← 返回扫描报告总表 · ← dshlib 图书馆

扫描报告 · mindscale-noah/MindMemOS

认证等级L2
验证状态self-declared(单方声明,待独立验证)
验证方法未登记 structured verifiedBy
运行级实测未做运行级实测
内容锚git commit 186db4a75122 · mindscale-noah/MindMemOS · git ls-remote / clone 复现可对账
DIDdid:cha2a:package:mindscale-noah/MindMemOS
身份锚点npm 未声明 GitHub 仓库——装前请自行核验来源
来源git
插件版本—
安装dsh plugin add github:mindscale-noah/MindMemOS
扫描日期2026-08-26(37 天前)
扫描层级静态扫描(自研规则 + GuardDog 复核 + OSV 依赖)
扫描器版本dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev

自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描

⚠️ 结论待复核:上次扫描距今 37 天(2026-08-26),插件或运行时更新后结论可能过期,建议重新扫描后再安装。
语义:扫描是提示信号,非安全审查。✅ 通过=无命中;⚠️ 待审=有命中需人工判断;❌ 失败=无法扫描。人工确认恶意→下架。本页全部内容由 dshlib 数据库派生(验证报告 可核对证据)。认证等级与依赖漏洞正交:L4 认证覆盖插件包内容/来源/生态,不覆盖依赖安全(见收录与验证标准)。结论有有效期:插件或运行时更新后,本页结论可能过期(>30 天将标注待复核)。本库能力与边界:披露页。

1. 自研扫描(dshlib-scan)

verified

True

findings

{'hardcoded_secrets': [{'file': 'MindMemOS-main/README.md', 'line': 199, 'match': 'api_key="<api_key>"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/README_ZH.md', 'line': 187, 'match': 'api_key="<api_key>"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 237, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 286, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 321, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 342, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 362, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 387, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 415, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 432, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_auth.py', 'line': 452, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 62, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 89, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 122, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 164, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 188, 'match': 'secret="test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 204, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/api/test_internal_routes.py', 'line': 246, 'match': 'secret = "test-internal-secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/llm/test_router.py', 'line': 167, 'match': 'api_key="service-token"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/mindmemos_sdk/test_config_manager.py', 'line': 26, 'match': 'api_key="mk_secret"', 'label': '明文凭据'}, {'file': 'MindMemOS-main/tests/scripts/test_send_async_add.py', 'line': 35, 'match': 'api_key="test-key"', 'label': '明文凭据'}], 'data_exfiltration': [{'file': 'MindMemOS-main/docs/config/README.md', 'line': 192, 'match': 'token_budget` | `1` | Minimum token budget accepted for request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/docs/config/README.md', 'line': 193, 'match': 'token_budget` | `128000` | Maximum token budget accepted for request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/docs/config/README.md', 'line': 198, 'match': 'token cost relative to the request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/docs/eval/README.md', 'line': 212, 'match': 'tokens/query` / `search_avg_tokens/call` | ClickHouse | Search-stage token total', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/docs/eval/README.md', 'line': 249, 'match': 'token percentiles | ClickHouse (per search *request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/api/schemas.py', 'line': 6, 'match': 'api_key_uuid`` / ``scopes`` / ``request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/config/algo/search/retention.py', 'line': 13, 'match': 'token budget accepted for request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/config/algo/search/retention.py', 'line': 16, 'match': 'token budget accepted for request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/config/algo/search/retention.py', 'line': 31, 'match': 'token cost relative to the request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos_eval/mindmemos_eval/memory/metrics.py', 'line': 217, 'match': 'token_percentiles_sql(run, request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/src/mindmemos_eval/mindmemos_eval/memory/metrics.py', 'line': 220, 'match': 'token_percentiles_sql(run, request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 88, 'match': 'token = request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/tests/pipelines/add/test_schema_pipeline.py', 'line': 657, 'match': 'api_key": "sk-request', 'label': '凭据字段进入网络请求'}, {'file': 'MindMemOS-main/tests/pipelines/add/test_schema_pipeline.py', 'line': 666, 'match': 'api_key": "sk-request', 'label': '凭据字段进入网络请求'}], 'dangerous_commands': [{'file': 'MindMemOS-main/src/mindmemos/mindmemos/api/app.py', 'line': 70, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/api/app.py', 'line': 78, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/infra/kafka/dispatcher.py', 'line': 119, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/infra/kafka/producer.py', 'line': 30, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/infra/telemetry.py', 'line': 147, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/infra/telemetry.py', 'line': 150, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/pipelines/add/schema/schema_add.py', 'line': 1185, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/src/mindmemos/mindmemos/pipelines/add/schema/schema_add.py', 'line': 1340, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 53, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 80, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 94, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 110, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'MindMemOS-main/tests/components/searcher/vanilla/test_executor.py', 'line': 140, 'match': 'shutdown', 'label': '系统关机'}], 'manifest_contract': [{'file': 'package.json', 'line': 0, 'match': 'main: ./dist/index.js', 'label': 'main 入口「./dist/index.js」在包内不存在——加载会报 Cannot find module'}]}

mode

git-refresh

branch

main

2. 第三方复核(GuardDog 3.2.0)

未复核。

3. 依赖漏洞(OSV.dev)

未查询。