← 返回扫描报告总表 · ← dshlib 图书馆

扫描报告 · Tyan66666/billion-context-dsh

认证等级L2
验证状态registry-confirmed(有 registry 凭证证据)
验证方法未登记 structured verifiedBy
运行级实测未做运行级实测
内容锚git commit bb9f2f61b14d · Tyan66666/billion-context-dsh · git ls-remote / clone 复现可对账
DIDdid:cha2a:package:Tyan66666/billion-context-dsh
身份锚点npm 未声明 GitHub 仓库——装前请自行核验来源
来源git
插件版本—
安装dsh plugin add github:Tyan66666/billion-context-dsh
扫描日期2026-08-27(36 天前)
扫描层级静态扫描(自研规则 + GuardDog 复核 + OSV 依赖)
扫描器版本dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev

自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描

⚠️ 结论待复核:上次扫描距今 36 天(2026-08-27),插件或运行时更新后结论可能过期,建议重新扫描后再安装。
语义:扫描是提示信号,非安全审查。✅ 通过=无命中;⚠️ 待审=有命中需人工判断;❌ 失败=无法扫描。人工确认恶意→下架。本页全部内容由 dshlib 数据库派生(验证报告 可核对证据)。认证等级与依赖漏洞正交:L4 认证覆盖插件包内容/来源/生态,不覆盖依赖安全(见收录与验证标准)。结论有有效期:插件或运行时更新后,本页结论可能过期(>30 天将标注待复核)。本库能力与边界:披露页。

1. 自研扫描(dshlib-scan)

verified

True

findings

{'data_exfiltration': [{'file': 'billion-context-dsh-main/AGENTS.md', 'line': 85, 'match': 'tokens − heuristicTokens` (`tokens` is the route-priced request', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/README.en.md', 'line': 202, 'match': 'tokens` either (under 0.1.2+ image route pricing that is request', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/docs/dsh-porting-verification.md', 'line': 157, 'match': 'token 计价 | 投影层为图片/文件块生成确定性占位符(`[image …]` / `[file …]`,照抄宿主对文件的 handle 文本投影:dsh-', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/helpers.ts', 'line': 10, 'match': 'tokens stored in Redis with 30 day TTL, implemented in src/auth/login.ts with sl', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/instruction-barrier.test.ts', 'line': 302, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 103, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 136, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 154, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 824, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1226, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1258, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1288, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1355, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1414, 'match': 'tokens in Redis with 30 day TTL, login flow in src/auth/login.ts with sliding-wi', 'label': '凭据字段进入网络请求'}], 'dangerous_commands': [{'file': 'billion-context-dsh-main/docs/dsh-porting-analysis.md', 'line': 20, 'match': 'shutdown', 'label': '系统关机'}], 'excessive_permissions': [{'file': 'billion-context-dsh-main/src/prompts.ts', 'line': 108, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/src/tools.ts', 'line': 194, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/src/tools.ts', 'line': 638, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 76, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 244, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 402, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 409, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1108, 'match': 'exec(', 'label': '命令执行'}, {'file': 'billion-context-dsh-main/tests/tools.test.ts', 'line': 1495, 'match': 'exec(', 'label': '命令执行'}]}

mode

git-refresh

branch

main

2. 第三方复核(GuardDog 3.2.0)

未复核。

3. 依赖漏洞(OSV.dev)

未查询。