In the DSH (DeepSeek Harness) ecosystem, an Agent often needs a security gate before delivering code. The dsh-code-security plugin addresses code security scanning and policy gating through a deterministic rule engine and git diff incremental review.

Plugin Introduction

The DeepSeek Harness AI code security review plugin, maintained by STARDUSTLC666, is released under the MIT license. The plugin adopts the Codex security skill methodology (vulnerability grading, evidence first, supply chain layering) and implements it as a reproducible tool. It features zero runtime dependencies, with core value in a deterministic rule engine, git diff incremental review, a fix verification loop, and policy gating.

Core Features

The plugin provides the following core tools and capabilities:

  • Scanning and Review: secure_scan scans files/directories and outputs CWE/severity/line number/code snippet evidence; secure_diff reviews only the newly added lines in a git diff, suitable for incremental review.
  • Fix Verification Loop: secure_fix_verify rescans after fixes to determine whether vulnerabilities are closed or whether new issues have been introduced; secure_baseline accepts current known issues as a baseline, after which only newly added issues are evaluated.
  • Reports and Export: secure_report aggregates results by rule/file and provides a gating conclusion; secure_export supports export in SARIF 2.1.0 and Markdown formats.
  • Policies and Dependencies: secure_policy_show and secure_policy_set are used to manage .code-security.json policies (such as excluded paths, ignored rules, and thresholds); secure_deps provides SBOM-lite functionality, parsing dependency manifests and version constraint risks.
  • Technical Details: Supports secret entropy detection, covers 40+ rules, and spans scenarios such as injection, unsafe deserialization, weak encryption, hardcoded credentials, and sensitive configuration leakage.

Installation and Enablement

Installing the plugin requires the official install command. After installation, the web service must be restarted.

dsh plugin --profile web add dsh-code-security

Typical Usage

After installation, the following tools can be invoked in Harness:

secure_scan { target: src }
secure_diff { base: HEAD }
secure_fix_verify { target: src }
secure_baseline { reason: 历史遗留 }
secure_deps { target: . }

Applicable Scenarios and Notes

The plugin is suitable for scenarios where code security checks are required before an Agent delivers code, especially projects that need incremental review based on git diff or verification of fix outcomes.

Notes:
1. Environment Compatibility: The plugin has been validated on the official @deepseek-ai/dsh@0.1.5-rc.1 and Node 24.16.0 (2026-09-11). The Node version requirements are consistent with this Harness version: 22.19 or later in the 22.x line, or 24 or later.
2. Runtime Permissions: The plugin runs with the permissions of the current DSH process, so the configuration must be verified.
3. Source Code Review: Before installation, it is recommended to review the source code and license.
4. Technical Model: The plugin uses the cordis.patch.yml + dsh.bundle.patch combined package model.

Summary

dsh-code-security provides a complete code security review solution for DeepSeek Harness, covering key stages from incremental scanning to fix verification and policy gating.

GitHub Repository