This plugin is local-first:
- It only reads DSH session logs under
~/.dsh/sessions(or$DSH_HOME/sessions). - It does not send telemetry, does not call external APIs, and does not read credentials.
- Its HTTP API is loopback-only and returns token usage/cost statistics.
If you find a security issue, please open a private GitHub advisory or contact the repository owner.