Introduction

DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture. As the plugin ecosystem expands, dependency hygiene directly affects plugin stability and security. Unresolvable peer dependency ranges, dist-tags pointing to incorrect versions, missing licenses, or silent version drift can all lead to runtime failures or supply chain risks. dsh-dep-audit is designed to answer one question: “Can you trust the dependency graph of this plugin/Profile?” It provides a practical checklist.

Plugin Positioning

  • Name: dsh-dep-audit
  • Maintainer: zoahdev
  • Category: admin-security
  • Positioning: dependency supply chain hygiene audit. Manifest validity, peer range resolvability, bad dist-tag detection, stale/missing licenses/non-registry dependencies, and version drift between installed and declared versions.

Core Capabilities

This plugin performs the following dependency validations:

  1. Manifest validation: checks that package.json exists, is parseable, and contains the correct name and version.
  2. Peer dependency resolvability: verifies that each peerDependencies range has at least one published version on the registry.
  3. Bad dist-tag detection: detects whether dist-tags.latest contradicts the declared range (e.g., ERESOLVE-style errors).
  4. Dependency source validation: ensures dependencies use registry sources rather than git:, file:, link:, or workspace:.
  5. License detection: checks whether the latest registry metadata for a dependency declares a license.
  6. Freshness check: verifies whether registry dependencies have had a new release within 365 days (default threshold, configurable).
  7. Version drift detection: compares the actually installed version in node_modules with the range declared in package.json.
  8. Outdated version check: checks whether the installed version lags behind the registry latest.

Installation and Enablement

Install the plugin into a DeepSeek Harness environment:

dsh plugin add dsh-dep-audit

You can also run it directly without installing:

npx dsh-dep-audit .

The plugin returns a machine-readable report based on the dsh-dep-audit/v1 schema.

Usage

Command-Line Usage

Basic usage:

npx dsh-dep-audit .

Audit a specific directory:

npx dsh-dep-audit ~/.dsh/profiles/web --offline

Output a JSON report:

npx dsh-dep-audit . --json

Common options:
* --json: print a machine-readable report.
* --offline: skip registry network requests.
* --all: include devDependencies in the audit.
* --registry <url>: npm registry URL.
* --stale-days <n>: alert if no release has appeared within n days (default 365).

Usage in Harness

After installation, you can call the dep_audit tool during agent interactions.

Example prompt:

Audit the dependency health of the current plugin: dep_audit, with the directory pointing to the project root.

The agent will run the audit and return a structured report.

Report Structure

Each check returns a JSON object containing the following fields:
* id: check ID (e.g., manifest, peer-resolvable).
* status: status (ok, fail, warn).
* title: title.
* detail: detailed description.
* items: list of issues, containing name, issue, level.

Ecosystem and Notes

  • Environment requirement: Node.js >= 18 is required.
  • License: MIT.
  • Complementary plugins: Together with dsh-poison-guard (malware scanning) and dsh-plugin-doctor (release readiness checks), this plugin forms a complete plugin security and maintenance toolkit.
  • Exit codes: 0 all checks passed, 1 one or more fail items, 2 usage/IO error.
  • Directory page: https://www.skillhub.cn/plugins/zoahdev/dsh-dep-audit
  • GitHub repository: https://github.com/zoahdev/dsh-dep-audit