社区目录预览DeepSeek Harness 仍处于开发者预览阶段
DS

dsh-security-scan

插件已确认插件社区发布

ben7am1n/dsh-security-scan · 19 天前更新

安装方式

dsh plugin --profile web add /path/to/dsh-security-scan
dsh plugin --profile web add github:
dsh plugin --profile web add dsh-security-scan
dsh plugin --profile web add github:ben7am1n/dsh-security-scan

仓库内包含的插件

  • dsh-security-scanv0.1.0

    Secret & dangerous-pattern scanner for DeepSeek Harness — a security_scan tool that finds leaked API keys, tokens, private keys and credential files, with full redaction.

    package.json
    package.json
    dsh.bundle.patch
    cordis.patch.yml
    官方核心包 (4)
    • @deepseek-ai/cordis^4.0.1共享
    • @deepseek-ai/dsh-llm^0.1.0-rc.6共享
    • @deepseek-ai/dsh-tools^0.1.0-rc.6共享
    • @deepseek-ai/schemastery^3.18.1私有副本

路径固定于提交 b212b9af646b

概览

Secret & dangerous-pattern scanner for DeepSeek Harness — one securityscan tool that walks your files and reports leaked API keys, tokens, private keys, and credential-bearing connection strings. Zero runtime dependencies (pure Node built-ins).

仓库检查结果

结果绑定到所列 commit,仅涵盖本站实际执行的静态检查。证据分衡量可复核信息的完整度,不是兼容性百分比,也不构成安全保证。

仓库静态检查

高风险
检查 Commit
b212b9af646b
证据分
66/100
静态风险
高风险
扫描文件
2
检查发现
2

证据分项

来源溯源20/25
安装文档25/25
维护状况12/20
兼容性证据5/20
安全信号0/10

兼容性置信度: 有限

安装期脚本 (1)
  • preparetsc -p tsconfig.json
检查发现 (2)
  • install.script
    package.jsoninstall-time
    "prepare": "tsc -p tsconfig.json"
  • deps.core-package-installed
    package.jsondependencies
    "@deepseek-ai/schemastery": "^3.18.1"
未执行的检查
  • 依赖漏洞数据库扫描
  • 实际安装测试
  • 运行时行为验证

扫描器 1.0.0 · 评分器 1.0.0