securstack / securstack-dsh-plugin

목록에 있음

SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and JSON CLI results from safe AI-agent tools.

main도구샌드박스 소스 보기

설치

npx -y @deepseek-ai/dsh plugin --profile web add github:securstack/securstack-dsh-plugin

이 설치 명령은 GitHub 저장소 주소에서 생성된 확인되지 않은 시작점입니다.

README

유지 관리자가 작성한 문서 스냅샷입니다.

GitHub에서 보기 ↗
커밋 1b706dc동기화 2026. 8. 18.

SecurStack DeepSeek Harness Plugin

SecurStack DeepSeek Harness Plugin

SAST SCA DAST Secrets detection IaC security Policy as code

DeepSeek Harness plugin for running SecurStack security checks directly from an AI-agent workflow.

The plugin registers safe, non-destructive Harness tools that call the official securstack CLI to scan repositories, return structured JSON results, run environment diagnostics, and evaluate scan output against repository policy gates. It lets DeepSeek Harness ask SecurStack what is risky, what is misconfigured, and whether a codebase passes policy without reimplementing SecurStack product logic inside the plugin.

This package is intentionally a thin adapter. It does not implement scan engines, encryption, upload logic, API contracts, or Shielding operations. Those responsibilities stay in @securstack/cli and the SecurStack SaaS.

Capabilities

  • Repository security scans via securstack scan --format json.
  • Policy gates for CI-like pass/fail decisions with securstack policy check.
  • Local setup and credential diagnostics through securstack doctor.
  • Harness-friendly tool responses with parsed JSON where the CLI promises JSON output.
  • Existing SecurStack authentication through securstack login, SECURSTACK_API_KEY, and SECURSTACK_API_URL.
  • Adapter-only design that avoids destructive hooks, Shielding writes, or duplicated product contracts in v1.

Security Coverage

SecurStack coverage is represented through the CLI contract exposed to Harness, including SAST-style code analysis, SCA dependency checks, secrets detection, IaC/security configuration review, policy-as-code gates, and CLI diagnostics. DAST-oriented workflows can be surfaced through SecurStack scan output and policy checks when supported by the configured SecurStack project.

Requirements

  • Node.js 20 or newer.
  • DeepSeek Harness developer preview.
  • SecurStack credentials configured with either:
    • securstack login --api-key <key>
    • SECURSTACK_API_KEY and optional SECURSTACK_API_URL

Install

dsh plugin --profile securstack add @securstack/dsh-plugin
dsh --profile securstack

Tools

  • securstack_scan: runs securstack scan --format json for a repository path.
  • securstack_doctor: runs securstack doctor.
  • securstack_policy_check: runs securstack policy check --input <scan.json> with optional risk and severity limits.

Examples

Ask DeepSeek Harness:

Run a SecurStack scan on this repository and summarize critical findings.
Check whether the last SecurStack scan passes the repository policy.
Run SecurStack doctor and tell me what is misconfigured.

Development

npm install
npm run build
npm test
npm pack --dry-run

License

MIT

프로젝트 파일 및 신호

표시된 항목은 디렉터리 스냅샷에서 감지된 공개 저장소 신호입니다.

테스트감지됨

저장소 정보

언어
TypeScript
라이선스
MIT
마지막 업데이트
2026. 8. 13. 오후 9:29

신중하게 설치하기

소스 코드, 권한, 수명 주기 스크립트, 의존성 및 네트워크 접근을 검토하고 신뢰하지 않는 플러그인은 격리 환경에서 테스트하세요.