๐Ÿ›ก๏ธ dsh-security-gate

August 16, 2026 ยท View on GitHub

่ฃ…ๆ’ไปถ๏ผŒๅ…ˆ่ฟ‡ๅฎ‰ๆฃ€้—จใ€‚ A DSH (DeepSeek Harness / Cordis) plugin that inspects other plugins before you install them โ€” static scan + AI review + runtime watch, community ratings and bug bounty.

  • Plugin ID: gate-2 ยท Package: pkg-18 (v1.0.0 / v10)
  • Platform: DeepSeek Harness dynamic Cordis plugin (Host + Client)

Why SecurityGate

dsh-plugin-marketplace validates plugins and dsh-suite tests compatibility, but those are after-the-fact checks. SecurityGate moves security to proactive defense before install:

                   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                   โ”‚   ๐Ÿ›ก๏ธ SecurityGate ยท ๆ’ไปถๅฎ‰ๆฃ€้—จ            โ”‚
   new plugin โ”€โ”€โ”€โ–ถ โ”‚ โ‘  Static scan (malicious score + caps)    โ”‚
                   โ”‚ โ‘ก ๐Ÿค– LLM AI review (false-positive check) โ”‚
                   โ”‚ โ‘ข Runtime registry watch (live arrivals)  โ”‚
                   โ”‚ โ‘ฃ Community ratings + bug bounty          โ”‚
                   โ”‚  โ†’ verdict & advice โ†’ install with trust  โ”‚
                   โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Features

#FeatureDescription
1Dual-dimension scanๆถๆ„้ฃŽ้™ฉๅˆ† (malicious-risk score 0-100: dynamic code / shell / raw fs / obfuscation / policy bypass / persistence / exfil) separated from ๆƒ้™่ƒฝๅŠ›้ข (capability surface: network / file write / env read / services / tools โ€” functional permissions, not malice)
2๐Ÿค– LLM AI reviewOne click: the current model re-judges static findings to filter false positives (gate_scan ai_review param)
3Runtime registry watchBaselines the visible tool set at startup, subscribes tools/change, tracks added/removed tools and recent arrivals
4New-tool alertA floating "๐Ÿšจ new plugin tools detected" toast appears when any plugin registers tools during the session
5Quick accessA ๐Ÿ›ก๏ธ button in the session header opens a floating quick-scan panel โ€” no need to open Settings
6Scan historyLast 20 scans persisted with the community store; per-entry verdict copy
7Share reportOne-click export + copy of a shareable inspection report with the "โœ… passed SecurityGate" stamp
8Community ratings1-5 star security ratings + comments, leaderboard (local store; cloud sync on the roadmap)
9Bug bounty flowSubmit reports (critical 1000 / high 500 / medium 200 / low 50 pts), audit flow: pending โ†’ under review โ†’ confirmed (points awarded) / dismissed / fixed / blacklisted
10i18nzh-CN / en-US UI via the locale service (auto-falls back to Chinese)
11OnboardingA "SecurityGate is on duty" card in the Run card + in-app usage guide

Installation

This is a dynamic Cordis plugin for DSH. Two ways:

The file plugin/source.json contains the exact cordis_define payload:

plugin:  { kind: 'new', idPrefix: 'gate' }
name:    security-gate ๆ’ไปถๅฎ‰ๆฃ€้—จ
purpose: ๅฎ‰่ฃ…ๆ’ไปถๅ‰ๅ…ˆ่ฟ‡ๅฎ‰ๆฃ€้—จ๏ผšๅŒ็ปด้™ๆ€ๅฎ‰ๅ…จๆ‰ซๆ๏ผˆๆถๆ„้ฃŽ้™ฉๅˆ† + ๆƒ้™่ƒฝๅŠ›้ข๏ผ‰ใ€
         LLM AI ๅคๆ ธใ€่ฟ่กŒๆ—ถๆณจๅ†Œ่ง‚ๅฏŸใ€็คพๅŒบๅฎ‰ๅ…จ่ฏ„ๅˆ†ไธŽๆผๆดž่ต้‡‘ใ€‚
code.host:    plugin/host.js (or host.raw.js)
code.client:  plugin/client.js (or client.raw.js)

Ask your DSH agent to define it with code.host = plugin/host.raw.js content and code.client = plugin/client.raw.js content, then run it. Approve the client half when prompted.

B. Manual copy

plugin/host.raw.js and plugin/client.raw.js are the bare function bodies exactly as recorded by the Host โ€” paste them into cordis_define.

How to use

Settings UI: Sidebar โ†’ Settings โ†’ ๐Ÿ›ก๏ธ ๆ’ไปถๅฎ‰ๆฃ€้—จ

  • ๐Ÿงช Preview Sandbox: paste source or scan a local file/directory โ†’ risk score, capability surface, findings (with line numbers), dry-run trace, advice; ๐Ÿค– AI Review button
  • โญ Community Ratings: rate plugins 1-5 stars, leaderboard
  • ๐Ÿ› Bug Bounty: submit reports, drive the audit status flow

Conversation: just say "็”จๅฎ‰ๆฃ€้—จๆ‰ซไธ€ไธ‹่ฟ™ไธชๆ’ไปถ" โ€” the model calls gate_scan automatically. Four model tools:

ToolPurpose
gate_scanstatic scan + dry-run preview; source or path; optional ai_review
gate_registryruntime registry watch: tools added/removed since gate start, recent arrivals
gate_ratesubmit a 1-5 star community rating
gate_reportsubmit a bug bounty report

Architecture

Host (Node process):
  static scan engine (7 malicious rules ร— weights โ†’ 0-100 score; 4 capability markers)
  AI review (llm service + agentDefaultModel, JSON verdict parsing)
  runtime watcher (tools baseline + tools/change subscription, arrivals log)
  community store (ratings + reports + history, persisted to <workspace>/.security-gate-store.json)
  scan history + share-text exporter
  4 model tools + 11 package-private RPCs
Client (browser):
  settings page (3 tabs) + usage guide (i18n)
  session-header ๐Ÿ›ก๏ธ quick button + floating quick-scan panel
  floating new-arrival alert (8s poll)
  Run card "on duty" status card

Data & privacy

  • Community data lives locally: <workspace>/.security-gate-store.json (ratings, reports, scan history)
  • SecurityGate itself makes no network calls (the plugin's own runtime sends nothing anywhere)
  • Scanning is read-only: inspected code is never executed
  • AI review sends only scan findings/snippets to the configured model

Roadmap

  • v2.0: cloud community backend (shared ratings / blacklist / bounty across users โ€” minimal JSON API or serverless)
  • Cloud preview sandbox backend (e2b / container) behind the backend seam
  • Marketplace integration (install button โ†’ inspection gate)
  • Behavior signature library (known-malicious fingerprints + auto-blacklist)

License

MIT โ€” see LICENSE.