Zenquiem/dsh-security-suite
Security assessment workflows for DeepSeek Harness
A native security assessment suite for DeepSeek Harness adapted from openai/codex-security: repository, diff, and deep security scans inside DSH. LLM review subagents do the discovery (baseline auditors, focused investigators, file-review and deep workers) while a deterministic engine produces the evidence baseline; every reportable finding is bound to a claim-token validation receipt and an attack-path receipt before finalization. Workflows: standard scan (baseline auditor + focused investigator subagents over source-backed packets), diff scan (one restricted file-review subagent per changed file), deep scan (six workers per round, each with a distinct review lens, semantic reducer per round, stop-after-no-new saturation), deterministic fallback via discovery: engine. Tracking (GitHub/Jira/Linear issues + private draft advisories), triage/backlog import, remediation (reviewed, approval-gated, atomic multi-file patches with rollback and verification), exports (Markdown/JSON/SARIF/CSV + canonical manifests), threat models, vulnerability write-ups, hardening portfolios, pre-commit hook.
Install
npm install && npm run build && dsh plugin --profile web add /absolute/path/to/dsh-security-suiteSource install: git clone the repo, npm install && npm run build, then dsh plugin --profile web add /absolute/path/to/dsh-security-suite. Then run a scan: dsh run "Run a deep security scan, validate candidates, trace attack paths, and produce a report for this workspace." Bilingual README (English primary).
Compatibility
DSH Web profile; adapted from openai/codex-security architecture (Apache-2.0); runs LLM review subagents plus a deterministic rule/AST/flow engine; Node build required.
Details
- Repo: Zenquiem/dsh-security-suite
- Category: Web UI Enhancements
- Stars: 2
- Version: GitHub source (build from source; no npm)
- Last push: 2026-08-14
- First seen: 2026-08-13
Recent updates
codex-security-style scan suite; LLM subagent discovery + deterministic engine; claim-token + attack-path receipts; diff/deep scans; remediation with rollback.
FAQ
- How are findings validated?
- Every reportable finding is bound to a claim-token validation receipt and an attack-path receipt before it can be finalized.
- Can it scan without LLM subagents?
- Yes — the deterministic rule/AST/flow engine is available via discovery: engine and still produces the receipt baseline.
- What can it export?
- Markdown, JSON, SARIF, and CSV, plus canonical scan-manifest.json / findings.json / coverage.json.
Alternatives
omdsh-dev/dsh-security-audit · omdsh-dev-dsh-mcpguard · Zenquiem/dsh-security-suite