← all reports

npm:dsh-find-plugin@0.4.0

dsh-verified: partial — npm:dsh-find-plugin@0.4.0. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin partial partial

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==

Subject

namedsh-find-plugin
version0.4.0
integritysha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==
repositorygit+https://github.com/awesome-dsh-plugin/dsh-find-plugin.git
declared bundle patch"./cordis.patch.yml"
declared engines.dshnot declared — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 b07a7e8d0093
generated2026-10-03T15:57:40.152Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (15 files, 151561 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

metrics
{
  "fileCount": 15,
  "unpackedBytes": 151561,
  "patchPaths": [
    "./cordis.patch.yml"
  ],
  "declaredEnginesDsh": null,
  "shipsSource": true
}
e-resolve, e-tarball, e-l0
L1 fail peer-incompatible with the pinned runtime

DSH refused the install: the plugin's declared peerDependencies on @deepseek-ai/dsh* do not match the runtime. An exact-version exemption would bypass this check; granting one is a user decision and is not done here.

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 1639,
  "exitCode": 1,
  "declaredPeers": {
    "@deepseek-ai/dsh-tools": "^0.1.0-rc.6 || ^0.1.1-rc.1 || ^0.1.2-alpha.2 || ^0.1.3-alpha.2 || ^0.1.5-alpha.1 || ^0.1.6-alpha.1 || ^0.1.7-alpha.1"
  },
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base"
  ],
  "pendingBuildScripts": [],
  "buildScriptsApproved": 0,
  "diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-jqcPJ1/pnpm.log"
}
e-l1-install
L2 skip not run: the subject did not install

loading a plugin that is not present would measure nothing

no evidence cited
L3 skip not run: the subject did not install

a session cannot be attributed to a subject that is not present

no evidence cited
L4 pass 2 capability signal(s) present across 9 scanned file(s)

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 9,
  "scannedBytes": 53201,
  "skippedFiles": 0
}
e-l4, e-patch
L5 inconclusive the subject did not install, so there was nothing to activate

no overhead claim is made when the differential could not be completed

metrics
{
  "samples": 0
}
no evidence cited
L6 skip not run: the subject did not install

removal was not attempted because nothing was installed

no evidence cited

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
network_egressmediumauthor-sourcepackage/src/github.ts:164
writes_outside_workspacelowauthor-sourcepackage/src/registry.ts:73

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

No overhead measurement was published for this report.

Evidence

idkindartifact
e-resolve command exit 0 83 ms resolve dsh-find-plugin@0.4.0 -> dsh-find-plugin@0.4.0
{
  "name": "dsh-find-plugin",
  "version": "0.4.0",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/dsh-find-plugin/-/dsh-find-plugin-0.4.0.tgz",
  "advertisedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
  "publishedAt": "2026-09-25T14:59:44.271Z"
}
e-tarball artifact exit 0 20 ms fetch https://registry.npmjs.org/dsh-find-plugin/-/dsh-find-plugin-0.4.0.tgz
{
  "bytes": 45308,
  "resolvedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
  "advertisedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
  "integrityMatchesRegistry": true,
  "sha256": "39fc2dfd519b53bc71c9d4fb8cb7faa678d2c14ffb77c6df38daf0eedf0b56a0"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "./cordis.patch.yml"
    ],
    "clientPlatform": null,
    "enginesDsh": null,
    "enginesNode": null
  },
  "missingPatchPaths": [],
  "fileCount": 15,
  "unpackedBytes": 151561,
  "shipsSource": true
}
e-patch static read cordis.patch.yml
# dsh bundle patch: inserts this plugin into a profile's layer stack.
- insert:
    - id: find-dsh-plugin
      name: 'dsh-find-plugin'
e-l4 static scan 9 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "network_egress",
      "confidence": "medium",
      "attribution": "author-source",
      "firstEvidence": {
        "file": "package/src/github.ts",
        "line": 164,
        "snippet": "res = await fetch(url, { headers, signal: signalFor() })"
      }
    },
    {
      "id": "writes_outside_workspace",
      "confidence": "low",
      "attribution": "author-source",
      "firstEvidence": {
        "file": "package/src/registry.ts",
        "line": 73,
        "snippet": "const fromEnv = process.env.DSH_HOME"
      }
    }
  ],
  "scannedFiles": 9,
  "skippedFiles": 0,
  "limits": [
    "static analysis cannot see dynamically constructed code or prove intent"
  ]
}
e-l1-install command exit 1 1639 ms dsh plugin --profile verify add dsh-find-plugin@0.4.0
dsh: initialized profile verify at /work/dsh-home/profiles/verify

dsh: installation rejected: Plugin dsh-find-plugin@0.4.0 is incompatible with dsh 0.2.0-rc.2: peerDependencies {"@deepseek-ai/dsh-tools":"^0.1.0-rc.6 || ^0.1.1-rc.1 || ^0.1.2-alpha.2 || ^0.1.3-alpha.2 || ^0.1.5-alpha.1 || ^0.1.6-alpha.1 || ^0.1.7-alpha.1"}. Running it may cause crashes or data loss. Update the plugin or install a plugin version compatible with this dsh runtime. To accept this risk explicitly, grant the exact-version exemption for dsh-find-plugin@0.4.0 on dsh 0.2.0-rc.2 with `dsh plugin allow-version` or the plugin manager, then retry the installation or restart dsh. Exact-version exemption: not active.
dsh: nothing was installed.
dsh: to accept the risk, run: dsh plugin --profile verify allow-version dsh-find-plugin@0.4.0 --dsh-version 0.2.0-rc.2 --accept-risk
dsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-jqcPJ1/pnpm.log

Limits

Disclaimers

raw report JSON · badge · dispute this report