Skip to main content

dsh-plugin-healthcheck

14Stars0Forks2Issues0Watchers

Checks installed plugins for stability and security, detecting potential crashes or embedded malware.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
JavaScript
License
MIT
Branch
main
dshdsh-plugindsh-pluginsdsharpplus

Install

cmdweb profile
$ dsh plugin --profile web add --allow-build=dsh-plugin-healthcheck github:chenw2759-wq/dsh-plugin-healthcheck

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin chenw2759-wq/dsh-plugin-healthcheck for me: review the repository at https://github.com/chenw2759-wq/dsh-plugin-healthcheck first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

一句话定位

DSH 插件装好之后还没重启后端之前的体检:扫 files 白名单/依赖副本/lockfile/Windows 命令/恶意代码、组合配置层、在隔离子进程里完整 boot 整个 profile tree。发现即给出修复——自动改代码、删危险副本、写禁用行热回滚,或把修复提示词打包交给 agent。

核心能力

  • 提供「插件检测」面板入口(设置左下角的 settings 插槽),可视化选作用域和层级、跑检测、看结果、回滚、看历史
  • L0 静态检查 7 项:C1 files 白名单 / C2 依赖声明 / C3 高危副本(cordis 等 6 个 harness 核心包)/ C4 依赖可解析 / C5 Windows 命令(在注册表 PATH 找 .exe)/ C6 lockfile 一致性 / C7 禁用插件
  • L0 静态检查 C9:扫描 cordis 用法错误(异步 plugin 后同步取服务、new Service 缺 config、inject 缺服务声明),毫秒级预先抓 cannot get property X without inject 类崩溃
  • L1 配置组合:用基座自己的 composeEntries 算法组合 bundle+profile+home 补丁层,找补丁语法错、id 冲突、补丁跳失
  • L2 隔离试跑:在子进程里 boot() 整个 profile tree(端口覆写到 0),90s 超时抓 hang;失败自动回滚(HMR 热生效)
  • C8 木马扫描:纯静态(只 readFile,绝不 import/require/spawn),覆盖 7 类恶意模式(下载执行/凭据窃取/外联回传/混淆后门/持久化/破坏性/环境劫持),强组合命中升级为 error,密钥/令牌自动脱敏

技术实现

  • 语言: TypeScript(host 半 + client 半双程序,tsconfig.host.json + 浏览器构建走 tsdown)
  • 关键依赖: @deepseek-ai/cordis(patch 注入)/ @deepseek-ai/dsh-host-webserver(路由宿主)/ @deepseek-ai/dsh-app-boot(L1/L2 调用基座 boot 算法)/ js-yaml + @deepseek-ai/cordis-plugin-include(patch 文件读写与校验)
  • 架构模式: 双面插件——通过 cordis.patch.yml 在 web profile 注入一行 dsh-plugin-healthcheck,host 半注册 /healthcheck/* HTTP 路由(inject: webServer, systemPrompt),client 半通过 package.json 的 dsh.client 字段在 Web GUI 注册 settings.section 插槽(inject: slots, locale)
  • 入口文件: src/index.ts(host 半 apply)/ src/client/index.ts(client 半 apply)/ src/host/runner.ts(L2 子进程 lib/runner.js 入口)

适用场景

装完新插件但还不想立刻重启后端的窗口期里跑一次验证,或线上排查“装了某个插件之后端就起不来”的事故根因。也适合在自定义插件发版前自检,CI 里抓“hash chunk 漏发”“file: 装出核心包副本”“lockfile 没重解析”这类常见坑。

前置依赖与兼容性

依赖最低版本说明
DSH(@deepseek-ai/cordis)^4.0.1由宿主提供,plugin 通过 cordis.patch.yml 注入
@deepseek-ai/dsh-host-webserver^0.1.0-rc.6提供 webServer 路由宿主
@deepseek-ai/dsh-system-prompt^0.1.0-rc.6用于给模型发“插件检测”面板通告
@deepseek-ai/dsh-app-boot^0.1.0-rc.6L1 配置组合复用基座 composeEntries,L2 子进程 boot() 复用其 boot 与 assertEntriesActivated
@deepseek-ai/dsh-client-runtime^0.1.0-rc.6browser 半需要的 client 上下文(type-only import)
@deepseek-ai/dsh-client-ui-settings^0.1.0-rc.6拉 settings.section 插槽的 SlotMap 合并类型
@deepseek-ai/dsh-client-locale^0.1.0-rc.6中英文案注册依赖
react^18.2.0client 半 UI 渲染依赖
Node.js未声明package.json 未声明 engines
平台macOS / Windows / Linux跨平台;C5 Windows 命令检查仅在 win32 平台生效
原生模块无仅依赖 Node 内置 API(fs/path/http/child_process)

安装方式

dsh plugin --profile web add github:chenw2759-wq/dsh-plugin-healthcheck

配置项

本插件无需额外配置。运行参数全部通过 /healthcheck/* HTTP 路由的请求体传入(无需写到 DSH profile 设置里):

配置(请求体字段)类型说明默认值
layersstring[]选跑的层级,必须是 l0 / l1 / l2 / malware 的子集;空数组或省略则跑全部 4 层全部 4 层
profilestring被检测的 profile 名(home/profiles/)web
pluginstring只测一个插件:填它的包名(含未安装的内置包会从安装 scope 自动兜底)全部插件
confirmedboolean(必填)走 /healthcheck/repair 或 /healthcheck/rollback 时必须为 true;panel 二次确认后才会带这个字段提交无,缺这个字段直接 400
repairobject一键修复的具体动作(kind: 'files-whitelist' | 'remove-copies' | 'none'),由 L0 finding 自带无

常见问题

Q: 它会修改装好的插件或宿主后端吗?

A: 只在三类路径下写:插件源码目录、profile 配置层、home 补丁文件。修复执行器对每个目标做 realpath 后比对安装根和 home 边界,落在安装根的直接抛 forbidden-harness;回滚由后端 HMR 热生效,不需要重启。

Q: 跑一次检测要多久?

A: L0 静态检查秒级、L1 配置组合数百毫秒、L2 隔离试跑要看 profile 规模(默认上限 90 秒,超时会被强制 kill 子进程并标 smoke-failed),木马扫描视插件源码大小在数秒到十余秒。

Q: 回滚怎么撤销?

A: 调用 DELETE /healthcheck/rollback?pluginId=<id>,会按 # healthcheck auto-rollback <时间戳> 注释标记整段删掉并用热重载还原。

Q: 木马扫描会不会误报?

A: 会。签名匹配是单类命中就 warn,组合命中(下载执行 + 凭据 + 外联等强组合)才升 error;明显的合法用法(构建产物里的 eval 块、new Function("return ...") 的 schemastery 惯用法、回环 IP、普通 https API、自身插件代码)已经按规则排除,命中后建议人工按证据复核。

Q: 能不能批量给所有内置插件也做检查?

A: inventory 接口同时列出用户插件和安装 scope 下的内置 bundle(按 settings 插件页面那个清单扫描约 190 个),面板下拉里“全部插件”模式会把它们一起扫。

上手难度

入门 — 装上之后直接在设置面板里点“开始检测”,无需任何额外配置;进阶用户可以理解修复门禁和回滚机制以便在 CI 中跑 RUN_HEALTHCHECK_E2E=1 的 e2e 测试。

已知问题与限制

  • L2 smoke boot 子进程从 lib/runner.js 起,会在 home/profiles// 目录下写一个临时的 .healthcheck-overlay-<pid>.yml 端口覆写文件,跑完尝试删掉但不保证成功;profile 目录需要可写
  • C9 cordis 用法检测是纯静态启发式,可能误报——所有命中都标 warn,最终是否真有 bug 由 L2 隔离试跑做权威确认(src/host/cordis.ts:13-15)
  • 木马扫描不会扫自己,service.ts 第 117 行显式跳过 dsh-plugin-healthcheck;同样不扫 node_modules、tests、构建产物目录(malware.ts:130)
  • C5 Windows 命令检查只在 process.platform === 'win32' 时生效,其他平台不跑(checkers.ts:257)
  • e2e 测试(tests/live.e2e.spec.ts、tests/smoke.e2e.spec.ts)默认 describe.skip,需要 RUN_HEALTHCHECK_E2E=1 环境变量才会真正连接真实 profile
  • 历史记录只保留最近 20 条(repair.ts:210-223),超出后最旧的会被裁掉
  • L2 smoke boot 默认 90s 超时(SMOKE_TIMEOUT_MS,verify.ts:84),冷启动插件多的 profile 可能偏紧——这个值会出现在超时 finding 的 stage 字段里

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/chenw2759-wq/dsh-plugin-healthcheck)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory