{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"wenzetan-dsh-llm-newapi","slug":"wenzetan-dsh-llm-newapi","rank":545,"url":"https://github.com/wenzetan/dsh-llm-newapi","name":"wenzetan/dsh-llm-newapi","category":"model","description":{"zh":"NewAPI（OpenAI 兼容网关）模型接入：注册 `newapi` 路由，仅发现聊天类模型，自动从 models.dev 获取模型参数（上下文窗口、思考强度等）并填充，并在 Web 设置页配置 base URL 与 API Key。","en":"NewAPI (OpenAI-compatible gateway) LLM provider: registers a `newapi` route with chat-only model discovery, auto-fills model parameters (context window, reasoning effort) from models.dev, and adds a Web settings section for the base URL and API key."},"stars":5,"starsCheckedAt":"2026-08-21","repository":{"owner":"wenzetan","repo":"dsh-llm-newapi","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:wenzetan/dsh-llm-newapi","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/wenzetan/dsh-llm-newapi/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"wenzetan-dsh-llm-newapi","slug":"wenzetan-dsh-llm-newapi","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:26:01.124Z","scanStatus":"static-complete","verdict":"review","score":84,"commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","commitDate":"2026-08-18T03:19:23Z","artifactDigest":"sha256:0b30771eef9278e9887a8ab5ae2a07873762702bbf3463b471deea4ec60e5ea5","downloadUrl":"https://github.com/wenzetan/dsh-llm-newapi/archive/ff24e65bba30df09360fb28c7c11c3e06567fcc9.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:wenzetan/dsh-llm-newapi","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-llm-newapi","packageVersion":"0.8.3","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-settings"]},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-credentials","@deepseek-ai/dsh-launch-environment","@deepseek-ai/dsh-llm","@deepseek-ai/dsh-settings","@deepseek-ai/dsh-timeout","@deepseek-ai/schemastery"]},"identity":{"status":"found","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-llm-newapi","nameMatch":null,"npm":{"name":"dsh-llm-newapi","latestVersion":"0.8.3","publishedAt":"2026-08-18T03:21:22.075Z","createdAt":"2026-08-15T07:04:23.633Z","versionCount":5,"maintainers":1,"repository":null,"hasInstallScripts":false,"deprecated":false},"repositoryMatch":"missing","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"llm-newapi","name":"dsh-llm-newapi","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","credentials","environment","filesystem","host-bundle","network","subprocess","telemetry"],"outboundHosts":[{"host":"models.dev","count":11},{"host":"gw.local","count":6},{"host":"newapi.example.com","count":5}],"findings":[{"id":"HT-DATA-001","title":"同一模块同时接触凭据与网络","severity":"high","confidence":"medium","layer":"static","path":"lib/index.js","pathClass":"source","line":898,"evidence":"credential access at line 898 + outbound network at line 519","remediation":"拆分能力边界，限定目的域名，并提供不会发送凭据值的可验证证明。","hash":"0e345e962bab80d25a09f98e"}],"counts":{"critical":0,"high":1,"medium":0,"low":0},"rawCounts":{"critical":0,"high":1,"medium":0,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"failed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":34,"bytesScanned":557172,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"test-example-docs":3,"markdown":3,"cordis":1,"source":23,"data":3,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:26:01.124Z","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.2","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T11:27:24.562Z","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.1","verdict":"review","status":"static-complete"},{"scannedAt":"2026-08-21T10:56:22.804Z","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:26:01.124Z"},{"kind":"verdict-change","from":"caution","to":"review","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:27:24.562Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"ff24e65bba30df09360fb28c7c11c3e06567fcc9","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:56:22.804Z"}]}