← 返回扫描报告总表 · ← dshlib 图书馆

扫描报告 · Stormycry-cryp/dsh-AuthInOne

认证等级L2
验证状态self-declared(单方声明,待独立验证)
验证方法未登记 structured verifiedBy
运行级实测未做运行级实测
内容锚git commit 190ecc2d834b · Stormycry-cryp/dsh-AuthInOne · git ls-remote / clone 复现可对账
DIDdid:cha2a:package:Stormycry-cryp/dsh-AuthInOne
身份锚点npm 未声明 GitHub 仓库——装前请自行核验来源
来源git
插件版本—
安装dsh plugin add github:Stormycry-cryp/dsh-AuthInOne
扫描日期2026-08-28(35 天前)
扫描层级静态扫描(自研规则 + GuardDog 复核 + OSV 依赖)
扫描器版本dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev

自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描

⚠️ 结论待复核:上次扫描距今 35 天(2026-08-28),插件或运行时更新后结论可能过期,建议重新扫描后再安装。
语义:扫描是提示信号,非安全审查。✅ 通过=无命中;⚠️ 待审=有命中需人工判断;❌ 失败=无法扫描。人工确认恶意→下架。本页全部内容由 dshlib 数据库派生(验证报告 可核对证据)。认证等级与依赖漏洞正交:L4 认证覆盖插件包内容/来源/生态,不覆盖依赖安全(见收录与验证标准)。结论有有效期:插件或运行时更新后,本页结论可能过期(>30 天将标注待复核)。本库能力与边界:披露页。

1. 自研扫描(dshlib-scan)

verified

True

findings

{'data_exfiltration': [{'file': 'dsh-AuthInOne-main/docs/architecture.md', 'line': 70, 'match': 'credentials, Provider responses, authorization URLs, cookies, or request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/docs/design/self-contained-installer.md', 'line': 30, 'match': 'credentials, authorization URLs, cookies, request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/docs/releases/v0.2.0-alpha.4.md', 'line': 15, 'match': 'credentials, authorization URLs, cookies, Provider responses, or request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/anthropic.js', 'line': 421, 'match': 'token refresh request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/client.js', 'line': 70, 'match': 'token`,supportsImageInput:`支持图片输入`,supportsImageInputHelp:`默认关闭。仅在已确认该自定义模型可接收图片', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/client.js.map', 'line': 1, 'match': "token',\\n    supportsImageInput: '支持图片输入',\\n    supportsImageInputHelp: '默认关闭。仅在", 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/client.js.map', 'line': 1, 'match': 'credentials/topology change refetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 3128, 'match': 'token, request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 9456, 'match': 'token counts of the request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42529, 'match': 'tokenRegExp.exec(method) === null) throw new InvalidArgumentError("invalid reque', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 47960, 'match': 'credentials: request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 48003, 'match': 'credentials !== void 0) request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 48683, 'match': 'password) && !sameOrigin(request, locationURL)) return Promise.resolve(makeNetwo', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 48684, 'match': 'password)) return Promise.resolve(makeNetworkError("URL cannot contain credentia', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 48722, 'match': 'credentials === "include" || request.credentials === "same-origin" && request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234252, 'match': 'token for a plugin-owned auxiliary request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234619, 'match': 'token, init = {}, request = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234643, 'match': 'token, signal, request = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234663, 'match': 'token, signal === void 0 ? {} : { signal }, request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234671, 'match': 'token, signal, request = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234718, 'match': 'token, signal, request = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 234761, 'match': 'token, credential, signal, request = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/types/host/auth.d.ts', 'line': 122, 'match': 'token for a plugin-owned auxiliary request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/types/host/provider-quotas.d.ts', 'line': 5, 'match': 'token: string, signal?: AbortSignal, request?: typeof fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/types/host/provider-quotas.d.ts', 'line': 7, 'match': 'token: string, signal?: AbortSignal, request?: typeof fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/types/host/provider-quotas.d.ts', 'line': 9, 'match': 'token: string, signal?: AbortSignal, request?: typeof fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/lib/types/host/provider-quotas.d.ts', 'line': 11, 'match': 'token: string, credential: StoredOAuthCredential, signal?: AbortSignal, request?', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/client/compat/vendor/models/client/index.ts', 'line': 99, 'match': 'credentials/topology change refetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/auth.ts', 'line': 670, 'match': 'token for a plugin-owned auxiliary request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/provider-quotas.ts', 'line': 56, 'match': 'token: string, init: RequestInit = {}, request: typeof fetch = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/provider-quotas.ts', 'line': 78, 'match': 'token: string, signal?: AbortSignal, request: typeof fetch = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/provider-quotas.ts', 'line': 99, 'match': 'token, signal === undefined ? {} : { signal }, request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/provider-quotas.ts', 'line': 113, 'match': 'token: string, signal?: AbortSignal, request: typeof fetch = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/src/host/provider-quotas.ts', 'line': 142, 'match': 'token: string, signal?: AbortSignal, request: typeof fetch = fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 135, 'match': "tokenResponse({ error: 'invalid_grant' }, 400)) as typeof fetch", 'label': '凭据字段进入网络请求'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 349, 'match': "tokenResponse({ error: 'invalid_grant' }, 400)) as typeof fetch", 'label': '凭据字段进入网络请求'}], 'excessive_permissions': [{'file': 'dsh-AuthInOne-main/lib/client.js', 'line': 64, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/client.js', 'line': 70, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/client.js.map', 'line': 1, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/client.js.map', 'line': 1, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 3972, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 5222, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 12121, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 13170, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 32767, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 34093, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 39602, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 41036, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42527, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42529, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42735, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42742, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 42759, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 100850, 'match': 'child_process(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/src/client/compat/vendor/models/client/DeepSeekModelsEditor.tsx', 'line': 46, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-AuthInOne-main/src/client/time-range.ts', 'line': 35, 'match': 'exec(', 'label': '命令执行'}], 'hardcoded_secrets': [{'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 15690, 'match': "token: 'ghp_exampletoken'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/lib/host.js', 'line': 16089, 'match': "token: 'bearer_exampletoken'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 55, 'match': "token: 'access-new-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 56, 'match': "token: 'refresh-new-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 91, 'match': "token: 'access-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 91, 'match': "token: 'refresh-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 124, 'match': "token: 'access-new-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 124, 'match': "token: 'refresh-rotated-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 152, 'match': "token: 'refresh-old-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 280, 'match': "token: 'kimi-access-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 280, 'match': "token: 'kimi-refresh-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 341, 'match': "token: 'kimi-new-access'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 341, 'match': "token: 'kimi-new-refresh'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 479, 'match': "token: 'google-access-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/auth.test.ts', 'line': 479, 'match': "token: 'google-refresh-sensitive'", 'label': '明文凭据'}, {'file': 'dsh-AuthInOne-main/tests/codex-usage.test.ts', 'line': 17, 'match': "token: 'must-not-project'", 'label': '明文凭据'}]}

mode

git-refresh

branch

main

2. 第三方复核(GuardDog 3.2.0)

未复核。

3. 依赖漏洞(OSV.dev)

未查询。