DeepSeek Harness mobile remote-control plugin: LAN/external remote control (QR / on-off toggle / remote-access password gate), rich telemetry (expandable device details, system CPU/memory/load, DSH app state: version/sessions/workspaces/plugins/models), r
A reachable plugin endpoint accepts an unrestricted tunnel-server URL. It downloads an executable from that server, saves it locally, and starts it.
Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L8A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L8This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/external.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L24A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L8A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThis report applies to @feiyang666/dsh-mobile-remote@1.7.1.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L24Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L8A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L8A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L8This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/external.jsView on unpkg