omdsh-dev/dsh-security-audit
DSH native security audit plug-in: Configuration/Plug-in Source/Session/Network Exposure, read-only desensitization risk report
dsh-security-audit is a defensive, read-only local security audit plugin for DeepSeek Harness: it audits the local DSH environment and outputs redacted, reproducible, locatable risk reports covering six areas: (1) Configuration — service listening addresses, WebUI exposure, auto-update settings, debug flags; (2) Credential storage metadata — API key file locations, permissions, key count, type/length/HMAC fingerprint (values never output); (3) Installed plugin provenance — source (npm/GitHub/local), match against known-safe list, flag unsigned/unverified sources; (4) Key path permissions — home directory, DSH home, session directory, config files; (5) Session file structure — presence of anomalous session files, unexpected formats; (6) Network exposure surface — whether the web server is listening beyond localhost, open ports that could expose DSH to the local network or internet. The plugin outputs a structured risk report with severity levels (info / warning / risk) and locatable evidence (file path + line number where applicable). Designed to complement: dsh-session-health (session file diagnostics) and dsh-plugin-healthcheck (plugin structure compliance) — security-audit adds credential exposure and network exposure auditing.
Install
dsh plugin --profile web add github:omdsh-dev/dsh-security-auditGitHub source install (no npm package as of 2026-08-23): dsh plugin --profile web add github:omdsh-dev/dsh-security-audit. Also available as an npm pack tarball: npm pack in the repo, then dsh plugin --profile web add dsh-security-audit-*.tgz. The bundled dsh.bundle.patch automatically adds the plugin to the profile's layer stack after installation. Install for headless profile: dsh plugin --profile headless add github:omdsh-dev/dsh-security-audit.
Compatibility
DeepSeek Harness web and headless profiles. Read-only: never modifies or deletes any file, never executes the code of audited plugins, never proactively connects to remote endpoints. Secret redaction: suspected secrets return only type / length / in-process random HMAC fingerprint / path / line number — full values never appear in canonical output (design-level guarantee, not truncation). Scope: configuration, credential storage metadata, installed plugin provenance, key path permissions, session file structure, and network exposure surface. Complements dsh-session-health (which diagnoses session file corruption) and dsh-plugin-healthcheck (which checks plugin structure/compliance) — security-audit adds the credential exposure and network exposure angle.
Details
- Repo: omdsh-dev/dsh-security-audit
- Category: Agent Capabilities
- Stars: 13
- Version: GitHub source install from omdsh-dev/dsh-security-audit (no npm package; 2026-08-23)
- Last push: 2026-09-10
- First seen: 2026-08-10
Recent updates
The current English README (README.en.md, primary English) documents: six audit domains (config, credential metadata, plugin provenance, path permissions, session structure, network exposure), security model (read-only, secret redaction, path fencing, zero business dependencies), tool declaration (session_health equivalent for security auditing), and installation (GitHub source + npm pack tarball, web and headless profiles).
FAQ
- Does the plugin read or expose my API keys or secrets?
- No — secrets are only reported as type / length / in-process random HMAC fingerprint / path / line number. Full values never appear in any output. This is a design-level guarantee, not a truncation.
- How does this differ from dsh-plugin-healthcheck?
- dsh-plugin-healthcheck checks plugin structure and compliance (missing files, bad deps, build scripts). dsh-security-audit adds a different angle: credential exposure surface, plugin provenance trustworthiness, network listening exposure, and key path permissions — it is concerned with real-world risk, not plugin format correctness.
- Can the audit damage or modify my DSH installation?
- No — the plugin is strictly read-only. It never modifies or deletes any file, never executes the code of audited plugins, and never proactively connects to remote endpoints.
Alternatives
chenw2759-wq/dsh-plugin-healthcheck · omdsh-dev/dsh-session-health · omdsh-dev/dsh-advisor