DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dshscan

Dual-channel security scanner for DSH plugins with DSH-specific attack surface rules, npm audit, and HTML reports.

UI & ProductivityTerminal & TUIDeveloper ToolsSecurity & PolicySkills & WorkflowsRemote Execution
10GitHub Stars0ForksUpdated2026-08-21

Install

No clear install command was found in the current repository evidence.

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
DShScan is a security scanner designed specifically for DeepSeek Harness plugins. It performs static analysis and optional LLM semantic analysis on plugin source code, ZIP archives, GitHub repositories, or local directories. It detects DSH-specific attack vectors including cordis.patch.yml tree injections, client-side browser exploits, and profile tampering, while offering npm dependency audits, customizable policies, benchmark evaluation suites, and an interactive local dashboard.

Key Capabilities

  • Dual-channel analysis using offline static rules and optional LLM-assisted semantic scanning
  • Detection of DSH-specific attack vectors including cordis.patch.yml injections, client.mjs browser exploits, and profile tampering
  • Source code inspection across GitHub repositories, npm packages, local directories, ZIP archives, and Markdown documentation
  • Supply chain dependency security auditing and npm audit integration
  • Custom JSON rules and policy configuration with severity overrides and scope filtering
  • HTML and JSON report generation with risk scoring, severity ratings, and contextual evidence
  • Local web dashboard service with historical scan trends and severity distributions

Useful For

  • Auditing third-party DeepSeek Harness plugins before installing them into local environments
  • Integrating automated security scans into CI/CD pipelines for DSH plugin development
  • Batch scanning plugin registries and directories to evaluate ecosystem supply chain security
  • Investigating suspicious plugin behaviors and checking compliance with custom security policies

Who It Fits

  • DeepSeek Harness plugin developers
  • Security engineers auditing DSH plugins and supply chains
  • DSH ecosystem maintainers and registry operators

Documented Limitations

  • Semantic LLM scanning requires an external API key (e.g., DSCAN_LLM_API_KEY or OPENAI_API_KEY)
  • Remote GitHub scanning requires network access unless running in offline metadata-only mode
  • Reports truncate findings display after 100 entries, though scoring reflects all findings

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 2 runtime, 5 development, 1 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
shaoshi20/dshscan
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
0633b01 · 2026-08-29

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
10GitHub stars
Forks
0
Open issues
1
Last commit
2026-08-21
Last release
2026-08-20
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app