{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"xmanrui-dsh-im","slug":"xmanrui-dsh-im","rank":27,"url":"https://github.com/xmanrui/dsh-im","name":"xmanrui/dsh-im","category":"notify","description":{"zh":"通过二维码或机器人凭据将 IM 机器人接入 DeepSeek Harness（支持飞书、微信、钉钉、企业微信、QQ、Slack、Telegram、Discord 和 WhatsApp 共 9 种渠道）。","en":"Connect IM bots to DeepSeek Harness via QR codes or bot credentials (9 channels: Feishu, WeChat, DingTalk, WeCom, QQ, Slack, Telegram, Discord, and WhatsApp)."},"stars":431,"starsCheckedAt":"2026-08-21","repository":{"owner":"xmanrui","repo":"dsh-im","requestedRef":null,"subpath":""},"npm":"@xmanrui/dsh-im","downloads":3929,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add @xmanrui/dsh-im","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/xmanrui/dsh-im/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"xmanrui-dsh-im","slug":"xmanrui-dsh-im","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:19:46.659Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"f7d2fe70472bed8c0e66aaad47631ab1fb137f2f","commitDate":"2026-08-22T14:45:25+08:00","artifactDigest":"sha256:5a91ffb1dec46f82ae07921cdaa9107035033f9b13abea31be8a11324e8802d5","downloadUrl":"https://github.com/xmanrui/dsh-im/archive/f7d2fe70472bed8c0e66aaad47631ab1fb137f2f.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add @xmanrui/dsh-im","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"@xmanrui/dsh-im","packageVersion":"1.0.1","bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-client-connection","@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-ui-slots","@deepseek-ai/dsh-client-locale"],"platform":"web"},"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"@xmanrui/dsh-im","manifestName":"@xmanrui/dsh-im","nameMatch":true,"npm":{"name":"@xmanrui/dsh-im","latestVersion":"0.17.0","publishedAt":"2026-08-21T09:00:26.157Z","createdAt":"2026-08-16T07:09:05.381Z","versionCount":22,"maintainers":1,"repository":"git+https://github.com/xmanrui/dsh-im.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"differs"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"xmanrui-dsh-im","name":"@xmanrui/dsh-im","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["browser-ui","credentials","environment","filesystem","host-bundle","network","session","subprocess"],"outboundHosts":[{"host":"office.example.com","count":2},{"host":"api.slack.com","count":2},{"host":"oapi.dingtalk.com","count":2},{"host":"api.dingtalk.com","count":2},{"host":"work.weixin.qq.com","count":2},{"host":"discord.com","count":1},{"host":"open.larksuite.com","count":1},{"host":"open.feishu.cn","count":1},{"host":"slack.com","count":1},{"host":"api.telegram.org","count":1},{"host":"ilinkai.weixin.qq.com","count":1},{"host":"novac2c.cdn.weixin.qq.com","count":1}],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"bin/dsh-im.mjs","pathClass":"source","line":6,"evidence":"spawnSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"a283ab3cff1b2f907540110a"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"bin/dsh-im.mjs","pathClass":"source","line":6,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"d690bc08ffd6205a9f7f50bd"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/channels/feishu/config.mjs","pathClass":"source","line":1,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"472d756d1e57599047042b86"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/channels/feishu/config.mjs","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"d7338db796dcbd3421196a9d"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"src/channels/shared/harness-client.mjs","pathClass":"source","line":1,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"fa0f4907954abe6ea2b2ffb0"},{"id":"HT-CLIENT-001","title":"浏览器端使用危险 HTML 注入点","severity":"medium","confidence":"low","layer":"static","path":"test/channels/dingtalk/client-ui.test.mjs","pathClass":"test-example-docs","line":28,"evidence":"dangerouslySetInnerHTML","remediation":"使用安全 DOM API，并在不可避免时对不可信内容进行严格清洗。","note":"位于测试、示例或文档目录","hash":"d35942d58f7c9f382eba3ce8"}],"counts":{"critical":0,"high":0,"medium":0,"low":5},"rawCounts":{"critical":0,"high":0,"medium":1,"low":5},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-present","vulnerabilities":"complete","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":291,"bytesScanned":3638870,"truncated":false,"lockfiles":["package-lock.json"],"pathClasses":{"markdown":3,"source":195,"cordis":1,"data":2,"manifest":1,"test-example-docs":89}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:19:46.659Z","commit":"f7d2fe70472bed8c0e66aaad47631ab1fb137f2f","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:18:32.377Z","commit":"7fbb459e00c1335f99703da8229cc138da88a0c0","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:46:21.909Z","commit":"c3b3a29f27ed3807709c887251ab322494357869","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"f7d2fe70472bed8c0e66aaad47631ab1fb137f2f","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:19:46.659Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"7fbb459e00c1335f99703da8229cc138da88a0c0","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:18:32.377Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"c3b3a29f27ed3807709c887251ab322494357869","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:46:21.909Z"}]}