npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-plugin-gate

v1.3.2

Published

Installation safety gate & data-protection guard for DeepSeek Harness: 60 static signature rules scan plugin sources for malicious install scripts, credential theft, obfuscation and network callbacks before 'dsh plugin add', with scan baselines (gate_diff

Readme

dsh-plugin-gate(安装安全闸门)

DeepSeek Harness 插件的安装安全闸门与数据保护闸 —— 在 dsh plugin add 之前,用 60 条静态签名规则(31 高危 / 24 中危 / 5 低危)扫描插件源码中的恶意安装脚本、凭据窃取、混淆与外传行为;并以 12 种危险命令模式与工作区边界检查,在 rm -rf 一类误删事故发生前将其拦截。

插件市场膨胀迅速(数千条目),恶意代码混入插件只是时间问题。本插件为 agent 提供 gate_scan 工具,可扫描插件源码——本地目录或 npm tarball——检测经典恶意代码形态:

| 维度 | 检查内容 | |---|---| | 脚本 | npm 生命周期脚本(pre/install/postinstall)、exec/spawn/shell:true、curl|sh、编码 PowerShell、cmd/WSH 启动、动态 require | | 混淆 | eval / new Function / vm.runIn*、十六进制转义洪泛、base64 大块、字符数组打包 | | 权限 | 读取凭据环境变量(OPENAI_API_KEY 等)、读取 ssh/aws/npmrc 文件、写入系统/家目录/点文件、chmod 777、沙箱权限升级请求 | | 网络 | 外部 URL 与主机、fetch/axios/socket/WebSocket/DNS API、云元数据端点(169.254.169.254)、Discord/Telegram/Slack webhook、.onion、读文件后外发的"窃取"形态 | | 密钥 | 硬编码 sk- 密钥、ghp_ token、AWS key、私钥块、Bearer token | | 供应链 | 精确版本直接依赖对接 Google OSV 漏洞库核查(range 与官方 @deepseek-ai 包跳过;可配置,离线静默降级) |

闸门只读:绝不执行被扫描的代码,绝不写文件。

安装

dsh plugin --profile <profile> add dsh-plugin-gate

使用

安装插件前让 agent 扫描(插件也会注入提示词,引导 agent 自动执行):

gate_scan target: "npm:dsh-plugin-some-package"
gate_scan target: "npm:[email protected]"   # 固定版本
gate_scan target: "./downloaded-plugin"                 # 本地目录

判定语义

  • BLOCK:存在高危特征(安装期执行、编码 PowerShell、eval/Function、云元数据探测、webhook、私钥、读取凭据)。修复并重新扫描前不要安装。
  • WARN:中等风险特征需人工复核(网络 I/O、家目录写入、base64 大块)。逐条看证据再决定。
  • PASS:未发现风险签名。仅为启发式结果,对陌生作者仍需保持警惕。

上下文感知:文件未 import child_process 时,exec()/正则 RegExp#exec 命中会被降级,减少误报;代码执行类规则(exec、eval、curl|sh、PowerShell…)出现在注释或文档中时自动降为 low(示例而非行为),而密钥与 webhook 即使在注释中仍保持高警示。依赖从 git/http/file 安装会标记为 risky_dependency,超 4000 字符的压缩单行标记为 minified_line(low)。

配置

| 键 | 默认 | 含义 | |---|---|---| | maxFiles | 1000 | 目录扫描文件数上限 | | maxFileBytes | 2 MiB | 单文件文本上限 | | includeNodeModules | false | 是否进入 node_modules | | maxTarballBytes | 32 MiB | npm tarball 下载上限 | | allowlistHosts | [] | 白名单主机(不出现在未白名单列表) | | osvCheck | true | 对接 Google OSV 查询精确版本依赖的已知漏洞 | | osvMaxDeps | 8 | 最多检查的精确版本直接依赖数 | | osvTimeoutMs | 10000 | 单个依赖 OSV 查询超时 | | promptSection | true | 注入 agent 使用指引 | | sectionOrder | 5 | 提示词区块顺序 |

开发

node --check lib/*.js
node test/rules.test.mjs   # 主模块方式(DSH 沙箱内 node --test 会被拦截)
node test/scan.test.mjs

纯逻辑位于 lib/rules.js(签名规则)、lib/targz.js(内存 tar.gz 解压)、lib/scan.js(编排与判定);Cordis 插件为 lib/index.js。

安全

闸门绝不执行被扫描内容,是启发式签名扫描器——可能漏报新型恶意代码,也可能误报正常代码。BLOCK/WARN 命中请人工复核,详见 SECURITY.md。

许可证

MIT