dsh-security
安全审计插件:发现、验证并报告漏洞,含技能与工作流脚本。 适合需要仓库安全扫描与漏洞修复流程的用户;需 DSH 与 Node 版本满足要求。
同名包的其他仓库
安装
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:id7869/dsh-security说明文档
阅读完整 README ↗使用方式
方式一:自然语言(推荐)
在会话中直接说「扫描这个仓库」「做一次安全审计」「修复这个漏洞」「把这个告警入库」,入口 skill dsh-security-run 会自动触发,并驱动 workflow/scan.js / fix.js / triage.js / diff.js 执行。
方式二:手动执行 workflow 脚本
在 DSH 会话中,用原生 workflow 工具执行插件内脚本,并传入 args。
扫描(workflow/scan.js)
{
"repo": "C:/path/to/your/repo",
"skillDir": "C:/path/to/dsh-security/skills",
"outputDir": "C:/path/to/output",
"stateDir": "C:/path/to/dsh-security/state",
"mode": "standard",
"maxDiscoveryRuns": 5,
"stopAfterNoNew": 2,
"classify": false
}
args 字段:
| 字段 | 默认 | 说明 |
|---|---|---|
repo | 必填 | 待审计目录绝对路径(工作区内) |
skillDir | 必填 | 各阶段 SKILL.md 所在目录绝对路径 |
outputDir | 必填 | 产物目录(独立目录) |
stateDir | 必填 | 本地 JSONL workbench 目录 |
mode | standard | standard 单轮发现;deep 多 pass 深扫 |
maxDiscoveryRuns | 5 | 深扫最大发现轮数 |
stopAfterNoNew | 2 | 连续 N 轮无新 reportable 根因即停止 |
historyLimit | 500 | 历史召回上限(去重阶段) |
classify | false | 是否追加 rubric 严重度重分级 |
diff 扫描(workflow/diff.js)
{
"repo": "C:/path/to/your/repo",
"skillDir": "C:/path/to/dsh-security/skills",
"outputDir": "C:/path/to/output",
"stateDir": "C:/path/to/dsh-security/state",
"baseRef": "main",
"headRef": "HEAD"
}
baseRef/headRef都给时审该区间;否则审工作区未提交变更。- 只审变更文件,report-only,不改源码。
修复(workflow/fix.js)
{
"repo": "C:/path/to/your/repo",
"skillDir": "C:/path/to/dsh-security/skills",
"outputDir": "C:/path/to/output",
"stateDir": "C:/path/to/dsh-security/state",
"verify": true,
"findings": [{ "title": "SQL injection in POST /login handler", "location": {"file": "src/index.js", "line": 17}, "category": "SQL injection", "severity": "high", "remediation": "改用参数化查询" }]
}
流程:fix(最小修复,改源码)→ verify-fix(独立读码复验 fixed/not_fixed/regressed)→ 追加 stateDir/fixes.jsonl。
已有 finding 入库(workflow/triage.js)
{
"repo": "C:/path/to/your/repo",
"skillDir": "C:/path/to/dsh-security/skills",
"outputDir": "C:/path/to/output",
"stateDir": "C:/path/to/dsh-security/state",
"findings": [{ "title": "Possible XSS in search", "location": {"file": "src/index.js"}, "category": "XSS" }]
}
流程:外部 finding 独立复核 → reportable 项追加进 stateDir/findings.jsonl。
跟踪(workflow/track.js)
{
"repo": "C:/path/to/your/repo",
"skillDir": "C:/path/to/dsh-security/skills",
"outputDir": "C:/path/to/output",
"stateDir": "C:/path/to/dsh-security/state",
"destination": "auto",
"findings": [{ "id": "csf_1234567890abcdef", "title": "XSS" }]
}
destination:auto(探针检测可用目标)、github、linear、jira、export。- 无外部连接时降级为
exports/track.json导出。