LeslieWylie/dsh-fleet-audit

DSH agent-fleet hygiene audit plugin: credential-file permissions, embedded git-

dsh-fleet-audit is a read-only agent-fleet hygiene audit plugin for DSH that checks three things and masks every secret-like value in its output. (1) Credential-file permissions: well-known files (~/.gitconfig, ~/.netrc, ~/.npmrc, ~/.env, ~/.ssh/) should be 600/700, and group/other-readable entries are flagged tooOpen. (2) Embedded credentials in git remotes: it scans ~/.gitconfig and .git/config under the given roots for https://user:pass@host, https://oauth2:TOKEN@host, or token-like usernames, masking values as *** with a byte-for-byte guarantee the raw secret never appears. (3) Optional provider token-prefix literals (github / github-fine-grained / gitlab / gitlab-ci / slack / aws / openai / jwt) reported as provider x count only. It exposes one fleet_audit tool with parameters roots, files, scanSecrets, maxGitConfigs, and maxDepth.

Coding & Development ★ 1 updated 2026-08-18 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit

It documents three forms: a local validation install (dsh plugin --profile web add /path/to/dsh-fleet-audit), and, after publishing, dsh plugin --profile web add dsh-fleet-audit or dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit. The npm name dsh-fleet-audit was NOT found on the registry on 2026-09-30, so use the GitHub-source form shown here. Restart dsh web after installing, then ask the agent to "audit credential hygiene on this machine" (it calls fleet_audit). Roll back with dsh plugin --profile <p> remove dsh-fleet-audit.

Compatibility

DeepSeek Harness. Zero-dependency, deterministic, read-only: no writes, no process spawn, no network, no state. The README notes it is an independent community plugin with no affiliation to DeepSeek; the dsh-plugin topic is added for discoverability at release time. Its default checks cover a fixed credential list; pass roots / files to cover arbitrary paths. Uninstalling never touches user data.

Details

Recent updates

The README documents the tool parameter table (roots, files, scanSecrets default true, maxGitConfigs default 200 max 2000, maxDepth default 5 max 20), a masked sample output object, the safety boundary (read-only, masked, bounded), the dev flow (npm install, npm run check), known limitations (textual config files only; token-prefix matching is heuristic; default checks cover a fixed credential list; the plugin never modifies anything -- run chmod 600 and rotate the credential yourself), and a rollback command.

FAQ

How do I install dsh-fleet-audit?
Per the README, install from GitHub source with dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit, then restart dsh web. The npm name dsh-fleet-audit is not published, so use the GitHub-source form.
Can it leak my secrets?
No -- the README states output is masked and tests assert the raw secret never appears in the output JSON; the plugin is read-only with no writes, no process spawn, no network, and no state.
What does it check?
Three things per the README: credential-file permissions (600/700 expected), embedded credentials in git remotes (masked), and optionally provider token-prefix literals reported as provider x count only.

Alternatives

ben7am1n/dsh-security-scan · bigclawd/dsh-security-guard · ChenLaoshiYF/dsh-mcpguard

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins