BotonJ/dsh-plugin-sentinel
Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.
$ dsh plugin --profile web add dsh-plugin-sentinel$ dsh plugin --profile web add github:botonj/dsh-plugin-sentinelHealth breakdown
80 / 100This plugin has not fully disclosed its data-collection behavior. Review the source and manifest before installing.
Security
Key metrics
Related
Related plugins
Software-engineering method pack for coding agents, with skills for baseline-first planning, systematic debugging, prompt hygiene, verification before completion, and repair/retirement tracking.
An MC-Fabric-style hook processor.
Pin Git commits to the environment's own author identity; env-var injection overrides all `git config` settings.
Plugin health checks: manifest protocol / patch format / build traps, zero-dependency and read-only.
Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.
Finds potential UX issues in your project: automatically reviews React/TypeScript code, pinpoints each problem, and gives concrete suggestions.