LeslieWylie/dsh-fleet-audit
DSH agent-fleet hygiene audit plugin: credential-file permissions, embedded git-
dsh-fleet-audit is a read-only agent-fleet hygiene audit plugin for DSH that checks three things and masks every secret-like value in its output. (1) Credential-file permissions: well-known files (~/.gitconfig, ~/.netrc, ~/.npmrc, ~/.env, ~/.ssh/) should be 600/700, and group/other-readable entries are flagged tooOpen. (2) Embedded credentials in git remotes: it scans ~/.gitconfig and .git/config under the given roots for https://user:pass@host, https://oauth2:TOKEN@host, or token-like usernames, masking values as *** with a byte-for-byte guarantee the raw secret never appears. (3) Optional provider token-prefix literals (github / github-fine-grained / gitlab / gitlab-ci / slack / aws / openai / jwt) reported as provider x count only. It exposes one fleet_audit tool with parameters roots, files, scanSecrets, maxGitConfigs, and maxDepth.
Install
dsh plugin --profile web add github:LeslieWylie/dsh-fleet-auditIt documents three forms: a local validation install (dsh plugin --profile web add /path/to/dsh-fleet-audit), and, after publishing, dsh plugin --profile web add dsh-fleet-audit or dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit. The npm name dsh-fleet-audit was NOT found on the registry on 2026-09-30, so use the GitHub-source form shown here. Restart dsh web after installing, then ask the agent to "audit credential hygiene on this machine" (it calls fleet_audit). Roll back with dsh plugin --profile <p> remove dsh-fleet-audit.
Compatibility
DeepSeek Harness. Zero-dependency, deterministic, read-only: no writes, no process spawn, no network, no state. The README notes it is an independent community plugin with no affiliation to DeepSeek; the dsh-plugin topic is added for discoverability at release time. Its default checks cover a fixed credential list; pass roots / files to cover arbitrary paths. Uninstalling never touches user data.
Details
- Repo: LeslieWylie/dsh-fleet-audit
- Category: Coding & Development
- Stars: 1
- Version: GitHub source install (npm name dsh-fleet-audit NOT published -- registry empty 2026-09-30); MIT (c) LeslieWylie
- Last push: 2026-08-18
- First seen: 2026-08-14
Recent updates
The README documents the tool parameter table (roots, files, scanSecrets default true, maxGitConfigs default 200 max 2000, maxDepth default 5 max 20), a masked sample output object, the safety boundary (read-only, masked, bounded), the dev flow (npm install, npm run check), known limitations (textual config files only; token-prefix matching is heuristic; default checks cover a fixed credential list; the plugin never modifies anything -- run chmod 600 and rotate the credential yourself), and a rollback command.
FAQ
- How do I install dsh-fleet-audit?
- Per the README, install from GitHub source with dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit, then restart dsh web. The npm name dsh-fleet-audit is not published, so use the GitHub-source form.
- Can it leak my secrets?
- No -- the README states output is masked and tests assert the raw secret never appears in the output JSON; the plugin is read-only with no writes, no process spawn, no network, and no state.
- What does it check?
- Three things per the README: credential-file permissions (600/700 expected), embedded credentials in git remotes (masked), and optionally provider token-prefix literals reported as provider x count only.
Alternatives
ben7am1n/dsh-security-scan · bigclawd/dsh-security-guard · ChenLaoshiYF/dsh-mcpguard