In the DSH (DeepSeek Harness) ecosystem, an Agent often needs a security gate before delivering code. The dsh-code-security plugin addresses code security scanning and policy gating through a deterministic rule engine and git diff incremental review.
Plugin Introduction¶
The DeepSeek Harness AI code security review plugin, maintained by STARDUSTLC666, is released under the MIT license. The plugin adopts the Codex security skill methodology (vulnerability grading, evidence first, supply chain layering) and implements it as a reproducible tool. It features zero runtime dependencies, with core value in a deterministic rule engine, git diff incremental review, a fix verification loop, and policy gating.
Core Features¶
The plugin provides the following core tools and capabilities:
- Scanning and Review:
secure_scanscans files/directories and outputs CWE/severity/line number/code snippet evidence;secure_diffreviews only the newly added lines in a git diff, suitable for incremental review. - Fix Verification Loop:
secure_fix_verifyrescans after fixes to determine whether vulnerabilities are closed or whether new issues have been introduced;secure_baselineaccepts current known issues as a baseline, after which only newly added issues are evaluated. - Reports and Export:
secure_reportaggregates results by rule/file and provides a gating conclusion;secure_exportsupports export in SARIF 2.1.0 and Markdown formats. - Policies and Dependencies:
secure_policy_showandsecure_policy_setare used to manage.code-security.jsonpolicies (such as excluded paths, ignored rules, and thresholds);secure_depsprovides SBOM-lite functionality, parsing dependency manifests and version constraint risks. - Technical Details: Supports secret entropy detection, covers 40+ rules, and spans scenarios such as injection, unsafe deserialization, weak encryption, hardcoded credentials, and sensitive configuration leakage.
Installation and Enablement¶
Installing the plugin requires the official install command. After installation, the web service must be restarted.
dsh plugin --profile web add dsh-code-security
Typical Usage¶
After installation, the following tools can be invoked in Harness:
secure_scan { target: src }
secure_diff { base: HEAD }
secure_fix_verify { target: src }
secure_baseline { reason: 历史遗留 }
secure_deps { target: . }
Applicable Scenarios and Notes¶
The plugin is suitable for scenarios where code security checks are required before an Agent delivers code, especially projects that need incremental review based on git diff or verification of fix outcomes.
Notes:
1. Environment Compatibility: The plugin has been validated on the official @deepseek-ai/dsh@0.1.5-rc.1 and Node 24.16.0 (2026-09-11). The Node version requirements are consistent with this Harness version: 22.19 or later in the 22.x line, or 24 or later.
2. Runtime Permissions: The plugin runs with the permissions of the current DSH process, so the configuration must be verified.
3. Source Code Review: Before installation, it is recommended to review the source code and license.
4. Technical Model: The plugin uses the cordis.patch.yml + dsh.bundle.patch combined package model.
Summary¶
dsh-code-security provides a complete code security review solution for DeepSeek Harness, covering key stages from incremental scanning to fix verification and policy gating.