给 DeepSeek Harness(DSH)的 Agent 增加 code scan 工具:对指定目录运行 semgrep 代码安全扫描,输出按文件、行号、严重级别分组的中文 Markdown 报告。
Adds a code scan tool to the DeepSeek Harness (DSH) Agent: runs a semgrep security scan on a given directory and outputs a Chinese Markdown report grouped by file, line number and severity.
安装
dsh plugin --profile web add github:xiaohuang-zaianlian/dsh-code-scanGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
给 DeepSeek Harness(DSH)的 Agent 增加 code_scan 工具:对指定目录运行 semgrep 代码安全扫描,输出按文件、行号、严重级别分组的中文 Markdown 报告。
功能
- 单个工具
code_scan,传入目录路径即可扫描。 - 报告按文件分组,含行号和严重级别(ERROR / WARNING / INFO)。
- 结果按严重级别优先排序,默认最多显示 200 条,避免撑爆 Agent 上下文。
- 未安装 semgrep 时返回友好的中文提示,不会崩溃。
安装前提
本机需安装 semgrep,并保证 semgrep 命令在 PATH 上。Windows 建议用独立虚拟环境安装,避免污染其他 Python 环境:
python -m venv C:\Users\<你>\semgrep-venv
C:\Users\<你>\semgrep-venv\Scripts\pip install semgrep
# 把 C:\Users\<你>\semgrep-venv\Scripts 加入用户 PATH
安装插件
dsh plugin --profile web add dsh-code-scan
安装完成后重启 dsh web 生效。
使用
在 DSH 对话中让 Agent 扫描某个目录,例如:
用 code_scan 工具扫描 C:\path\to\your\project
报告示例:
# semgrep 扫描报告
- 扫描目录:`C:\...\demo`
- 发现问题:共 4 处(ERROR 2 / WARNING 2 / INFO 0)
## C:\...\app.py(2 处)
- [ERROR] 第 8 行 · 规则 `...sqlalchemy-execute-raw-query`:Avoiding SQL string concatenation...
- [WARNING] 第 18 行 · 规则 `...eval-detected`:Detected the use of eval()...
工作原理
- 调用
semgrep scan --json <目录>。 - 解析 JSON,提取文件、行号、严重级别、规则 id、描述。
- 按严重级别优先排序,并截断到上限条数。
- 生成中文 Markdown 报告返回给 Agent。
License
原始 README: https://github.com/xiaohuang-zaianlian/dsh-code-scan/blob/main/README.md ↗
同类插件
查看全部 →
dsh-anchored-standard
两阶段 DeepSeek Harness 预设:先 Minimal 对齐的 bootstrap,再切完整 Standard 工具(Project2 98/99)

PicGo-Core
极致的图片上传引擎,CLI 与 API 双支持

awesome-deepseek-harness
DeepSeek Harness(DSH)及其优秀社区插件的精选指南。

awesome-deepseek-harness
DeepSeek Harness (DSH)生态系统:来自dsh-external/hub和公共dsh-plugin主题的精选插件、工具和基础设施。

AI-Novel-Writer
本地优先 AI 小说创作工作台,提供 Windows/macOS 桌面版与 DeepSeek Harness 插件开发预览,支持角色、大纲、章节蓝图、审稿修稿和本地模型。

mcp-for-stata
MCP-for-Stata:把 Stata 集成进你的 agent