← 返回扫描报告总表 · ← dshlib 图书馆

扫描报告 · taxueseek/argo

认证等级L2
验证状态registry-confirmed(有 registry 凭证证据)
验证方法未登记 structured verifiedBy
运行级实测未做运行级实测
内容锚git commit 588bbbfba625 · taxueseek/argo · git ls-remote / clone 复现可对账
DIDdid:cha2a:package:taxueseek/argo
身份锚点npm 未声明 GitHub 仓库——装前请自行核验来源
来源git
插件版本—
安装dsh plugin add github:taxueseek/argo
扫描日期2026-08-27(36 天前)
扫描层级静态扫描(自研规则 + GuardDog 复核 + OSV 依赖)
扫描器版本dshlib-scan v0.1 · GuardDog 3.2.0 · OSV.dev

自研扫描:⚠️ 待审 · GuardDog 复核:未扫描 · OSV 依赖:未扫描

⚠️ 结论待复核:上次扫描距今 36 天(2026-08-27),插件或运行时更新后结论可能过期,建议重新扫描后再安装。
语义:扫描是提示信号,非安全审查。✅ 通过=无命中;⚠️ 待审=有命中需人工判断;❌ 失败=无法扫描。人工确认恶意→下架。本页全部内容由 dshlib 数据库派生(验证报告 可核对证据)。认证等级与依赖漏洞正交:L4 认证覆盖插件包内容/来源/生态,不覆盖依赖安全(见收录与验证标准)。结论有有效期:插件或运行时更新后,本页结论可能过期(>30 天将标注待复核)。本库能力与边界:披露页。

1. 自研扫描(dshlib-scan)

verified

True

findings

{'hardcoded_secrets': [{'file': 'argo-main/config.yaml', 'line': 2992, 'match': "api_key: '{TAVILY_API_KEY}'", 'label': '明文凭据'}, {'file': 'argo-main/tests/test_archive_redact.py', 'line': 78, 'match': 'secret = "sk-ARGO-TEST-SECRET-VALUE"', 'label': '明文凭据'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 97, 'match': 'sk-FIRST1111111111aaa', 'label': 'OpenAI API key'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 97, 'match': 'sk-SECOND2222222222bbb', 'label': 'OpenAI API key'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 100, 'match': '"sk-SECOND2222222222"', 'label': 'OpenAI API key'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 115, 'match': 'sk-bareKEY123456789', 'label': 'OpenAI API key'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 118, 'match': '"sk-bareKEY123456789"', 'label': 'OpenAI API key'}, {'file': 'argo-main/tests/test_twitter_syndication.py', 'line': 81, 'match': 'token=" in url and not url.endswith("', 'label': '明文凭据'}, {'file': 'argo-main/tests/test_twitter_syndication.py', 'line': 81, 'match': 'token=")\n\n\nclass TestBuilder:\n    "', 'label': '明文凭据'}], 'data_exfiltration': [{'file': 'argo-main/docs/RELEASE_NOTES_v2.8.5.md', 'line': 71, 'match': 'os.environ 优先),改文件即生效无需重启;search 引擎与 fetch 渲染层同真源,修复「search 能用、fetch', 'label': '读取敏感数据后发起网络请求'}, {'file': 'argo-main/docs/数据源扩展与算法改进调研_2026-09-12.md', 'line': 44, 'match': 'token;一个 key 通吃搜索+抓取 | **免 key 通道已死(401 bad IP reputation)**;注册后 s.jina.ai 是少见 g', 'label': '凭据字段进入网络请求'}, {'file': 'argo-main/docs/数据源扩展与算法改进调研_2026-09-12.md', 'line': 54, 'match': 'token;旧 Sonar 支持至 2026-09-27 | 「一步出带引用摘要」与已有 evidence/fetch', 'label': '凭据字段进入网络请求'}, {'file': 'argo-main/tests/test_fetch_focus_cli.py', 'line': 6, 'match': 'token」),但入口 scripts/fetch', 'label': '凭据字段进入网络请求'}, {'file': 'argo-main/tests/test_key_redaction.py', 'line': 56, 'match': 'secrets(f"The security token included in the request', 'label': '凭据字段进入网络请求'}], 'dangerous_commands': [{'file': 'argo-main/docs/代码质量审查_排序管线与子技能_2026-09-13.md', 'line': 104, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/docs/代码质量审查_排序管线与子技能_2026-09-13.md', 'line': 294, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/scripts/bounded_run.py', 'line': 8, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/scripts/cli_io.py', 'line': 174, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/scripts/engine_dispatch.py', 'line': 672, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/scripts/mcp_handlers.py', 'line': 465, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/scripts/search.py', 'line': 242, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/sub-skills/local-search/search_v3.py', 'line': 1177, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/sub-skills/local-search/search_v3.py', 'line': 1307, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/tests/test_cache_reclaim.py', 'line': 215, 'match': 'TRUNCATE', 'label': '数据库破坏'}, {'file': 'argo-main/tests/test_cli_stdin_and_positional.py', 'line': 241, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/tests/test_conn_pool.py', 'line': 217, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 10, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 249, 'match': 'shutdown', 'label': '系统关机'}, {'file': 'argo-main/tests/test_search_executor_singleton.py', 'line': 4, 'match': 'shutdown', 'label': '系统关机'}], 'excessive_permissions': [{'file': 'argo-main/packages/dsh-plugin/dsh/index.js', 'line': 1050, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/scripts/content_security.py', 'line': 286, 'match': '"sudo"', 'label': '完全访问'}, {'file': 'argo-main/scripts/hot_state.py', 'line': 84, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/scripts/mcp_transport.py', 'line': 90, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/scripts/recompute.py', 'line': 88, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 85, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 125, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 133, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 141, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 153, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 164, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 183, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_per_engine_budget.py', 'line': 220, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 367, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 408, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 417, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_race_fast_budget_0906.py', 'line': 432, 'match': 'exec(', 'label': '命令执行'}, {'file': 'argo-main/tests/test_yaml_loader_centralized.py', 'line': 414, 'match': 'exec(', 'label': '命令执行'}], 'manifest_contract': [{'file': 'package.json', 'line': 0, 'match': 'main: ./dsh/index.js', 'label': 'main 入口「./dsh/index.js」在包内不存在——加载会报 Cannot find module'}]}

mode

git-refresh

branch

main

2. 第三方复核(GuardDog 3.2.0)

未复核。

3. 依赖漏洞(OSV.dev)

未查询。