← Back to list

dsh-cve-audit

DeepSeek Harness Other High risk

Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.

面向你自己项目依赖(npm/pip/go)的实时 CVE/供应链审计,基于 OSV.dev,提供 `cve_audit` 工具,并支持在 lockfile 变化时自动重新扫描。

How to install

DeepSeek Harness dsh plugin add github:SARTHAK2511/dsh-cve-audit

About

dsh-cve-audit Live CVE / supply-chain audit for **your project's own dependencies** — not the harness's plugins. Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the *plugin ecosystem itself*. None of them scan the dependency lockfiles of the codebase you're actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a…

Recommendation signals

39 Tool quality · Based on stars, downloads, maintenance, security and docs
– User interest · Adjusted by in-site views, install copies and download clicks
39 Overall
0views
0unique visitors
0install copies
0download clicks
0outbound clicks

Meta

License
–
Language
TypeScript
GitHub stars
2
mo. downloads
–
Last push
2026-08-15
Created
2026-08-15

Links

GitHub ↗ Report issue ↗

Basic safety check

Findings
curated 收录但无 npm 包/安装命令;无 license
Sources
curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin

Related plugins

DeepSeek Harness Featured
Score77

dsh-auto-mode

NanmiCoder/dsh-auto-mode

Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.

☆ 162 ↓ 3.3K Other ↗
DeepSeek Harness
Score75

dsh-passwords

slywalker2006/dsh-passwords

Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.

☆ 64 ↓ 5.2K Other ↗
DeepSeek HarnessMCP Server Featured
Score73

sofagent

KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit

Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.

☆ 49 ↓ 2.7K Other ↗
DeepSeek Harness Featured
Score72

dsh-vault

Ox0400/dsh-vault

Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.

☆ 11 ↓ 15.9K Other ↗