ben7am1n/dsh-security-scan
A secret & dangerous-pattern scanner for DeepSeek Harness — one security_scan tool that walks your files and reports leaked API keys, tokens, private keys, and credential-bearing connection strings. It reports findings redacted, so raw key material never reaches the model context or the logs; zero runtime dependencies (pure Node built-ins); 19 vitest tests.
Install
pnpm dsh plugin --profile web add /path/to/dsh-security-scanpnpm dsh plugin --profile web add /path/to/dsh-security-scan (local checkout; pnpm runs the prepare script, so allow it once — copy the printed package key for pnpm-workspace.yaml if blocked; verified 2026-08-30). Uninstall: pnpm dsh plugin --profile web remove dsh-security-scan.
Compatibility
DSH web profile; @deepseek-ai/dsh 0.1.0-rc.6 / @deepseek-ai/cordis ^4.0.1; zero runtime dependencies (pure Node built-ins); MIT.
Details
- Repo: ben7am1n/dsh-security-scan
- Category: Other
- Stars: 1
- Version: GitHub source (no npm package)
- Last push: 2026-08-13
- First seen: 2026-08-13
Recent updates
One security_scan tool; finds leaked keys/tokens/private keys/connection strings; redacted output; zero runtime deps; 19 tests.
FAQ
- What does it scan for?
- Leaked API keys, tokens, private keys and credential-bearing connection strings across the files you point it at.
- Is output redacted?
- Yes — findings are reported redacted so raw key material never reaches the model context or the logs.
- Does it need dependencies?
- No — zero runtime dependencies, pure Node built-ins.
Alternatives
MkaliezZ/dsh-agentfuse-plugin · Zenquiem/dsh-security-suite · LeslieWylie/dsh-fleet-audit