perrylink/dsh-skill-pack-security

Security audit methodology skills package: eight agent skills (key scanning, dependency audit, supply chain review, prompt injection review, audit orchestration, threat modeling, vulnerability intelligence, incident response), both Chinese and English versions; dsh plugin add @perrylink/dsh-skill-pack-security-provider One-click mounting

A skill pack plus supply-chain gate for DeepSeek Harness. It ships eight security methodologies as SKILL.md bundles the model discovers in its context: key scanning, dependency audit, supply-chain review and more, each step a real command (gitleaks, trivy, pnpm audit, npm view, git) with an expected-output sample and an exit-code criterion. Alongside the skills it provides plugin_vet, an automated pre-install gate that builds an SBOM from the lockfile, checks licenses, flags typosquats and mutable @tag/branch refs (commit pins must be immutable 40-hex SHAs), looks for malicious lifecycle scripts, exfiltration domains and obfuscated payloads, and feeds a warn (default) or deny install gate.

Skill Packs ★ 2 updated 2026-09-21 — untested
View on GitHub ↗

Install

dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider

npm package @perrylink/dsh-skill-pack-security-provider 2.2.14 (registry-verified 2026-09-10; registry repository field -> github.com/PerryLink/dsh-skill-pack-security). The README also documents a git channel (github:PerryLink/dsh-skill-pack-security#main) and a tarball channel. After installing, restart and verify the row: dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'. Uninstall: dsh plugin --profile web remove @perrylink/dsh-skill-pack-security-provider.

Compatibility

DeepSeek Harness dsh-v0.1.5-rc.1 (README verified 2026-09-10; @deepseek-ai/dsh dependency line 0.1.5-rc.1). Skills are installed per language — skills/ (Chinese) or skills-en/ (English) — one language per root.

Details

FAQ

How do I install the security skill pack?
Run: dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider, restart, then confirm the row with dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'. Git and tarball channels are also documented.
What is plugin_vet?
An automated pre-install scan: SBOM extraction from the lockfile, license and typosquat checks, commit-pinning validation, lifecycle-script and exfiltration/obfuscation pattern detection, and a five-dimension risk card.
Can the gate block an install?
Yes. gate.policy: warn (the default) only prints a warning on FAIL, while gate.policy: deny blocks installs that fail plugin_vet.

Alternatives

LayneChai/superpowers-dsh · Jayden-X-L/forkprobe · sandbaseai/sandbase-skills

More plugins in Skill Packs

Browse more in Skill Packs

Guides for Skill Packs plugins