securstack/securstack-dsh-plugin
SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and
Runs SecurStack security checks directly from an AI-agent workflow: safe, non-destructive Harness tools that call the official securstack CLI to scan repositories (securstack scan --format json), run CI-like policy gates (securstack policy check), and diagnose local setup/credentials (securstack doctor). Returns structured JSON results the agent can evaluate; existing SecurStack auth flows through securstack login / SECURSTACK_API_KEY / SECURSTACK_API_URL. Adapter-only design — no destructive hooks, Shielding writes, or duplicated product logic.
Install
dsh plugin --profile securstack add @securstack/dsh-pluginnpm package @securstack/dsh-plugin 0.1.2 (registry-verified 2026-08-26). dsh plugin --profile securstack add @securstack/dsh-plugin (profile name example from README; any profile works), or dsh plugin --profile demo add ./securstack-dsh-plugin-0.1.1.tgz for the tarball. Requires the official @securstack/cli and SecurStack authentication (securstack login, SECURSTACK_API_KEY, or SECURSTACK_API_URL).
Compatibility
DeepSeek Harness (any profile with the securstack CLI available). Thin adapter — scan engines, encryption, upload logic, and API contracts stay in @securstack/cli and the SecurStack SaaS.
Details
- Repo: securstack/securstack-dsh-plugin
- Category: Files & Data
- Stars: 3
- Version: npm @securstack/dsh-plugin 0.1.2 (registry-verified 2026-08-26)
- Last push: 2026-08-19
- First seen: 2026-08-13
Recent updates
v0.1.2: scan/policy-check/doctor tools; JSON-structured results; existing auth passthrough; adapter-only design.
FAQ
- What does the plugin add?
- Harness tools that call the official SecurStack CLI — scan, policy check, and doctor diagnostics — and return structured JSON the agent can act on.
- Does it implement scan engines?
- No — this package is intentionally a thin adapter; engines, encryption, upload, and API contracts live in @securstack/cli and the SaaS.
- How is authentication handled?
- Existing SecurStack auth: securstack login, SECURSTACK_API_KEY, or SECURSTACK_API_URL.
Alternatives
omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit · jkrandom-sudo/dsh-ci-doctor