Preface

DeepSeek Harness (DSH) uses a plugin-based architecture, aiming to extend agent capabilities through modular components. When building agents, project dependency security and version maintenance are common concerns. The dsh-dependency-audit plugin addresses these two pain points by providing basic dependency auditing capabilities.

What Is This

This is a dependency security auditing tool maintained by developer uckkk. It is implemented in pure Node.js and only requires network access to OSV.dev and the npm registry. Its core purpose is to scan the security status of project dependencies: first, it queries each dependency’s known vulnerabilities through OSV.dev; second, it compares against the npm registry to detect outdated dependencies.

Core Features

This plugin provides the following two core tools:

  • Vulnerability scanning: Batch-queries OSV.dev and returns vulnerability IDs, severity levels, summaries, and fix versions for affected dependencies.
  • Dependency checks: Compares installed versions against the latest versions and returns outdated dependencies along with upgrade magnitude (major/minor/patch).

Installation and Enablement

Run the following command in the terminal to install the plugin:

dsh plugin add dsh-dependency-audit

After installation, it needs to be enabled in the profile configuration file package.json. Find the dsh.profile.bundles field and add the plugin name:

"dsh.profile.bundles": ["dsh-dependency-audit"]

Typical Usage

After installing the plugin and loading it in a session, you can directly invoke its registered tools.

  • Check known vulnerabilities: Enter a command or call the function to audit project dependencies.
    audit_vulnerabilities(root="/workspace")
  • Check outdated dependencies: View which dependencies are outdated and their upgrade magnitudes.
    audit_outdated(root="/workspace")

Use Cases and Notes

  • Data sources: Vulnerability data comes from OSV.dev (an open-source vulnerability database covering sources such as GitHub Advisory). Queries are free and do not require an API key.
  • Check scope: Only installed dependencies with resolvable exact versions are checked. Dependencies in node_modules that cannot be resolved will be skipped.
  • Ecosystem integration: This plugin forms a security toolkit with dsh-license-guard (license compliance) and dsh-secret-scan (secret scanning).
  • Source review: Installing the plugin executes third-party code locally. Please review the source code yourself.

Summary

This plugin provides DSH with basic dependency security checking capabilities. For more details, refer to the plugin directory or the source repository.