A Practical Security Guide for dsh Plugins
2026-08-14
Plugins are code
A dsh plugin can declare tools, hooks and UI — and, like any npm package, it can run arbitrary code during installation and at runtime. Treat each plugin the way you treat a new dependency in your own project.
What to check before installing
Look at the repository's license, activity, and documentation, and prefer an install path that does not ask for credentials. Our health score combines license, community adoption, documentation, and distribution — real signals, not a substitute for reviewing the source.
Limit privileges
Run untrusted plugins in a dedicated profile, review manifests before first run, and pin commits for GitHub installs. Audit your installed plugins periodically with a plugin health check.