SecurStack 适配器:仓库安全扫描、策略门、doctor 诊断等
SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and
安装
dsh plugin --profile web add github:securstack/securstack-dsh-pluginGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
目录
SecurStack DeepSeek Harness Plugin
DeepSeek Harness plugin for running SecurStack security checks directly from an AI-agent workflow.
The plugin registers safe, non-destructive Harness tools that call the official securstack CLI to scan repositories, return structured JSON results, run environment diagnostics, and evaluate scan output against repository policy gates. It lets DeepSeek Harness ask SecurStack what is risky, what is misconfigured, and whether a codebase passes policy without reimplementing SecurStack product logic inside the plugin.
This package is intentionally a thin adapter. It does not implement scan engines, encryption, upload logic, API contracts, or Shielding operations. Those responsibilities stay in @securstack/cli and the SecurStack SaaS.
Capabilities
- Repository security scans via
securstack scan --format json. - Policy gates for CI-like pass/fail decisions with
securstack policy check. - Local setup and credential diagnostics through
securstack doctor. - Harness-friendly tool responses with parsed JSON where the CLI promises JSON output.
- Existing SecurStack authentication through
securstack login,SECURSTACK_API_KEY, andSECURSTACK_API_URL. - Adapter-only design that avoids destructive hooks, Shielding writes, or duplicated product contracts in v1.
Security Coverage
SecurStack coverage is represented through the CLI contract exposed to Harness, including SAST-style code analysis, SCA dependency checks, secrets detection, IaC/security configuration review, policy-as-code gates, and CLI diagnostics. DAST-oriented workflows can be surfaced through SecurStack scan output and policy checks when supported by the configured SecurStack project.
Requirements
- Node.js 20 or newer.
- DeepSeek Harness developer preview.
- SecurStack credentials configured with either:
securstack login --api-key <key>SECURSTACK_API_KEYand optionalSECURSTACK_API_URL
The plugin reuses SECURSTACK_CLI_PATH or a securstack executable already
available in PATH. On a clean machine it downloads the compatible standalone
CLI, verifies its SHA-256 digest, and stores it under
~/.securstack/bin/<version>/. The downloaded CLI itself does not require
Node.js. SECURSTACK_CLI_VERSION and SECURSTACK_CLI_MANIFEST_URL can be used
to pin or test another release.
Install
dsh plugin --profile securstack add @securstack/dsh-plugin
dsh --profile securstack
Tools
securstack_scan: runssecurstack scan --format jsonfor a repository path.securstack_doctor: runssecurstack doctor.securstack_policy_check: runssecurstack policy check --input <scan.json>with optional risk and severity limits.
Examples
Ask DeepSeek Harness:
Run a SecurStack scan on this repository and summarize critical findings.
Check whether the last SecurStack scan passes the repository policy.
Run SecurStack doctor and tell me what is misconfigured.
Development
npm install
npm run build
npm test
npm pack --dry-run
Release and publishing operations are documented in docs/release.md. Releases must be authenticated as the securstack account on both npm and GitHub; personal accounts must not publish or push the public release.
For local Harness testing:
npm pack
dsh plugin --profile demo add ./securstack-dsh-plugin-0.1.1.tgz
dsh --profile demo --dump-config
原始 README: https://github.com/securstack/securstack-dsh-plugin/blob/main/README.md ↗
同类插件
查看全部 →
k8e
k8e.sh — 开源 Agentic AI 沙箱矩阵

hol-guard
开源AI代理防病毒:运行时拦截风险工具、秘密访问、提示注入、恶意软件包、MCP服务器、插件和技能。

anolisa
ANOLISA(Agentic Nexus Operating Layer & Interface System Architecture):具备运行时、安全性、可观测性和 Tokenless 响应压缩能力的 Agentic OS,可降低 Token 使用量与成本。

mobius
首个自我演进的开源 Agent OS:连接你的团队、AI agent、设备与算力

deepseek-harness-desktop
DeepSeek Harness Tauri 桌面版 | Only 5mb installer, zero environment setup. Windows / macOS / Linux.

open-managed-agents
开源Claude管理代理API实现和自托管Claude标签式代理运行时。即插即用;在Cloudflare Workers/Durable Objects或Node.js上运行。Apache 2.0。