← 返回扫描报告总表 · ← dshlib 图书馆

扫描报告 · Nagi-ovo/voyager

认证等级L2
验证状态self-declared(单方声明,待独立验证)
验证方法未登记 structured verifiedBy
运行级实测未做运行级实测
内容锚git commit c3b4d8295d1d · Nagi-ovo/voyager · git ls-remote / clone 复现可对账
DIDdid:cha2a:package:Nagi-ovo/voyager
身份锚点npm 未声明 GitHub 仓库——装前请自行核验来源
来源git
插件版本—
安装dsh plugin add github:Nagi-ovo/voyager
扫描日期2026-08-28(35 天前)
扫描层级静态扫描(自研规则 + GuardDog 复核 + OSV 依赖)
扫描器版本dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev

自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描

⚠️ 结论待复核:上次扫描距今 35 天(2026-08-28),插件或运行时更新后结论可能过期,建议重新扫描后再安装。
语义:扫描是提示信号,非安全审查。✅ 通过=无命中;⚠️ 待审=有命中需人工判断;❌ 失败=无法扫描。人工确认恶意→下架。本页全部内容由 dshlib 数据库派生(验证报告 可核对证据)。认证等级与依赖漏洞正交:L4 认证覆盖插件包内容/来源/生态,不覆盖依赖安全(见收录与验证标准)。结论有有效期:插件或运行时更新后,本页结论可能过期(>30 天将标注待复核)。本库能力与边界:披露页。

1. 自研扫描(dshlib-scan)

verified

True

findings

{'data_exfiltration': [{'file': 'voyager-main/docs/en/privacy.md', 'line': 23, 'match': 'credentials in the macOS Keychain. Both paths request', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.cjs', 'line': 9, 'match': 'token for fetch', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.cjs', 'line': 108, 'match': 'token, { fetchImpl = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.cjs', 'line': 216, 'match': 'token, { fetchImpl = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.test.js', 'line': 55, 'match': "token', { fetch", 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.test.js', 'line': 91, 'match': "token', { fetch", 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.test.js', 'line': 105, 'match': "token', { fetch", 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/scripts/generate-sponsors.test.js', 'line': 110, 'match': "token', { fetch", 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/src/core/services/__tests__/googleOAuthWebFlow.test.ts', 'line': 31, 'match': 'token=tok&expires_in=1800&state=${request', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/src/core/services/__tests__/googleOAuthWebFlow.test.ts', 'line': 48, 'match': 'token whose state does not match the request', 'label': '凭据字段进入网络请求'}, {'file': 'voyager-main/src/core/services/__tests__/googleOAuthWebFlow.test.ts', 'line': 98, 'match': 'token=legacy&state=${request', 'label': '凭据字段进入网络请求'}], 'excessive_permissions': [{'file': 'voyager-main/docs/public/oauth/callback/relay.js', 'line': 30, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/scripts/bump-version.js', 'line': 102, 'match': 'execSync(', 'label': '命令执行'}, {'file': 'voyager-main/scripts/verify-katex-export.ts', 'line': 534, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/services/DiagnosticsExportService.ts', 'line': 228, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/services/__tests__/GoogleDriveSyncService.test.ts', 'line': 464, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/services/__tests__/GoogleDriveSyncService.test.ts', 'line': 511, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/services/googleOAuthWebFlow.ts', 'line': 83, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/services/googleOAuthWebFlow.ts', 'line': 85, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/utils/__tests__/firefoxCssFloor.test.ts', 'line': 118, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/core/utils/customWebsites.ts', 'line': 34, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/export/services/ImageRenderService.ts', 'line': 267, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/export/services/MarkdownFormatter.ts', 'line': 49, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/export/services/__tests__/markdownImageArchive.test.ts', 'line': 56, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/export/services/boundedImageFetch.ts', 'line': 149, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/builtin/chatgptTemporaryHandoff/handoff.ts', 'line': 231, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/builtin/chatgptTemporaryHandoff/handoff.ts', 'line': 249, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/builtin/chatgptTemporaryHandoff/handoff.ts', 'line': 251, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/catalog/sites/index.ts', 'line': 72, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/catalog/sites/index.ts', 'line': 82, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/catalog/sites/index.ts', 'line': 92, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/remote/hostCatalogPolicy.ts', 'line': 104, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/runtime/siteRegistration.ts', 'line': 111, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/semver.ts', 'line': 14, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/sites/matchPattern.ts', 'line': 47, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/plugins/verbs/turnNavigator/TurnNavigator.ts', 'line': 91, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/prompt/model/promptTemplate.ts', 'line': 93, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/features/prompt/model/promptTextMatch.ts', 'line': 162, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/background/index.ts', 'line': 382, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/changelog/platformLogoMarks.ts', 'line': 48, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/changelog/platformLogoMarks.ts', 'line': 48, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/export/selectionUtils.ts', 'line': 44, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/fork/turnId.ts', 'line': 12, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/fork/turnId.ts', 'line': 36, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/fork/turnId.ts', 'line': 44, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/prompt/PromptTemplateFill.ts', 'line': 79, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/content/prompt/__tests__/promptFormStyle.test.ts', 'line': 15, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/popup/components/PluginManager.tsx', 'line': 116, 'match': 'exec(', 'label': '命令执行'}, {'file': 'voyager-main/src/pages/popup/components/ThemeColorButton.tsx', 'line': 25, 'match': 'exec(', 'label': '命令执行'}], 'dangerous_commands': [{'file': 'voyager-main/package.json', 'line': 34, 'match': "rm -rf {} + && echo 'Cleared Xcode derived data (kept .build/", 'label': 'rm -rf 危险删除'}, {'file': 'voyager-main/src/pages/content/formulaCopyStartup.test.ts', 'line': 35, 'match': 'shutdown', 'label': '系统关机'}], 'hardcoded_secrets': [{'file': 'voyager-main/src/core/services/GoogleDriveSyncService.ts', 'line': 742, 'match': "token:', error);\n    }\n  }\n\n  private async saveToken(token: string, expiresIn: ", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/GoogleDriveSyncService.ts', 'line': 754, 'match': "token:', error);\n    }\n  }\n\n  private async clearToken(): Promise<void> {\n    th", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/GoogleDriveSyncService.ts', 'line': 764, 'match': "token:', error);\n    }\n  }\n\n  private isUserDeniedAuthError(message: string): bo", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/__tests__/DiagnosticsExportService.test.ts', 'line': 159, 'match': "token: '<redacted>'", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/__tests__/GoogleDriveSyncService.test.ts', 'line': 214, 'match': "token: 'cached-token'", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/__tests__/googleOAuthWebFlow.test.ts', 'line': 65, 'match': "token: 'ff-token'", 'label': '明文凭据'}, {'file': 'voyager-main/src/core/services/__tests__/googleOAuthWebFlow.test.ts', 'line': 75, 'match': "secret: 'desktop-secret'", 'label': '明文凭据'}, {'file': 'voyager-main/src/features/plugins/builtin/chatgptTemporaryHandoff/handoff.test.ts', 'line': 94, 'match': "token = 'test-tab-token'", 'label': '明文凭据'}]}

mode

git-refresh

branch

main

2. 第三方复核(GuardDog 3.2.0)

未复核。

3. 依赖漏洞(OSV.dev)

未查询。