dsh-plugin-development

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches templates and source code from the official DeepSeek Harness repository on GitHub for analysis and local plugin development.
  • [COMMAND_EXECUTION]: Instructs the use of standard development tools including git for repository synchronization, pnpm for dependency management and build script execution, and a specialized dsh CLI for profile management.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface by analyzing external codebases and configuration files, which could theoretically contain malicious instructions.
  • Ingestion points: External Git repositories and local configuration files like package.json and cordis.patch.yml (SKILL.md).
  • Boundary markers: None implemented in instructions; relies on the user to manually verify content.
  • Capability inventory: Full shell access to execute git, pnpm, and dsh commands.
  • Sanitization: None; the skill explicitly warns the user to only trust and审查 (review) repositories before enabling build scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:23 PM