仓库静态检查
- 检查 Commit
bfcc75029f9a- 证据分
- 76/100
- 静态风险
- 高风险
- 扫描文件
- 2
- 检查发现
- 1
证据分项
兼容性置信度: 有限
安装期脚本 (1)
preparetsdown
检查发现 (1)
- 高
install.scriptpackage.jsoninstall-time"prepare": "tsdown"
- 依赖漏洞数据库扫描
- 实际安装测试
- 运行时行为验证
扫描器 1.0.0 · 评分器 1.0.0
tallahandsome-ux/dsh-fetch-third-party · 10 天前更新
安装方式
dsh plugin --profile web add https://github.com/tallahandsome-ux/dsh-fetch-third-party.gitdsh plugin --profile web add file:D:\你的目录\dsh-fetch-third-partydsh plugin --profile web add file:D:\plugins\dsh-fetch-third-partydsh plugin --profile web add dsh-fetch-third-partydsh plugin --profile web add github:tallahandsome-ux/dsh-fetch-third-partySafe third-party web fetch for dsh: delegates page retrieval to a user-configured third-party service (Tavily / Jina / Firecrawl / custom crawler via contract v1) so the local machine never connects to arbitrary URLs (no SSRF surface). API key lives only in the managed credentials store; per-session fetch budget caps usage; a bundled Crawl4AI stack can be auto-managed.
@deepseek-ai/cordis^4.0.1共享@deepseek-ai/dsh-credentials^0.1.0-rc.5共享@deepseek-ai/dsh-launch-environment^0.1.0-rc.5共享@deepseek-ai/dsh-settings^0.1.0-rc.5共享@deepseek-ai/dsh-tools^0.1.0-rc.5共享@deepseek-ai/dsh-web^0.1.0-rc.5共享@deepseek-ai/schemastery^3.18.1共享路径固定于提交 bfcc75029f9a
Safe third-party web fetch for DSH — delegates page crawling to user-configured services with no direct URL access (no SSRF), API keys in the managed credentials store, per-session budget, and an auto-managed local web scraping service stack.
结果绑定到所列 commit,仅涵盖本站实际执行的静态检查。证据分衡量可复核信息的完整度,不是兼容性百分比,也不构成安全保证。
bfcc75029f9a兼容性置信度: 有限
preparetsdowninstall.scriptpackage.jsoninstall-time"prepare": "tsdown"扫描器 1.0.0 · 评分器 1.0.0