ben7am1n/dsh-security-scan

A secret & dangerous-pattern scanner for DeepSeek Harness — one security_scan tool that walks your files and reports leaked API keys, tokens, private keys, and credential-bearing connection strings. It reports findings redacted, so raw key material never reaches the model context or the logs; zero runtime dependencies (pure Node built-ins); 19 vitest tests.

Other ★ 1 updated 2026-08-13 ✅ runtime-tested
View on GitHub ↗

Install

pnpm dsh plugin --profile web add /path/to/dsh-security-scan

pnpm dsh plugin --profile web add /path/to/dsh-security-scan (local checkout; pnpm runs the prepare script, so allow it once — copy the printed package key for pnpm-workspace.yaml if blocked; verified 2026-08-30). Uninstall: pnpm dsh plugin --profile web remove dsh-security-scan.

Compatibility

DSH web profile; @deepseek-ai/dsh 0.1.0-rc.6 / @deepseek-ai/cordis ^4.0.1; zero runtime dependencies (pure Node built-ins); MIT.

Details

Recent updates

One security_scan tool; finds leaked keys/tokens/private keys/connection strings; redacted output; zero runtime deps; 19 tests.

FAQ

What does it scan for?
Leaked API keys, tokens, private keys and credential-bearing connection strings across the files you point it at.
Is output redacted?
Yes — findings are reported redacted so raw key material never reaches the model context or the logs.
Does it need dependencies?
No — zero runtime dependencies, pure Node built-ins.

Alternatives

MkaliezZ/dsh-agentfuse-plugin · Zenquiem/dsh-security-suite · LeslieWylie/dsh-fleet-audit

More plugins in Other

Browse more in Other

Guides for Other plugins