DSH Code Security
STARDUSTLC666/dsh-code-security · tools
DSH AI Code Security Review Plugin: Ten Tool Scanning for certainty (40+ rules, key entropy testing, saged diff, SARIF export), Baseline Acceptance, SBOM-lite relying on checklists and health self-inspection, and zero running.
★ 2GitHub stars
0Forks
2026-09-05Last updated
JavaScriptLanguage
MITLicense
Key features
- Encryptionweak Hashi, ECB, hard-coding IV/keys, JWT none, TLS Validation Closed, Shell TLS circumvented (curl-k / wget --no-check-certificate / glt sslVerify = false)
- DocumentHard code password, token, private key, high entropy key
- LeakSensitive logs, error stacks out, route crossing, SSR
Requirements
- Validation under @deepseek-ai/dsh@0.1.2-alpha.4 Source mode (2026-09-02).
- Follows the Cordis package patch model (cordis.pact.yml + dsh.bundle.pay) and runs without imitation of any @deepseek-ai/ internal module.
Install command
dsh plugin --profile web add github:STARDUSTLC666/dsh-code-security