stardustlc666/dsh-code-security
AI code security review: secure_scan/diff/fix_verify/report/export/baseline/deps/policy_*/health, 40+ deterministic rules, key entropy detection, SARIF export, baseline acceptance and SBOM-lite
Deterministic AI code-security review for DSH: 40+ rules (injection, deserialization, weak crypto incl. shell TLS bypass flags, hardcoded secrets, dangerous config, sensitive logging, path traversal, SSRF) with CWE/severity/line/snippet evidence. Nine tools: secure_scan, secure_diff (added lines only), secure_fix_verify (closed/remaining/fresh), secure_report, secure_export (SARIF 2.1.0 / Markdown), secure_baseline (accept current findings, gate only on new), secure_deps (SBOM-lite), secure_policy_show / secure_policy_set (.code-security.json policy with exclude/ignore/failOn). Findings contain only objective evidence and CWE IDs — no fix suggestions; the agent generates fixes from evidence.
Install
dsh plugin --profile web add dsh-code-securitydsh plugin --profile web add dsh-code-security (npm dsh-code-security 0.3.0, verified on npm 2026-08-29). Zero runtime dependencies. Verified against @deepseek-ai/dsh@0.1.1-rc.2 (2026-08-26). English README.en.md + 简体中文 primary.
Compatibility
DSH 0.1.1-rc.2+; cordis patch-bundle model; zero runtime deps.
Details
- Repo: stardustlc666/dsh-code-security
- Category: Coding & Development
- Stars: 2
- Version: npm dsh-code-security 0.3.0
- Last push: 2026-08-27
- First seen: 2026-08-15
Recent updates
40+ deterministic security rules; git-diff incremental review; fix-verify loop; SARIF export; baseline gating; SBOM-lite deps; policy JSON.
FAQ
- Does it suggest fixes?
- No — findings contain only objective evidence and CWE IDs; the agent generates the fix from that evidence.
- What rules does it cover?
- 40+ rules across injection, deserialization, weak crypto (including shell TLS bypass flags like curl -k / git sslVerify=false), credentials, dangerous config, sensitive logging, path traversal and SSRF.
- Can I set a policy?
- Yes — .code-security.json supports exclude globs, per-rule ignores with reasons, and a failOn severity threshold; secure_policy_set gates on approval.
Alternatives
stardustlc666/dsh-codex-port · Rianico/dsh-better-edit · zhang66633/dsh-plugin-installer