DeepSeek Harness mobile remote-control plugin: LAN/external remote control (QR / on-off toggle / remote-access password gate), rich telemetry (expandable device details, system CPU/memory/load, DSH app state: version/sessions/workspaces/plugins/models), r
At runtime, the external-tunnel endpoint can obtain a native frpc binary and execute it. The package can also expose the DSH web server on all interfaces by changing its profile patch.
Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L23A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L23This report applies to @feiyang666/dsh-mobile-remote@1.4.5.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/external.jsView on unpkg · L23Source appears to send environment or credential material to an external endpoint.
lib/external.jsView on unpkg · L23A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/external.jsView on unpkg · L23A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
lib/external.jsView on unpkg · L23