id7869/dsh-security ↗★ 2

dsh-security

安全审计插件:发现、验证并报告漏洞,含技能与工作流脚本。 适合需要仓库安全扫描与漏洞修复流程的用户;需 DSH 与 Node 版本满足要求。

包名
dsh-security
兼容性
待验证
版本
0.1.0
许可证
MIT
最近更新
2026年9月15日

同名包的其他仓库

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:id7869/dsh-security

使用方式

方式一:自然语言(推荐)

在会话中直接说「扫描这个仓库」「做一次安全审计」「修复这个漏洞」「把这个告警入库」,入口 skill dsh-security-run 会自动触发,并驱动 workflow/scan.js / fix.js / triage.js / diff.js 执行。

方式二:手动执行 workflow 脚本

在 DSH 会话中,用原生 workflow 工具执行插件内脚本,并传入 args。

扫描(workflow/scan.js)
{
  "repo": "C:/path/to/your/repo",
  "skillDir": "C:/path/to/dsh-security/skills",
  "outputDir": "C:/path/to/output",
  "stateDir": "C:/path/to/dsh-security/state",
  "mode": "standard",
  "maxDiscoveryRuns": 5,
  "stopAfterNoNew": 2,
  "classify": false
}

args 字段:

字段默认说明
repo必填待审计目录绝对路径(工作区内)
skillDir必填各阶段 SKILL.md 所在目录绝对路径
outputDir必填产物目录(独立目录)
stateDir必填本地 JSONL workbench 目录
modestandardstandard 单轮发现;deep 多 pass 深扫
maxDiscoveryRuns5深扫最大发现轮数
stopAfterNoNew2连续 N 轮无新 reportable 根因即停止
historyLimit500历史召回上限(去重阶段)
classifyfalse是否追加 rubric 严重度重分级
diff 扫描(workflow/diff.js)
{
  "repo": "C:/path/to/your/repo",
  "skillDir": "C:/path/to/dsh-security/skills",
  "outputDir": "C:/path/to/output",
  "stateDir": "C:/path/to/dsh-security/state",
  "baseRef": "main",
  "headRef": "HEAD"
}
  • baseRef/headRef 都给时审该区间;否则审工作区未提交变更。
  • 只审变更文件,report-only,不改源码。
修复(workflow/fix.js)
{
  "repo": "C:/path/to/your/repo",
  "skillDir": "C:/path/to/dsh-security/skills",
  "outputDir": "C:/path/to/output",
  "stateDir": "C:/path/to/dsh-security/state",
  "verify": true,
  "findings": [{ "title": "SQL injection in POST /login handler", "location": {"file": "src/index.js", "line": 17}, "category": "SQL injection", "severity": "high", "remediation": "改用参数化查询" }]
}

流程:fix(最小修复,改源码)→ verify-fix(独立读码复验 fixed/not_fixed/regressed)→ 追加 stateDir/fixes.jsonl。

已有 finding 入库(workflow/triage.js)
{
  "repo": "C:/path/to/your/repo",
  "skillDir": "C:/path/to/dsh-security/skills",
  "outputDir": "C:/path/to/output",
  "stateDir": "C:/path/to/dsh-security/state",
  "findings": [{ "title": "Possible XSS in search", "location": {"file": "src/index.js"}, "category": "XSS" }]
}

流程:外部 finding 独立复核 → reportable 项追加进 stateDir/findings.jsonl。

跟踪(workflow/track.js)
{
  "repo": "C:/path/to/your/repo",
  "skillDir": "C:/path/to/dsh-security/skills",
  "outputDir": "C:/path/to/output",
  "stateDir": "C:/path/to/dsh-security/state",
  "destination": "auto",
  "findings": [{ "id": "csf_1234567890abcdef", "title": "XSS" }]
}
  • destination: auto(探针检测可用目标)、github、linear、jira、export。
  • 无外部连接时降级为 exports/track.json 导出。