liustack/modlens| 认证等级 | L2 |
| 验证状态 | registry-confirmed(有 registry 凭证证据) |
| 验证方法 | 未登记 structured verifiedBy |
| 运行级实测 | 未做运行级实测 |
| 内容锚 | git commit fdc6c4bc49e1 · liustack/modlens · git ls-remote / clone 复现可对账 |
| DID | did:cha2a:package:liustack/modlens |
| 身份锚点 | npm 未声明 GitHub 仓库——装前请自行核验来源 |
| 来源 | git |
| 插件版本 | — |
| 安装 | dsh plugin add github:liustack/modlens |
| 扫描日期 | 2026-08-27(36 天前) |
| 扫描层级 | 静态扫描(自研规则 + GuardDog 复核 + OSV 依赖) |
| 扫描器版本 | dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev |
自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描
True
{'data_exfiltration': [{'file': 'modlens-main/CHANGELOG.md', 'line': 35, 'match': 'token \'d\', "data:{"id""... is not valid JSON` — making modlens unusable against ', 'label': '凭据字段进入网络请求'}, {'file': 'modlens-main/src/auto/routes.ts', 'line': 13, 'match': 'credentials are fetch', 'label': '凭据字段进入网络请求'}], 'dangerous_commands': [{'file': 'modlens-main/INSTALL.md', 'line': 96, 'match': 'rm -rf /tmp/', 'label': 'rm -rf 危险删除'}], 'excessive_permissions': [{'file': 'modlens-main/src/cooldown.ts', 'line': 45, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/doctor.ts', 'line': 148, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/guard/modelSniff.test.ts', 'line': 344, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/providers/antigravity.ts', 'line': 183, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/recoverPaste/adapters/opencode.test.ts', 'line': 58, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/recoverPaste/adapters/opencode.test.ts', 'line': 195, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/recoverPaste/adapters/opencode.ts', 'line': 145, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/recoverPaste/detect.ts', 'line': 29, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/skillPin.ts', 'line': 47, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/apiKeys.ts', 'line': 48, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/json.ts', 'line': 49, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 215, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 255, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 391, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 422, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 435, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 474, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 475, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 492, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 514, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 521, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 528, 'match': 'exec(', 'label': '命令执行'}, {'file': 'modlens-main/src/util/winExec.ts', 'line': 530, 'match': 'exec(', 'label': '命令执行'}], 'hardcoded_secrets': [{'file': 'modlens-main/src/util/redact.test.ts', 'line': 17, 'match': 'ghp_ABCDEFGHIJKLMNOPQRST123456', 'label': 'GitHub token'}]}git-refresh
main
未复核。
未查询。