securstack/securstack-dsh-plugin
SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and JSON CLI results from safe AI-agent tools.
이것은 DeepSeek Harness(DSH) 플러그인입니다. 이 사이트는 GitHub README, 설치 정보, 유지보수 상태, 공개 보안 시그널을 모아 보여줍니다.
업스트림에서 중국어 README를 제공하지 않아 저장소 원본 내용을 표시합니다.
SecurStack DeepSeek Harness Plugin
DeepSeek Harness plugin for running SecurStack security checks directly from an AI-agent workflow.
The plugin registers safe, non-destructive Harness tools that call the official securstack CLI to scan repositories, return structured JSON results, run environment diagnostics, and evaluate scan output against repository policy gates. It lets DeepSeek Harness ask SecurStack what is risky, what is misconfigured, and whether a codebase passes policy without reimplementing SecurStack product logic inside the plugin.
This package is intentionally a thin adapter. It does not implement scan engines, encryption, upload logic, API contracts, or Shielding operations. Those responsibilities stay in @securstack/cli and the SecurStack SaaS.
Capabilities
- Repository security scans via
securstack scan --format json. - Policy gates for CI-like pass/fail decisions with
securstack policy check. - Local setup and credential diagnostics through
securstack doctor. - Harness-friendly tool responses with parsed JSON where the CLI promises JSON output.
- Existing SecurStack authentication through
securstack login,SECURSTACK_API_KEY, andSECURSTACK_API_URL. - Adapter-only design that avoids destructive hooks, Shielding writes, or duplicated product contracts in v1.
Security Coverage
SecurStack coverage is represented through the CLI contract exposed to Harness, including SAST-style code analysis, SCA dependency checks, secrets detection, IaC/security configuration review, policy-as-code gates, and CLI diagnostics. DAST-oriented workflows can be surfaced through SecurStack scan output and policy checks when supported by the configured SecurStack project.
Requirements
- Node.js 20 or newer.
- DeepSeek Harness developer preview.
- SecurStack credentials configured with either:
securstack login --api-key <key>SECURSTACK_API_KEYand optionalSECURSTACK_API_URL
Install
dsh plugin --profile securstack add @securstack/dsh-plugin
dsh --profile securstack
Tools
securstack_scan: runssecurstack scan --format jsonfor a repository path.securstack_doctor: runssecurstack doctor.securstack_policy_check: runssecurstack policy check --input <scan.json>with optional risk and severity limits.
Examples
Ask DeepSeek Harness:
Run a SecurStack scan on this repository and summarize critical findings.
Check whether the last SecurStack scan passes the repository policy.
Run SecurStack doctor and tell me what is misconfigured.
Development
npm install
npm run build
npm test
npm pack --dry-run
License
MIT
보안 및 설치 증거
이 점수는 공개 저장소 메타데이터와 이 사이트에 등록된 설치 증거에만 기반하며, 코드 보안 감사와 다릅니다.
공개 플러그인 카탈로그에서 왔으며, 공개 GitHub 저장소로 연결됩니다.
저장소가 MIT 라이선스를 선언했습니다.
최근 180일 내 코드 업데이트가 있습니다.
재현 가능한 정확한 설치 메타데이터가 아직 등록되지 않았습니다. 저장소 설명에 따라 직접 확인하세요.
검사한 패키지 메타데이터에 설치 라이프사이클 스크립트가 선언되지 않았습니다.