← 返回列表

dsh-sentinel-scanner

DeepSeek Harness 其他 低风险

DSH 插件安全扫描器:只读静态审计(执行、凭据、外传、混淆、安装脚本、bundle 清单),输出 0-100 风险分。

Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.

怎么安装

DeepSeek Harness dsh plugin add deepseek-harness-sentinel

简介

🛡️ dsh-sentinel **给 DeepSeek Harness 插件拍 X 光 · Plugin security & health scanner for DSH** 一个只读的 DSH 插件供应链 + Agent Tool 静态安全审计器:静态启发式扫描代码执行、凭据窃取、数据外传、混淆、安装脚本、原生二进制、供应链风险与 bundle 清单合规,输出 **0–100 风险分 + 裁决**,并给出每一条命中的修复建议。 既可以装进 DeepSeek Harness 当 **Agent 工具**(sentinel_scan / sentinel_scan_profile / sentinel_audit_package),也可以作为 **独立 CLI**(npx dsh-sentinel)在 CI 里使用,并输出 **SARIF 2.1.0** 对接 GitHub Code Scanning。 Node ^22.18 || ≥ 24.11 · 只读静态分析 · 绝不执行被扫描代码 · 安装前隔离审计 · MIT --- 为什么做这个 DeepSeek Harness 插件生态在爆发:截至 2026-08,仅 awesome-dsh-plugin 就收录了 **4798** 个经核实的插件仓库——其中 **253** 个被维护者拉黑或剔除。而插件本质上等于"**让你的 …

推荐参考

64 工具本身 · 参考星标、下载量、最近更新、安全检查和文档情况
用户关注 · 参考最近的查看、安装命令复制和外链访问
64 推荐程度
0访问
0独立访客
0复制安装命令
0下载点击
0外链跳转

信息

协议
MIT
语言
JavaScript
GitHub 星标
3
月下载
986
最近更新
2026-08-20
创建于
2026-08-17

链接

GitHub ↗ npm ↗ 报告问题 ↗

基础安全检查

检查结果
收录来源
curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
主题标签
deepseek-harness, dsh-plugin, scanner, security, static-analysis, supply-chain-security

同类推荐

DeepSeek Harness 新上架
推荐72

dsh-auto-review

PerryLink/dsh-auto-review

审批链上的第二模型自动审查:只读审查子代理返回带理由的 allow/deny 结构化裁决,默认 fail-closed。

☆ 57 ↓ 1.1K 其他
DeepSeek Harness 新上架
推荐70

dsh-passwords

slywalker2006/dsh-passwords

让 DeepSeek Harness 变成服务器级多租户平台:远程访问 + 自动 HTTPS、子用户权限与配额、沙盒强制、加密认证与审计日志。

☆ 15 ↓ 2.5K 其他
DeepSeek Harness 精选
推荐66

dsh-auth-gate

TecFancy/dsh-auth-gate

DSH 网页端登录门插件:账号口令或共享令牌认证、会话 cookie、登录限速,附用户管理 CLI(0.4.1 起声明 dsh.bundle manifest,`dsh plugin add` 一键挂载)。

☆ 3 ↓ 3.2K 其他
DeepSeek Harness 新上架
推荐65

dsh-approval-llm

Letter2025/dsh-approval-llm

基于模型的权限审批:由独立审查模型自动应答 approval 权限请求。

☆ 7 ↓ 461 其他