仓库静态检查
- 检查 Commit
7ec62f7e00ee- 证据分
- 73/100
- 静态风险
- 中风险
- 扫描文件
- 4
- 检查发现
- 1
证据分项
兼容性置信度: 有限
检查发现 (1)
- 中
deps.core-package-installeduserspace-gate/package.jsondependencies"@deepseek-ai/schemastery": "^3.18.1"
- 依赖漏洞数据库扫描
- 实际安装测试
- 运行时行为验证
扫描器 1.0.0 · 评分器 1.0.0
Snail-Turbo/dsh-android-sandbox · 17 天前更新
安装方式
dsh plugin --profile web add ./userspace-bashdsh plugin --profile web add ./userspace-gatedsh plugin --profile web add github:Snail-Turbo/dsh-android-sandboxUser-space bash executor for hosts without a usable kernel runner: advertises a sandbox mode (so permission-presets and tool escalation surfaces work) but never confines — file-effect enforcement is delegated to the userspace-gate gates at tools/pre-execute
@deepseek-ai/dsh-bash-local^0.1.0-rc.5共享@deepseek-ai/dsh-invariants^0.1.0-rc.5共享@deepseek-ai/dsh-sandbox-policy^0.1.0-rc.5共享@deepseek-ai/dsh-system-prompt^0.1.0-rc.5共享@deepseek-ai/dsh-tools^0.1.0-rc.5共享Workspace-write guard plugin: a pure-user-space equivalent of the workspace-write sandbox at the tool-call layer — denies write/edit and bash write-intent calls whose targets fall outside the session workspace and platform temp roots, following the session sandbox mode
@deepseek-ai/cordis^0.1.0-rc.5共享@deepseek-ai/dsh-invariants^0.1.0-rc.5共享@deepseek-ai/dsh-sandbox^0.1.0-rc.5共享@deepseek-ai/dsh-sandbox-policy^0.1.0-rc.5共享@deepseek-ai/dsh-session^0.1.0-rc.5共享@deepseek-ai/dsh-tools^0.1.0-rc.5共享@deepseek-ai/schemastery^3.18.1私有副本路径固定于提交 7ec62f7e00ee
DeepSeek Harness (dsh) normally keeps writes inside the workspace with kernel-backed sandboxes — Landlock / bwrap, the filesystem fence, Seatbelt, Windows ACL runners. If your device has a working kernel sandbox, you don't need this repo; the shipped sandbox already covers you.
结果绑定到所列 commit,仅涵盖本站实际执行的静态检查。证据分衡量可复核信息的完整度,不是兼容性百分比,也不构成安全保证。
7ec62f7e00ee兼容性置信度: 有限
deps.core-package-installeduserspace-gate/package.jsondependencies"@deepseek-ai/schemastery": "^3.18.1"扫描器 1.0.0 · 评分器 1.0.0