Introduction

DeepSeek Harness (DSH) adopts a plugin-based architecture. When developing agents or tools, hard-coded secrets, tokens, or private keys are a common security risk. The dsh-secret-scan plugin provides a localized sensitive information scanning solution, helping with self-checks before code is committed.

Plugin Purpose

The plugin is maintained by uckkk and belongs to the admin-security category. It is a pure Node-based local scanning tool that can run without internet access. It is primarily used to recursively scan codebases for sensitive information leaks and outputs desensitized locations and severity levels.

Core Capabilities

The plugin mainly includes the following capabilities:

  1. Detection Scope: Supports AWS, GitHub, OpenAI, npm, Stripe, Google, and Slack keys, JWTs, PEM private keys, hard-coded passwords, and generic API keys/tokens.
  2. Output Content: Reports file paths, line numbers, types, and severity levels, but does not echo plaintext secrets.
  3. Execution Environment: Pure Node implementation with no network requests and no dependencies on external services.
  4. Filtering Mechanism: Automatically skips node_modules, .git, dist, and build directories, as well as binary files, images, archives, and lock files.

Installation and Configuration

Run the following command to install the plugin:

dsh plugin add github:uckkk/dsh-secret-scan

After installation, configure dsh.profile.bundles in the profile’s package.json by adding "dsh-secret-scan". Then the plugin will take effect in sessions.

Usage

Simply call the tools registered by the plugin in a session. For example, to scan in a specified working directory:

secret_scan(root="/workspace")

Notes

Because it uses heuristic scanning (based on high-precision regular expressions), a small number of false positives may occur. Results must be confirmed manually. The plugin does not automatically remediate vulnerabilities.

In addition, the plugin runs third-party code locally with the permissions of the current DSH process. Please review the source code and license (MIT) before installing and using it.

Summary

This tool is suitable for security pre-checking before code build or submission, ensuring that sensitive information is not leaked. For more details, refer to the plugin directory or GitHub repository.