dshscan
Dual-channel security scanner for DSH plugins with DSH-specific attack surface rules, npm audit, and HTML reports.
Install
No clear install command was found in the current repository evidence.
Plugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Dual-channel analysis using offline static rules and optional LLM-assisted semantic scanning
- Detection of DSH-specific attack vectors including cordis.patch.yml injections, client.mjs browser exploits, and profile tampering
- Source code inspection across GitHub repositories, npm packages, local directories, ZIP archives, and Markdown documentation
- Supply chain dependency security auditing and npm audit integration
- Custom JSON rules and policy configuration with severity overrides and scope filtering
- HTML and JSON report generation with risk scoring, severity ratings, and contextual evidence
- Local web dashboard service with historical scan trends and severity distributions
Useful For
- Auditing third-party DeepSeek Harness plugins before installing them into local environments
- Integrating automated security scans into CI/CD pipelines for DSH plugin development
- Batch scanning plugin registries and directories to evaluate ecosystem supply chain security
- Investigating suspicious plugin behaviors and checking compliance with custom security policies
Who It Fits
- DeepSeek Harness plugin developers
- Security engineers auditing DSH plugins and supply chains
- DSH ecosystem maintainers and registry operators
Documented Limitations
- Semantic LLM scanning requires an external API key (e.g., DSCAN_LLM_API_KEY or OPENAI_API_KEY)
- Remote GitHub scanning requires network access unless running in offline metadata-only mode
- Reports truncate findings display after 100 entries, though scoring reflects all findings
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 2 runtime, 5 development, 1 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- shaoshi20/dshscan
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 0633b01 · 2026-08-29
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 10GitHub stars
- Forks
- 0
- Open issues
- 1
- Last commit
- 2026-08-21
- Last release
- 2026-08-20
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
A DeepSeek Harness notification plugin with a model-facing notify tool, automatic session-event alerts, and multi-channel delivery.
View plugin →A read-only DeepSeek Harness security and compliance plugin for injection scanning, PII redaction, and local configuration audits.
View plugin →Second-model approval reviewer for DeepSeek Harness that returns structured allow/deny verdicts with fail-closed fallback and session-log auditing.
View plugin →Composable three-tier memory control plane for DeepSeek Harness with runtime context, searchable documents, and pluggable long-term memory.
View plugin →