Back to plugin

Security audit

DSH Bridge

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly disclosed chat-to-DeepSeek Harness bridge with powerful remote-control implications, but its behavior matches its stated purpose and includes visible safety guidance.

Only install and enable this if you intend chat messages to control your DSH desktop session. Set allowedSenders to your own account before use, keep allowGroups false unless you truly need group access, and leave bridge URLs pointed at trusted local endpoints.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:33
Evidence
"description": "Base URL of the DSH-side plugin routes. Default http://127.0.0.1:19387/phone-bridge"