perrylink/dsh-skill-pack-security
Security audit methodology skills package: eight agent skills (key scanning, dependency audit, supply chain review, prompt injection review, audit orchestration, threat modeling, vulnerability intelligence, incident response), both Chinese and English versions; dsh plugin add @perrylink/dsh-skill-pack-security-provider One-click mounting
A skill pack plus supply-chain gate for DeepSeek Harness. It ships eight security methodologies as SKILL.md bundles the model discovers in its context: key scanning, dependency audit, supply-chain review and more, each step a real command (gitleaks, trivy, pnpm audit, npm view, git) with an expected-output sample and an exit-code criterion. Alongside the skills it provides plugin_vet, an automated pre-install gate that builds an SBOM from the lockfile, checks licenses, flags typosquats and mutable @tag/branch refs (commit pins must be immutable 40-hex SHAs), looks for malicious lifecycle scripts, exfiltration domains and obfuscated payloads, and feeds a warn (default) or deny install gate.
Install
dsh plugin --profile web add @perrylink/dsh-skill-pack-security-providernpm package @perrylink/dsh-skill-pack-security-provider 2.2.14 (registry-verified 2026-09-10; registry repository field -> github.com/PerryLink/dsh-skill-pack-security). The README also documents a git channel (github:PerryLink/dsh-skill-pack-security#main) and a tarball channel. After installing, restart and verify the row: dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'. Uninstall: dsh plugin --profile web remove @perrylink/dsh-skill-pack-security-provider.
Compatibility
DeepSeek Harness dsh-v0.1.5-rc.1 (README verified 2026-09-10; @deepseek-ai/dsh dependency line 0.1.5-rc.1). Skills are installed per language — skills/ (Chinese) or skills-en/ (English) — one language per root.
Details
- Repo: perrylink/dsh-skill-pack-security
- Category: Skill Packs
- Stars: 2
- Version: npm @perrylink/dsh-skill-pack-security-provider 2.2.14 (registry-verified 2026-09-10)
- Last push: 2026-09-21
- First seen: 2026-08-13
FAQ
- How do I install the security skill pack?
- Run: dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider, restart, then confirm the row with dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'. Git and tarball channels are also documented.
- What is plugin_vet?
- An automated pre-install scan: SBOM extraction from the lockfile, license and typosquat checks, commit-pinning validation, lifecycle-script and exfiltration/obfuscation pattern detection, and a five-dimension risk card.
- Can the gate block an install?
- Yes. gate.policy: warn (the default) only prints a warning on FAIL, while gate.policy: deny blocks installs that fail plugin_vet.
Alternatives
LayneChai/superpowers-dsh · Jayden-X-L/forkprobe · sandbaseai/sandbase-skills