DeepSeek Harness plugin

dsh-secret-scan

敏感信息扫描:递归扫描代码库中的泄露密钥/令牌/私钥/硬编码密码,输出去敏感化的位置与严重级,提交前自查安全

Jump to install

Source facts

Repository
uckkk/dsh-secret-scan
Latest update
Aug 19, 2026
Category
Security & Permissions
GitHub stars
0
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/uckkk/dsh-secret-scan
Plugin: dsh-secret-scan
Author: uckkk

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-secret-scan · 敏感信息扫描

递归扫描代码库中的敏感信息泄露(AWS/GitHub/OpenAI/npm/Stripe/Google/Slack 密钥、JWT、私钥、硬编码密码等),输出去敏感化的位置与严重级。纯 Node 实现,无网络、无外部服务,绝不回显明文密钥

提供的工具

工具作用
secret_scan扫描目录,返回「文件 + 行号 + 类型 + 严重级」的敏感信息清单

安装

dsh plugin add dsh-secret-scan

安装后在 profile 的 package.jsondsh.profile.bundles 中加入 "dsh-secret-scan"

用法示例

提交前帮我扫一下项目里有没有泄露的密钥
→ 调用 secret_scan(root="/workspace")

识别范围

AWS Access/Secret Key、GitHub Token、OpenAI Key、npm Token、Stripe Live Key、Google API Key、Slack Token、JWT、PEM 私钥、硬编码密码、通用 API Key/Token 等。

说明

  • 自动跳过 node_modules.gitdistbuild、二进制/图片/压缩包、lock 文件等。
  • 这是启发式扫描(高精度正则),可能有少量误报,结果需人工确认;不负责自动修复。
  • 密钥/令牌正文不会被回显,只报告文件、行号、类型和严重级。

安装

dsh plugin add github:uckkk/dsh-secret-scan

> 安装即在本机运行第三方代码,请自行审阅源码。

安装

dsh plugin add github:uckkk/dsh-secret-scan

使用

安装后在会话中调用该插件注册的工具即可。

许可

MIT

> 安装即在本机运行第三方代码,请自行审阅源码。