Introduction¶
DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture. As the plugin ecosystem expands, dependency hygiene directly affects plugin stability and security. Unresolvable peer dependency ranges, dist-tags pointing to incorrect versions, missing licenses, or silent version drift can all lead to runtime failures or supply chain risks. dsh-dep-audit is designed to answer one question: “Can you trust the dependency graph of this plugin/Profile?” It provides a practical checklist.
Plugin Positioning¶
- Name: dsh-dep-audit
- Maintainer: zoahdev
- Category: admin-security
- Positioning: dependency supply chain hygiene audit. Manifest validity, peer range resolvability, bad dist-tag detection, stale/missing licenses/non-registry dependencies, and version drift between installed and declared versions.
Core Capabilities¶
This plugin performs the following dependency validations:
- Manifest validation: checks that
package.jsonexists, is parseable, and contains the correctnameandversion. - Peer dependency resolvability: verifies that each
peerDependenciesrange has at least one published version on the registry. - Bad dist-tag detection: detects whether
dist-tags.latestcontradicts the declared range (e.g., ERESOLVE-style errors). - Dependency source validation: ensures dependencies use registry sources rather than
git:,file:,link:, orworkspace:. - License detection: checks whether the latest registry metadata for a dependency declares a license.
- Freshness check: verifies whether registry dependencies have had a new release within 365 days (default threshold, configurable).
- Version drift detection: compares the actually installed version in
node_moduleswith the range declared inpackage.json. - Outdated version check: checks whether the installed version lags behind the registry
latest.
Installation and Enablement¶
Install the plugin into a DeepSeek Harness environment:
dsh plugin add dsh-dep-audit
You can also run it directly without installing:
npx dsh-dep-audit .
The plugin returns a machine-readable report based on the dsh-dep-audit/v1 schema.
Usage¶
Command-Line Usage¶
Basic usage:
npx dsh-dep-audit .
Audit a specific directory:
npx dsh-dep-audit ~/.dsh/profiles/web --offline
Output a JSON report:
npx dsh-dep-audit . --json
Common options:
* --json: print a machine-readable report.
* --offline: skip registry network requests.
* --all: include devDependencies in the audit.
* --registry <url>: npm registry URL.
* --stale-days <n>: alert if no release has appeared within n days (default 365).
Usage in Harness¶
After installation, you can call the dep_audit tool during agent interactions.
Example prompt:
Audit the dependency health of the current plugin:
dep_audit, with the directory pointing to the project root.
The agent will run the audit and return a structured report.
Report Structure¶
Each check returns a JSON object containing the following fields:
* id: check ID (e.g., manifest, peer-resolvable).
* status: status (ok, fail, warn).
* title: title.
* detail: detailed description.
* items: list of issues, containing name, issue, level.
Ecosystem and Notes¶
- Environment requirement: Node.js >= 18 is required.
- License: MIT.
- Complementary plugins: Together with
dsh-poison-guard(malware scanning) anddsh-plugin-doctor(release readiness checks), this plugin forms a complete plugin security and maintenance toolkit. - Exit codes: 0 all checks passed, 1 one or more
failitems, 2 usage/IO error.
Links¶
- Directory page: https://www.skillhub.cn/plugins/zoahdev/dsh-dep-audit
- GitHub repository: https://github.com/zoahdev/dsh-dep-audit