DeepSeek Harness mobile remote-control plugin: LAN/external remote control (QR / on-off toggle / remote-access password gate), rich telemetry (expandable device details, system CPU/memory/load, DSH app state: version/sessions/workspaces/plugins/models), r
LPM treats this as warn-only first-party agent extension lifecycle risk. After a user invokes the external-tunnel API, the plugin downloads and executes an frpc binary, then broadens the DSH profile's trusted hosts. This is a high-impact remote-access capability, but source does not show credential theft or covert triggering.
Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L23This report applies to @feiyang666/dsh-mobile-remote@1.4.3.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L23Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L23