Zenquiem/dsh-security-suite

Security assessment workflows for DeepSeek Harness

A native security assessment suite for DeepSeek Harness adapted from openai/codex-security: repository, diff, and deep security scans inside DSH. LLM review subagents do the discovery (baseline auditors, focused investigators, file-review and deep workers) while a deterministic engine produces the evidence baseline; every reportable finding is bound to a claim-token validation receipt and an attack-path receipt before finalization. Workflows: standard scan (baseline auditor + focused investigator subagents over source-backed packets), diff scan (one restricted file-review subagent per changed file), deep scan (six workers per round, each with a distinct review lens, semantic reducer per round, stop-after-no-new saturation), deterministic fallback via discovery: engine. Tracking (GitHub/Jira/Linear issues + private draft advisories), triage/backlog import, remediation (reviewed, approval-gated, atomic multi-file patches with rollback and verification), exports (Markdown/JSON/SARIF/CSV + canonical manifests), threat models, vulnerability write-ups, hardening portfolios, pre-commit hook.

Web UI Enhancements ★ 2 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

npm install && npm run build && dsh plugin --profile web add /absolute/path/to/dsh-security-suite

Source install: git clone the repo, npm install && npm run build, then dsh plugin --profile web add /absolute/path/to/dsh-security-suite. Then run a scan: dsh run "Run a deep security scan, validate candidates, trace attack paths, and produce a report for this workspace." Bilingual README (English primary).

Compatibility

DSH Web profile; adapted from openai/codex-security architecture (Apache-2.0); runs LLM review subagents plus a deterministic rule/AST/flow engine; Node build required.

Details

Recent updates

codex-security-style scan suite; LLM subagent discovery + deterministic engine; claim-token + attack-path receipts; diff/deep scans; remediation with rollback.

FAQ

How are findings validated?
Every reportable finding is bound to a claim-token validation receipt and an attack-path receipt before it can be finalized.
Can it scan without LLM subagents?
Yes — the deterministic rule/AST/flow engine is available via discovery: engine and still produces the receipt baseline.
What can it export?
Markdown, JSON, SARIF, and CSV, plus canonical scan-manifest.json / findings.json / coverage.json.

Alternatives

omdsh-dev/dsh-security-audit · omdsh-dev-dsh-mcpguard · Zenquiem/dsh-security-suite

More plugins in Web UI Enhancements

Browse more in Web UI Enhancements

Guides for Web UI Enhancements plugins