Developer Toolsdsh-plugin

dsh-plugin-vet

A trust-layer plugin for deepseek-harness (DSH) that covers a download → scan → audit → score → decide → runtime-watch pipeline: a deterministic static scan (11 rules), an LLM-driven audit protocol, a two-part scorecard, an optional runtime guard (T1 sentinel plus T2 fs and child_process hooks) and optional honeypot decoys. Monitor-and-alert only — vet never blocks or kills on its own in the default configuration.

Stars
3
Forks
1
Open issues
0
Last push
Sep 24, 2026
Latest release
—
24h Growth
+0
7d Growth
+0

Installation

dsh plugin --profile <profile> add @jieai/dsh-plugin-vet

Overview

A trust-layer plugin for deepseek-harness (DSH) that covers a download → scan → audit → score → decide → runtime-watch pipeline: a deterministic static scan (11 rules), an LLM-driven audit protocol, a two-part scorecard, an optional runtime guard (T1 sentinel plus T2 fs and child_process hooks) and optional honeypot decoys. Monitor-and-alert only — vet never blocks or kills on its own in the default configuration.

  • Deterministic static scan with 11 configurable rules (R1-R20) produces a deterministic, unforgeable verdict.
  • Agent-side audit of sensitive points and quality issues follows the vet-audit-protocol skill.
  • A final two-part scorecard is handed to a human or model to decide disposition.
  • Optional runtime guard adds a T1 sentinel (memory/fd/child-process monitoring) plus T2 fs, child_process and network hooks.
  • Optional honeypot lures plant fake credential files; T2 reports touches (read/write/delete) as a separate honeypot alarm class.
  • Default mode is report: vet never auto-uninstalls, never kills processes, never rewrites configs and blocks nothing.
  • Safety tiers standard, hardened and paranoid; deny mode and the N7 confirmation block are explicit opt-ins.
  • Includes OSV exact-version queries, an official-package content-hash baseline and runtime contract snapshots.

Related plugins