Yan-Zero/dsh-codex| 认证等级 | L2 |
| 验证状态 | self-declared(单方声明,待独立验证) |
| 验证方法 | 未登记 structured verifiedBy |
| 运行级实测 | 未做运行级实测 |
| 内容锚 | git commit f99e828f8447 · Yan-Zero/dsh-codex · git ls-remote / clone 复现可对账 |
| DID | did:cha2a:package:Yan-Zero/dsh-codex |
| 身份锚点 | npm 未声明 GitHub 仓库——装前请自行核验来源 |
| 来源 | git |
| 插件版本 | — |
| 安装 | dsh plugin add github:Yan-Zero/dsh-codex |
| 扫描日期 | 2026-08-26(37 天前) |
| 扫描层级 | 静态扫描(自研规则 + GuardDog 复核 + OSV 依赖) |
| 扫描器版本 | dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev |
自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描
True
{'data_exfiltration': [{'file': 'dsh-codex-main/docs/design.md', 'line': 13, 'match': 'tokens. The account page reads the fixed ChatGPT Codex usage endpoint without is', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/docs/design.md', 'line': 21, 'match': 'token as an explicit request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/client/locales.ts', 'line': 96, 'match': 'token meter, overflow detection, and automatic compaction on the next model requ', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/imagegen.ts', 'line': 309, 'match': 'credentials, request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/index.ts', 'line': 361, 'match': 'credentials, imageTools, service.proxy.fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/oauth-browser.ts', 'line': 35, 'match': 'token exchange through Codex fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/search-event.ts', 'line': 11, 'match': 'secret-free OpenAI Codex standalone-search request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/search.ts', 'line': 65, 'match': 'secret-free request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/search.ts', 'line': 89, 'match': 'secret-free request', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/src/service.ts', 'line': 107, 'match': 'credentials, this.proxy.fetch', 'label': '凭据字段进入网络请求'}, {'file': 'dsh-codex-main/tests/oauth-provider.spec.ts', 'line': 113, 'match': 'token exchange uses Codex fetch', 'label': '凭据字段进入网络请求'}], 'excessive_permissions': [{'file': 'dsh-codex-main/src/client/OpenAICodexSettings.tsx', 'line': 458, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-codex-main/src/compatibility.ts', 'line': 99, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-codex-main/src/model-catalog.ts', 'line': 8, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-codex-main/src/responses.ts', 'line': 297, 'match': 'exec(', 'label': '命令执行'}, {'file': 'dsh-codex-main/src/session-repair.ts', 'line': 131, 'match': 'exec(', 'label': '命令执行'}], 'hardcoded_secrets': [{'file': 'dsh-codex-main/tests/credential-document.spec.ts', 'line': 9, 'match': "token: 'keep-id-token'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/credential-document.spec.ts', 'line': 28, 'match': "token: 'keep-id-token'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/credential-document.spec.ts', 'line': 51, 'match': "token = 'secret-value'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/credential-document.spec.ts', 'line': 62, 'match': "token: 'new-id-token'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/doctor.spec.ts', 'line': 35, 'match': "secret = 'access-token-must-not-leak'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/oauth-provider.spec.ts', 'line': 26, 'match': "token: 'new-refresh'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/oauth-provider.spec.ts', 'line': 92, 'match': "token: 'first-refresh'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/oauth-provider.spec.ts', 'line': 118, 'match': "token: 'first-refresh'", 'label': '明文凭据'}, {'file': 'dsh-codex-main/tests/usage.spec.ts', 'line': 241, 'match': "token: 'fixture-response-token'", 'label': '明文凭据'}], 'manifest_contract': [{'file': 'package.json', 'line': 0, 'match': 'main: lib/index.js', 'label': 'main 入口「lib/index.js」在包内不存在——加载会报 Cannot find module'}]}git-refresh
main
未复核。
未查询。