In AI-assisted security, simply providing knowledge is often insufficient to complete complex tasks. Models may possess extensive knowledge, but lack workflow guidance and control, which can lead to low efficiency or deviation from the goal. DeepSeek Harness (DSH) aims to address this problem. dsh-redteam-model is a plugin implemented based on DSH Web, providing security researchers with a security research workflow covering penetration testing, red team assessments, code auditing, and other domains.
Core Features¶
This plugin includes ten security mode presets and seventeen runtime plugins:
-
Ten security mode presets:
redteam: General security researcherpentest: Penetration testingcode-audit: Code auditingbinary-analysis: Binary analysisattack-defense: Attack-defense assessmentav-evasion: AV evasionincident-response: Incident response and forensicscloud-security: Cloud security attack and defensectf-solver: CTF solvingasset-mapping: Asset mapping
-
Seventeen runtime plugins:
dsh-stage-gate: Gate structure validationdsh-route-boost: Per-round governance envelopedsh-sec-enforce: Deterministic tool interceptiondsh-refusal-guard: Refusal preventiondsh-trace-vault: Process trace vaultdsh-auto-advance: Auto-advance mechanismdsh-product-subagents: Subagentsdsh-mcp-studio: MCP tool consoledsh-redteam-results: Results showcasedsh-hunter: Asset huntingdsh-campaign-memory: Campaign memorydsh-mode-group: Mode selectordsh-session-pulse: Session status paneldsh-attack-atlas: Attack surface atlasdsh-scanner-tools: Scanner tool wrapperdsh-semgrep-audit: Static analysisdsh-webshell-mgr: Webshell management
-
Other features:
- Workflow-based design, addressing the lack of guidance in AI.
- Supports offline deployment.
- Integrates scanning tools (
nuclei,httpx,ffuf,nmap, etc.). - Supports the MCP tool console.
Installation and Activation¶
Prerequisites¶
- DeepSeek Harness (DSH) must be installed first.
- Node.js >= 22 is required.
Installation Methods¶
Option 1: Install via Command Line (Recommended)¶
Run the following command in a terminal:
dsh plugin --profile web add github:SeaOf0/dsh-redteam-model
Option 2: Install via the Web Interface¶
- Open the dsh web settings page.
- Find Redteam Manager.
- On that page, deploy the ten security modes or seventeen runtime plugins with one click.
Typical Usage¶
- View the gate schema: In any session, call
gates_listto view the gate structure definitions for specialized modes. - Use scanning tools: In modes such as
pentest,attack-defense,cloud-security,ctf-solver, andasset-mapping, you can directly use scanning tools such asnuclei_scan. - View results: In the
redteam-resultsplugin, view the task ledger and results page.
Applicable Scenarios and Notes¶
- Applicable scenarios: Only for security testing with written authorization, CTF competitions, bug bounty programs, and security research scenarios.
- Note: It must not be used for illegal activities. Workflow design is the core feature, aimed at addressing the lack of workflow guidance in AI.
Summary¶
dsh-redteam-model provides DeepSeek Harness with structured security research capabilities through preset workflows and runtime plugins. It covers the entire process from asset mapping to incident forensics and is suitable for users who need to conduct systematic security research under an authorized environment.
Project address: GitHub