Security audit for DeepSeek Harness plugins
jkrandom-sudo/dsh-plugin-audit · skills
Know what a DSH plugin can do before you let it run.
★ 5GitHub stars
0Forks
2026-08-28Last updated
TypeScriptLanguage
MITLicense
Key features
- Static audit — the plugin_audit tool.
- dsh-plugin-audit profiles third-party plugins statically — which files, processes, hosts, env vars and credential paths their code touches, with file/line evidence — and arms a runtime sentinel that asks for your approval when any tool call reaches for credentials or moves data to unknown hosts.
- Read-only scanner — read handles only, capped at 400 files / 256 KB per file, skipping node_modules, .git, lib, dist.
- dsh-plugin-audit/invariantpending (waiting for service: invariants) at boot — you wired the invariant row into a profile without the invariants service
- Point it at any plugin directory
Requirements
- DSH is in developer preview and ships breaking changes frequently
- the date above records the mainline snapshot this release was verified against.
Install command
dsh plugin --profile web add github:jkrandom-sudo/dsh-plugin-audit