{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"zhenyu98-dsh-context-doctor","slug":"zhenyu98-dsh-context-doctor","rank":197,"url":"https://github.com/Zhenyu98/dsh-context-doctor","name":"Zhenyu98/dsh-context-doctor","category":"dev","description":{"zh":"上下文注入审计：统计指令链/技能目录/工具 schema 的 token 成本，检测重复与冲突。","en":"Context injection audit: token costs of instruction chains / skill catalogs / tool schemas, duplicate and conflict detection."},"stars":18,"starsCheckedAt":"2026-08-21","repository":{"owner":"Zhenyu98","repo":"dsh-context-doctor","requestedRef":null,"subpath":""},"npm":null,"downloads":null,"installMode":"github-source","upstreamInstall":"dsh plugin --profile web add github:Zhenyu98/dsh-context-doctor","tarball":null,"added":"2026-08-13","page":"https://awesome-dsh-plugin.com/p/Zhenyu98/dsh-context-doctor/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"zhenyu98-dsh-context-doctor","slug":"zhenyu98-dsh-context-doctor","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:22:08.475Z","scanStatus":"static-complete","verdict":"pass","score":99,"commit":"f45096dc7a7ad52cfa7cf32cdaccae717faa662d","commitDate":"2026-08-22T14:57:38+08:00","artifactDigest":"sha256:e911ae0c59167443d0e6d8882ecdde507ce75c781ebe6f72879350bba0bda9d0","downloadUrl":"https://github.com/Zhenyu98/dsh-context-doctor/archive/f45096dc7a7ad52cfa7cf32cdaccae717faa662d.tar.gz","installMode":"github-source","installCommand":"dsh plugin --profile web add github:Zhenyu98/dsh-context-doctor","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-context-doctor","packageVersion":"0.6.1","bundle":{"patch":"./cordis.patch.yml"},"client":{"platform":"web","inject":["@deepseek-ai/dsh-client-runtime","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-slots","@deepseek-ai/dsh-client-ui-conversation"]},"lifecycleScripts":{},"peerDependencies":["@deepseek-ai/cordis","@deepseek-ai/dsh-tools"]},"identity":{"status":"not-published","installMode":"github-source","upstreamNpm":null,"manifestName":"dsh-context-doctor","nameMatch":null,"npm":null,"repositoryMatch":"not-checked","provenance":"not-checked","tarballHost":null},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"context-doctor","name":"dsh-context-doctor","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":0,"clientPlatform":"web","parseErrors":[]},"capabilities":["agent-control","browser-ui","environment","filesystem","host-bundle","mcp","network","subprocess"],"outboundHosts":[],"findings":[{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/setup-dsh-deps.mjs","pathClass":"source","line":21,"evidence":"execFileSync","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"d9a0aeea9020cddbb50f8e54"},{"id":"HT-EXEC-001","title":"直接创建宿主子进程","severity":"low","confidence":"medium","layer":"static","path":"scripts/setup-dsh-deps.mjs","pathClass":"source","line":21,"evidence":"node:child_process","remediation":"通过 DSH 的受控 subprocess/shell seam 执行，并公开命令、参数及审批策略。","hash":"9624a14da6edc67e8605f4d3"}],"counts":{"critical":0,"high":0,"medium":0,"low":2},"rawCounts":{"critical":0,"high":0,"medium":0,"low":2},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":48,"bytesScanned":275030,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":2,"cordis":1,"source":35,"manifest":1,"script":1,"test-example-docs":6,"data":2}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:22:08.475Z","commit":"f45096dc7a7ad52cfa7cf32cdaccae717faa662d","policyVersion":"HT-DSH-0.2.2","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T11:21:48.470Z","commit":"042ea0f88dc3e477172ce3defc26c31cd02f85b9","policyVersion":"HT-DSH-0.2.1","verdict":"pass","status":"static-complete"},{"scannedAt":"2026-08-21T10:50:00.300Z","commit":"042ea0f88dc3e477172ce3defc26c31cd02f85b9","policyVersion":"HT-DSH-0.2.0","verdict":"pass","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"f45096dc7a7ad52cfa7cf32cdaccae717faa662d","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:22:08.475Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"042ea0f88dc3e477172ce3defc26c31cd02f85b9","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:21:48.470Z"},{"kind":"first-scan","from":null,"to":"pass","commit":"042ea0f88dc3e477172ce3defc26c31cd02f85b9","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:50:00.300Z"}]}