Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #ai-agents#deepseek-harness#dsh-plugin#security#securstack#container-security

securstack-dsh-plugin

DeepSeek Harness 的 SecurStack 安全插件:在 agent 工作流中直接运行安全扫描、策略检查与诊断,输出结构化 JSON。

securstack @securstack ⬇ 1 ★ 3 main

安装

dsh plugin --profile web add github:securstack/securstack-dsh-plugin
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

DeepSeek Harness 的 SecurStack 安全插件:在 agent 工作流中直接运行安全扫描、策略检查与诊断,输出结构化 JSON。

该插件未提供要点说明,请参考仓库 README。

ai-agentsdeepseek-harnessdsh-pluginsecuritysecurstackcontainer-security
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/securstack/securstack-dsh-plugin
许可证MIT
主要语言main
下载量1
GitHub 星标3
最近推送2026-08-19
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

[图片: SecurStack DeepSeek Harness Plugin]

# SecurStack DeepSeek Harness Plugin

  [图片: SAST]

  [图片: SCA]

  [图片: DAST]

  [图片: Secrets detection]

  [图片: IaC security]

  [图片: Policy as code]

DeepSeek Harness plugin for running SecurStack security checks directly from an AI-agent workflow.

The plugin registers safe, non-destructive Harness tools that call the official `securstack` CLI to scan repositories, return structured JSON results, run environment diagnostics, and evaluate scan output against repository policy gates. It lets DeepSeek Harness ask SecurStack what is risky, what is misconfigured, and whether a codebase passes policy without reimplementing SecurStack product logic inside the plugin.

This package is intentionally a thin adapter. It does not implement scan engines, encryption, upload logic, API contracts, or Shielding operations. Those responsibilities stay in `@securstack/cli` and the SecurStack SaaS.

## Capabilities

- Repository security scans via `securstack scan --format json`.
- Policy gates for CI-like pass/fail decisions with `securstack policy check`.
- Local setup and credential diagnostics through `securstack doctor`.
- Harness-friendly tool responses with parsed JSON where the CLI promises JSON output.
- Existing SecurStack authentication through `securstack login`, `SECURSTACK_API_KEY`, and `SECURSTACK_API_URL`.
- Adapter-only design that avoids destructive hooks, Shielding writes, or duplicated product contracts in v1.

## Security Coverage

SecurStack coverage is represented through the CLI contract exposed to Harness, including SAST-style code analysis, SCA dependency checks, secrets detection, IaC/security configuration review, policy-as-code gates, and CLI diagnostics. DAST-oriented workflows can be surfaced through SecurStack scan output and policy checks when supported by the configured SecurStack project.

## Requirements

- Node.js 20 or newer.
- DeepSeek Harness developer preview.
- SecurStack credentials configured with either:
  - `securstack login --api-key `
  - `SECURSTACK_API_KEY` and optional `SECURSTACK_API_URL`

## Install

```bash
dsh plugin --profile securstack add @securstack/dsh-plugin
dsh --profile securstack
```

## Tools

- `securstack_scan`: runs `securstack scan --format json` for a repository path.
- `securstack_doctor`: runs `securstack doctor`.
- `securstack_policy_check`: runs `securstack policy check --input ` with optional risk and severity limits.

## Examples

Ask DeepSeek Harness:

```text
Run a SecurStack scan on this repository and summarize critical findings.
```

```text
Check whether the last SecurStack scan passes the repository policy.
```

```text
Run SecurStack doctor and tell me what is misconfigured.
```

## Development

```bash
npm install
npm run build
npm test
npm pack --dry-run
```

## License

MIT

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。