Replies: 2 comments 1 reply
|
You're right that the raw numbers are exploding and that "near-duplicate + potentially malicious" is the real risk. The practical answer is not necessarily official centralization (the team hasn't opened the PR channel, and a full official review org is heavy), but a layered, verifiable trust model — and most of the layers already exist in community form:
The honest caveat: none of these alone is a silver bullet, and "AI review" has a false-negative problem — a policy inconsistency that a static check catches instantly is exactly the kind of thing an LLM reviewer will often miss, and vice versa. That's why the useful model is gate = registry-verified AND static-audit-clean AND (optionally) LLM-reviewed, not "official team approves every plugin". If the maintainers want to define a single canonical |
|
插件库安全担忧很真实——上千个插件、近三分之一功能近似、可能埋恶意代码,官方审核或 AI 审核确实该上。 这和我们第 13 章的判断一致:安全工具链(vetting/check-dsh-profile/Plugin Doctor/Codex 门禁)先顶上,官方 registry + 审核是治本。https://github.com/Electricitysheep/dsh-handbook/blob/main/docs/13-security.md |
Uh oh!
There was an error while loading. Please reload this page.
现在一眼望去插件的库都是每天上千个,近似功能的可能有三分之一,而且有可能植入恶意代码/提示词。应该由官方统一审核管理才行吧,或者上一套AI审核的核心。
All reactions