DeepSeek Harness 插件

SARTHAK2511/dsh-cve-audit

Star 数 ★ 0 分类 工具与能力 收录于 2026-08-17

面向你自己项目依赖(npm/pip/go)的实时 CVE/供应链审计,基于 OSV.dev,提供 `cve_audit` 工具,并支持在 lockfile 变化时自动重新扫描。

安装

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:SARTHAK2511/dsh-cve-audit

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本。请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

Live CVE / supply-chain audit for your project's own dependencies — not the harness's plugins.

Most existing dsh security plugins (dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you're actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes.

Install

dsh plugin add @dsh-plugins/dsh-cve-audit

Usage

Ask the agent to "audit dependencies for CVEs" — it will call the cve_audit tool. Or trigger it directly:

cve_audit({ path: "." })

Config

watch: true          # re-scan automatically on lockfile changes
ecosystems: [npm, PyPI, Go]
osvEndpoint: https://api.osv.dev/v1/querybatch

Status

Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node's fs.watch rather than a harness-native workspace-change event, since that event name isn't in the public docs yet — swap in the native hook once confirmed. PRs welcome.

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →