Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture. Extending an Agent’s capabilities is usually done by introducing external tools. When an Agent needs to perform a security scan or quality check on project code, directly calling external command-line tools or writing custom parsing scripts increases development and maintenance costs.

dsh-code-scan plugin aims to solve this problem. It wraps semgrep and provides DSH Agents with a single tool named code_scan. An Agent only needs to pass a directory path, and the plugin runs a local security scan and outputs a Chinese Markdown report grouped by file, line number, and severity level.

Core Features

This plugin provides the following core capabilities:

  • Single tool interface: An Agent only needs to call code_scan and pass the target directory path to start a scan.
  • Structured report: Scan results are grouped by file and list specific line numbers, severity levels (ERROR / WARNING / INFO), and the corresponding rule descriptions.
  • Context protection: Results are sorted primarily by severity by default and limited to a maximum of 200 entries. This design avoids excessive scan results blowing up the Agent’s context window.
  • Fault tolerance: If semgrep is not installed on the local machine or the command is not in the PATH, the plugin returns a friendly Chinese prompt instead of causing the Agent call to fail.

Installation and Prerequisites

Before using this plugin, make sure the local environment meets the following conditions:

  1. Install semgrep: semgrep must be installed on the local machine, and the semgrep command must be available in the system PATH environment variable.
  2. Environment isolation (Windows): On Windows, it is recommended to use an independent virtual environment for installing semgrep to avoid polluting other Python project environments.

After meeting the above conditions, run the following command to install the plugin:

dsh plugin --profile web add dsh-code-scan

After installation, restart the dsh web process to make the tool available.

Typical Usage

After successful installation, in the DSH conversational interface, the Agent can use the code_scan tool.

Command example:

Use the code_scan tool to scan C:\path\to\your\project

Output report example:

# semgrep 扫描报告

- 扫描目录:`C:\...\demo`
- 发现问题:共 4 处(ERROR 2 / WARNING 2 / INFO 0)

## C:\...\app.py(2 处)

- [ERROR] 第 8 行 · 规则 `...sqlalchemy-execute-raw-query`:Avoiding SQL string concatenation...
- [WARNING] 第 18 行 · 规则 `...eval-detected`:Detected the use of eval()...

Applicable Scenarios and Notes

  • Intended users: Developers who need to add code security auditing capabilities to DeepSeek Harness Agents.
  • Permission notes: The plugin runs with the permissions of the current DSH process. This means the Agent needs appropriate file read/write permissions when scanning a directory.
  • Source code review: Since DSH plugins typically execute commands locally, it is recommended to review the GitHub repository source code before installation to confirm the license and implementation logic.

Summary

The dsh-code-scan plugin resolves the pain point of integrating static code analysis tools into Agents through a simple interface wrapper. It converts the complex semgrep scan process into a structured Chinese Markdown report, ensuring both the Agent’s context safety and clear readability. Project address: https://github.com/xiaohuang-zaianlian/dsh-code-scan