dsh-poison-guard-action
by zoahdev
GitHub Action:DeepSeek Harness插件供应链毒扫描(AST + 反混淆)
GitHub Action: supply-chain poison scan for DeepSeek Harness plugins (AST + deobfuscation)
安装
dsh plugin --profile web add github:zoahdev/dsh-poison-guard-actionGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
A GitHub Action that scans a DeepSeek Harness plugin for supply-chain poisoning before you publish or merge — powered by dsh-poison-guard (AST analysis via NodeSecure JS-X-Ray + deobfuscation decoder + regex heuristics).
One line in your workflow turns "it loads" into "it was scanned for obfuscated exfiltration, dynamic eval, hidden shell commands, and install-time scripts".
Usage
name: plugin
on: [push, pull_request]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: zoahdev/dsh-poison-guard-action@v1
with:
path: .
Inputs
| Input | Default | Meaning |
|---|---|---|
path |
. |
Plugin directory to scan |
version |
v0.2.0 |
dsh-poison-guard release tag to install |
fail_on |
MALICIOUS |
Verdict that fails the job (MALICIOUS or SUSPICIOUS) |
Outputs
| Output | Meaning |
|---|---|
verdict |
CLEAN, SUSPICIOUS, or MALICIOUS |
Findings are surfaced as GitHub annotations (::error for HIGH,
::warning for MEDIUM) and written to the run summary.
Why
DeepSeek Harness plugins are distributed as source checkouts, npm packages, and
git tarballs — any of which can carry an obfuscated require, a base64-hidden
exfiltration URL, or a postinstall shell command. This action runs the same
AST + deobfuscation scan a maintainer would run before any user installs the
plugin.
License
MIT
中文说明
一个 GitHub Action,在你的 DeepSeek Harness 插件发布或合并之前做供应链投毒扫描,底层是 dsh-poison-guard(AST 分析 NodeSecure JS-X-Ray + 反混淆解码 + 正则启发式)。
一行配置,把「能加载」变成「被扫描过」:混淆的外发、动态 eval、隐藏的 shell 命令、安装脚本,都会被标出来。
用法
name: plugin
on: [push, pull_request]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: zoahdev/dsh-poison-guard-action@v1
with:
path: .
输入参数
| 参数 | 默认值 | 说明 |
|---|---|---|
path |
. |
要扫描的插件目录 |
version |
v0.2.0 |
安装的 dsh-poison-guard release 标签 |
fail_on |
MALICIOUS |
触发失败的最低级别(MALICIOUS 或 SUSPICIOUS) |
输出
| 输出 | 说明 |
|---|---|
verdict |
CLEAN / SUSPICIOUS / MALICIOUS |
发现的问题会以 GitHub 注解呈现(HIGH→::error,MEDIUM→::warning),并写入运行摘要。
为什么需要它
DeepSeek Harness 插件以源码、npm 包、git tarball 多种形式分发,任何一个都可能夹带混淆的 require、base64 藏的外发 URL、或 postinstall 里的 shell 命令。这个 Action 在用户安装前,先跑一遍维护者会跑的 AST + 反混淆扫描。
许可
MIT
原始 README: https://github.com/zoahdev/dsh-poison-guard-action/blob/main/README.md ↗
同类插件
查看全部 →
k8e
k8e.sh — 开源 Agentic AI 沙箱矩阵

hol-guard
开源AI代理防病毒:运行时拦截风险工具、秘密访问、提示注入、恶意软件包、MCP服务器、插件和技能。

anolisa
ANOLISA(Agentic Nexus Operating Layer & Interface System Architecture):具备运行时、安全性、可观测性和 Tokenless 响应压缩能力的 Agentic OS,可降低 Token 使用量与成本。

mobius
首个自我演进的开源 Agent OS:连接你的团队、AI agent、设备与算力

deepseek-harness-desktop
DeepSeek Harness Tauri 桌面版 | Only 5mb installer, zero environment setup. Windows / macOS / Linux.

open-managed-agents
开源Claude管理代理API实现和自托管Claude标签式代理运行时。即插即用;在Cloudflare Workers/Durable Objects或Node.js上运行。Apache 2.0。