Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture. Extending an Agent’s capabilities is usually done by introducing external tools. When an Agent needs to perform a security scan or quality check on project code, directly calling external command-line tools or writing custom parsing scripts increases development and maintenance costs.
dsh-code-scan plugin aims to solve this problem. It wraps semgrep and provides DSH Agents with a single tool named code_scan. An Agent only needs to pass a directory path, and the plugin runs a local security scan and outputs a Chinese Markdown report grouped by file, line number, and severity level.
Core Features¶
This plugin provides the following core capabilities:
- Single tool interface: An Agent only needs to call
code_scanand pass the target directory path to start a scan. - Structured report: Scan results are grouped by file and list specific line numbers, severity levels (ERROR / WARNING / INFO), and the corresponding rule descriptions.
- Context protection: Results are sorted primarily by severity by default and limited to a maximum of 200 entries. This design avoids excessive scan results blowing up the Agent’s context window.
- Fault tolerance: If semgrep is not installed on the local machine or the command is not in the PATH, the plugin returns a friendly Chinese prompt instead of causing the Agent call to fail.
Installation and Prerequisites¶
Before using this plugin, make sure the local environment meets the following conditions:
- Install semgrep: semgrep must be installed on the local machine, and the
semgrepcommand must be available in the system PATH environment variable. - Environment isolation (Windows): On Windows, it is recommended to use an independent virtual environment for installing semgrep to avoid polluting other Python project environments.
After meeting the above conditions, run the following command to install the plugin:
dsh plugin --profile web add dsh-code-scan
After installation, restart the dsh web process to make the tool available.
Typical Usage¶
After successful installation, in the DSH conversational interface, the Agent can use the code_scan tool.
Command example:
Use the code_scan tool to scan C:\path\to\your\project
Output report example:
# semgrep 扫描报告
- 扫描目录:`C:\...\demo`
- 发现问题:共 4 处(ERROR 2 / WARNING 2 / INFO 0)
## C:\...\app.py(2 处)
- [ERROR] 第 8 行 · 规则 `...sqlalchemy-execute-raw-query`:Avoiding SQL string concatenation...
- [WARNING] 第 18 行 · 规则 `...eval-detected`:Detected the use of eval()...
Applicable Scenarios and Notes¶
- Intended users: Developers who need to add code security auditing capabilities to DeepSeek Harness Agents.
- Permission notes: The plugin runs with the permissions of the current DSH process. This means the Agent needs appropriate file read/write permissions when scanning a directory.
- Source code review: Since DSH plugins typically execute commands locally, it is recommended to review the GitHub repository source code before installation to confirm the license and implementation logic.
Summary¶
The dsh-code-scan plugin resolves the pain point of integrating static code analysis tools into Agents through a simple interface wrapper. It converts the complex semgrep scan process into a structured Chinese Markdown report, ensuring both the Agent’s context safety and clear readability. Project address: https://github.com/xiaohuang-zaianlian/dsh-code-scan