How to use dsh-plugin-healthcheck
Checks installed plugins for stability and security, detecting potential crashes or embedded malware.
This article is auto-derived from indexed fields (wiki / faq / compatibility_json), not freshly AI-generated.
This article is derived from the plugin's already-indexed fields (wiki / faq / compatibility_json / readme), not freshly generated by AI. Source field is noted at the end of each section.
Quick start
Checks installed plugins for stability and security, detecting potential crashes or embedded malware.
— source: plugins.ai_summary
Install & verify
dsh plugin --profile web add --allow-build=dsh-plugin-healthcheck github:chenw2759-wq/dsh-plugin-healthcheck
Run the command above in your DSH Web Profile. Then enable the plugin in the plugin list.
— source: plugins.install
Key points
- 隔离铁律:只
readFile,绝不 import / require / 执行插件代码。 - 7 类恶意模式:M1 下载执行、M2 凭据窃取、M3 外联回传、M4 混淆后门、M5 持久化、M6 破坏性、M7 环境劫持。
- 两级校准:强组合(下载执行 / 破坏性 / 凭据+外联)→ error;单一命中 → warn(提示人工复核)。
- 证据脱敏:密钥/令牌/私钥一律
[REDACTED]。 - 误报控制:跳过 tests/node_modules/构建产物;
new Function("return …")(schemastery 惯用法)、
— source: plugin_wiki.readme_en (fallback readme_raw)
Compatibility
- DSH: ^0.1.0-rc.6
- Node: 未声明
— source: plugin_wiki.compatibility_json
Pitfalls
Review the upstream repo before installing. This guide is auto-derived from indexed fields and may lag the latest release. If anything contradicts the official docs, treat the upstream source as authoritative.
— source: general rule