Replies: 1 comment
|
???????????:??????????????(dsh-plugin-certification v1) ???? Fz0x00 ???????????--"???????????"???????????? ?????????????????????????:
??????????:
????:A community certification draft for DSH plugins - five machine-checkable dimensions (manifest hygiene, build hygiene, OpenSSF Scorecard, npm provenance, isolated install smoke) with A-D grades and a security veto, backed by an independent daily-refreshed registry and badges. Feedback on thresholds and governance welcome. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi maintainers & community 👋
We conducted a third-party, defensive security audit of DeepSeek Harness (dsh) focused on the "plugins as capability providers" model, and are publishing the complete deliverable: report, evidence appendices, 13 reproducible demos, and live-verification artifacts.
Full report repo: https://github.com/Fz0x00/deepseek-harness-plugin-security-audit
What was audited
deepseek-ai/deepseek-harness@47f9438(pinned submodule; every claim carries a file:line citation)@deepseek-ai/dsh@0.1.0-rc.6, run only in isolatedDSH_HOMEdirectoriesHeadline finding
dsh has two trust axes, and they are sharply asymmetric:
Verified end to end against the official rc.6 release
!!jsconfiguration-as-code = host-level RCE at load time (PWNED-BY-LIVE-JS)dsh plugin removedoes not remove a persisted!!jsbackdoor; user-patch hot reload takes effect in ~15 s without restartsession.promptaccepts forged input (agent action still requires a model in the loop)AGENTS.md/ project-skill instruction injection fires with no install, no approval, no warning (L0 prerequisite) — baseline and skill-catalog injection both live-verifiedWhat the report contains
demos/), 8+2 live verifications with artifacts (evidence/live-test/).envbootstrap guard list, loopback pinning of privileged RPC methods — all real mitigations and acknowledged as suchREPORT.md§9: supply-chain pinning, install/update confirmation gates, treating telemetry exporter URL as sensitive, instruction/skill injection labeling, and a long-term declarative permission layerMethod & ethics
.pocsuffix or local-collector-only, no credential contents read, redacted evidence)DSH_HOMEdirs and loopback endpoints; nothing touched real deploymentsFeedback is very welcome — especially on which findings already exist on your roadmap, and where our reading of the design intent could be more precise.
All reactions