euthyna
Security-audit facts AI coding agents cannot compute, plus a verdict gate: euthyna history attributes deleted lines to commits and flags those from security fixes (--origins finds the first introducer), euthyna coverage reports which changed symbols no test ever invoked, and euthyna gate checks each finding against six gates, downgrading any without evidence to an observation.
面向 AI 编码代理的确定性安全审计事实与结论门禁:euthyna history 把每行被删代码归因到提交并标记安全修复类删除(--origins 追到最初引入者),euthyna coverage 报告哪些改动符号从未被测试调用,euthyna gate 用六道门禁逐条校验结论,拿不出证据的一律降级为观察。
How to install
dsh plugin add euthyna git clone https://github.com/slow-stack/euthyna ~/.claude/skills/euthyna npx -y euthyna About
**εὔθυνα** — in classical Athens, the audit every outgoing official had to submit. You did not get to simply walk away from office. You handed over your accounts and they were examined. Pass, and you left with your standing intact. Fail, and you faced trial. **euthyna is a code security audit framework for AI coding agents.** It is not another scanner. It does two things: it **produces the facts an agent cannot compute by reading code**, and it **forces every security claim the agent makes through gates before it counts as a finding**. --- 📖 The problem, in plain words When an AI coding agent…
Recommendation signals
Meta
- License
- Apache-2.0
- Language
- JavaScript
- GitHub stars
- 1
- mo. downloads
- –
- Last push
- 2026-09-24
- Created
- 2026-09-19
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- benchmark, claude-code, code-audit, codex, dsh-plugin, git-history, hermes-skills, llm-security, security, security-audit, security-auditing-tool, security-scanner, static-analysis, test-coverage, vulnerability-analysis, zero-dependency
Related plugins
dsh-auto-mode
NanmiCoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
dsh-vault
Ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.