DSH Hub

omdsh-dev/dsh-security-audit

dsh-security-audit

BundleWorkflow14 GitHub stars· updated 2026-09-10

dsh-security-audit is a community DeepSeek Harness plugin. Read the repository README before installing.

Install

npx @deepseek-ai/dsh plugin --profile <profile> add <source>`

Restart `dsh web` after install. Bundle APIs can change during the developer preview.

README badge

dsh-security-audit DSH Hub badge
[![DSH Hub](https://dshhub.dev/badge/dsh-security-audit.svg)](https://dshhub.dev/plugins/dsh-security-audit)

Paste this into your README. The star count updates with every catalog sync.

From the README

Excerpt from omdsh-dev/dsh-security-audit, cleaned of badges and images.

dsh-security-audit

English

DSH 本机安全审计插件 —— 防御性、只读的安全审计:配置、凭据存储元数据、已安装插件来源、关键路径权限、会话文件结构与网络暴露面。输出脱敏、可复现、可定位的风险报告。

仓库:https://github.com/omdsh-dev/dsh-security-audit(public)

动机

DSH 本地环境承载 API Key、token、会话内容和插件加载边界,误配置(服务监听公网、凭据文件权限过宽、插件来源不可信、会话文件结构异常)会造成真实风险。现有工具没有这个视角:

  1. plugin-check 只做结构/合规检查——不评估凭据暴露面、危险能力和路径逃逸
  2. session-health 只做健康诊断——不涉及来源可信度与安全风险裁定
  3. 手工排查不可复现——凭据位置、权限、监听端口、插件来源分散在多处,逐项人工检查极易遗漏且无法留档

本插件以只读方式审计本机 DSH 环境并输出风险报告:不自动修复、不连接远程、不执行被审计插件、不把"没读到"当作"安全"。

安全模型(审计器自身的边界)

  • 只读:绝不修改/删除任何文件,绝不执行被审计插件的代码,绝不主动连接远程目标
  • 秘密脱敏:疑似秘密只返回类型 / 长度 / 进程内随机 HMAC fingerprint / 路径 / 行号,完整值永不出现在 canonical 输出(设计级保证,非截断)
  • 路径围栏:所有路径经 lstat → realpath → containment 检查;root 固定为进程启动时解析的 $DSH_HOME(或管理员声明的 allowedRoot),模型参数不能扩大读取范围
  • 诚实判定:finding / pass / skipped / error 四态;skipped 与 error 不计为 pass(coverage 降为 incomplete);capability finding 只提示人工确认、不裁定恶意
  • 预算:
    • 文件 ≤ 200、插件 ≤ 200、会话 ≤ 1,000、findings ≤ 1,000
    • 源码单文件 ≤ 1 MiB(累计 ≤ 64 MiB);canonical 输出 ≤ 2 MiB
    • 单 action 10s / report 30s(deadline + AbortSignal 全程检查)
  • 工具参数会记入会话日志,不要传入敏感数据

工具声明

注册 security_audit 工具(@deepseek-ai/dsh-security-audit,row id security-audit),统一输出 JSON 文本字符串:所有 action 输出 { tool, version, root, platform, ... } 信封,扫描类 action 带 verdict/riskVerdict/coverageVerdict 与 summary。

action作用输出
scan_configDSH 配置、profile、env/credentials 元数据(秘密存在性、权限、外部端点)findings 含 secretKind/secretLength/fingerprint,无明文
scan_plugins已安装插件来源、路径、patch、危险静态能力、install script、秘密文件capability finding 标注人工确认
scan_sessions会话目录权限、symlink 逃逸、zstd 帧结构(解压炸弹预算内)帧级问题定位到文件
scan_network监听配置、URL 分类、明文 HTTP、代理路由(不主动联网)状态为配置级推断(unknown-listener-state 明确标注)
report汇总四类扫描riskVerdict + coverageVerdict 双维度 + findings 汇总
rules规则目录与适用平台规则 code / severity / critical / platforms
参数类型必填说明
actionstring✅scan_config / scan_plugins / scan_sessions / scan_network / report / rules
rootstringroot 覆盖;必须等于 $DSH_HOME 或管理员声明的 allowedRoot
profilestring限定单个 profile(^[A-Za-z0-9._-]{1,64}$,不接受路径)
strictbooleanstrict 模式:medium finding 也判 fail。默认 false
detailboolean详细输出。默认 true;敏感证据始终脱敏
includeSourceScanboolean启用插件静态源码能力扫描(更慢、更多误报)。默认 false

输出示例

{"tool":"security_audit","version":1,"root":"$DSH_HOME","platform":"win32","strict":false,
 "verdict":"fail","riskVerdict":"fail","coverageVerdict":"complete",
 "summary":{"critical":0,"high":1,"medium":0,"low":0},
 "findings":[{"code":"secret-in-settings","severity":"high","state":"finding",
   "evidence":{"path":"$DSH_HOME/.env","line":13,"secretKind":"api-key","secretLength":35,
               "fingerprint":"b99e1887d861d7be","redacted":true}}],
 "truncated":false}

设计要点

…

Related plugins