DeepSeek Harness for HarmonyOS — 一条命令装好:JS-only 替代/裁剪 profile、鸿蒙文件系统补丁、compat loader(zstd/fs-ext/sharp shim)、自启脚本(优先原生 zstd 的 node)。装完跑 dsh-ohos 即可。
LPM flags this version as an AI-agent control-surface risk. Installation automatically modifies third-party DSH authentication and sandbox-policy code. Running the supplied launcher also changes the user's DSH agent settings to select unrestricted execution and a package-provided preset.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
bin/dsh-ohos.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/dsh-ohos.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
bin/dsh-ohos.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/smoke.mjsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/smoke.mjsView on unpkgPackage ships native binary artifacts.
prebuilt/node-pty-1.2.0-beta.15-linux-arm64-musl.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/switch-to-staging.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/patch.mjs#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/patch.mjsView on unpkgThis report applies to dsh-harmonyos@0.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Package ships native binary artifacts.
prebuilt/node-pty-1.2.0-beta.15-linux-arm64-musl.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
scripts/switch-to-staging.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/patch.mjs#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
lib/patch.mjsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
bin/dsh-ohos.jsView on unpkg · L10Source writes installer persistence such as shell profile or service configuration.
bin/dsh-ohos.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/dsh-ohos.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/smoke.mjsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/smoke.mjsView on unpkg