All plugins

dsh-secret-scan

Verified

by uckkk · Security & Policy

@{name=dsh-secret-scan; version=0.1.0; description=敏感信息扫描:递归扫描代码库中的泄露密钥/令牌/私钥/硬编码密码,输出去敏感化的位置与严重级,提交前自查安全; type=module; main=lib/index.js; exports=; files=System.Object[]; dsh=; keywords=System.Object[]; author=istone <ad571@qq.com>; license=MIT; peerDependencies=}.description

Verified plugin

Depends on the Cordis runtime or ships a cordis.yml, so it loads as a real dsh plugin.

What we found in the repo

  • depends on @deepseek-ai/cordis
  • depends on @deepseek-ai/dsh-tools
  • npm package dsh-secret-scan

Installing

Install the package, then register it in your cordis.yml:

npm install dsh-secret-scan
# cordis.yml
plugins:
  dsh-secret-scan:

Plugin keys and config options vary — check the repo's README before copying this in. dsh is in developer preview and its loader format is still changing.

Before you install

A listing here is not a security audit. The tier above records whether this repo is wired as a real dsh plugin — not whether it is safe to run. A plugin executes with your agent's permissions: your files, your shell, your network. How to vet a dsh plugin before installing

Found malware or an impersonation in this repo? Report this listing

Repository details

Stars
0
Forks
0
Open issues
0
Language
JavaScript
License
MIT
npm package
dsh-secret-scan @ 0.1.0
Created
2026-08-16
Last push
2026-08-17

Topics

deepseek-harnessdsh-plugin

More in Security & Policy