DSH Sentinel Scanner
Eligahyu/dsh-sentinel-scanner · skills
Heuristic rules, AST/taint analysis, package quarantine, dependency intelligence, SBOM export, SARIF, and CI policy enforcement—without executing scanned code.
★ 6GitHub stars
0Forks
2026-08-31Last updated
JavaScriptLanguage
MITLicense
Key features
- Heuristic rules51 rules across execution, credentials, exfiltration, obfuscation, install scripts, filesystem, network, manifests, Agent Tools, taint, supply chain, binaries, and persistence.
- Scan completeness distinguishes security-critical coverage from optional enrichment
- Static completeness and dynamic completeness are separate signals.
- Workspace importer paths are containment-checked
- Agent Tool analysisTraces defineTool inputs such as args.
Install command
dsh plugin --profile web add github:Eligahyu/dsh-sentinel-scanner