CVE-2018-16487"],"package":"lodash","version":"3.2.0","severity":"high","fixed":"4.17.11","summary":"Prototype Pollution in lodash"},{"id":"GHSA-f23m-r3pf-42rh","aliases":["CVE-2025-13465","CVE-2026-2950","GHSA-xxjr-mmjv-4gpg"],"package":"lodash","version":"3.2.0","severity":"medium","fixed":"4.18.0","summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`"},{"id":"GHSA-fvqr-27wr-82fm","aliases":["CVE-2018-3721"],"package":"lodash","version":"3.2.0","severity":"medium","fixed":"4.17.5","summary":"Prototype Pollution in lodash"}],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"complete","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":37,"bytesScanned":240842,"truncated":false,"lockfiles":["pnpm-lock.yaml"],"pathClasses":{"test-example-docs":5,"markdown":2,"source":25,"cordis":1,"manifest":1,"yaml":1,"data":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"],"review":{"model":"sonnet","reviewedAt":"2026-08-22T08:22:08.144Z","summary":null,"intentMatch":null,"findingsReviewed":3,"findingsCandidates":3,"fromCache":3,"usage":null}},"timeline":[{"scannedAt":"2026-08-22T08:22:08.144Z","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.2","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T11:21:40.800Z","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.1","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T10:49:53.375Z","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.0","verdict":"review","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:22:08.144Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:21:40.800Z"},{"kind":"first-scan","from":null,"to":"review","commit":"888b9ea8e7d86ffdc0054afdbc88704133f6c187","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:49:53.375Z"}]}