SEMANTIC DIRECTORY · plugin-directory-semantic-v3-18

Vulnerability Scanning & Security Testing

对代码、依赖、仓库、部署配置或本机环境执行只读漏洞扫描、Security审计、SAST、渗透测试、红队作业、资产测绘和流量分析,并输出风险报告或加固建议。排除Plugin安装审计、审批和运行时拦截。

Use keyword search
Source catalog discovery.composite.2026-09-06.v1-0-5.b92b985e31dfCanonical structure · 823 nodes · 14829 plugins

Leaf membership

44 plugins

@aaub-software/dsh-eslint-security-sast@aaub-software/dsh-eslint-security-sastCatalog AnalyzedESLint Security SAST bundle and model-facing scan tool for DeepSeek Harness.Security & PermissionsnpmGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.0Evidence updated2026-09-09Public signalsNo public usage signals@aaub-software/dsh-semgrep-sast@aaub-software/dsh-semgrep-sastCatalog AnalyzedSemgrep SAST bundle and model-facing scan tool for DeepSeek Harness.Security & PermissionsnpmGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.1Evidence updated2026-09-10Public signalsNo public usage signals@securstack/dsh-plugin@securstack/dsh-pluginCatalog AnalyzedDeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.Security & PermissionsnpmGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.1.2Evidence updated2026-09-08Public signals508 downloadsapi-relay-audittoby-bridges/api-relay-auditCatalog AnalyzedRuns local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals823 starsawesome-security-agent-harnessesEd-Marcavage/awesome-security-agent-harnessesCatalog AnalyzedAI agents for pentesting, code audit, fuzzing, vulnerability discovery, and reverse engineering — harnesses, sandboxes, security MCP servers, benchmarks, and evals.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals18 starsDeepSecUnclecheng-li/DeepSecCatalog AnalyzedDeepSec — AI Security Offense & Defense Platform. Shield audits AI-generated code for hallucinated packages, missing safeguards & AI pattern errors in real time. Spear automates authorized penetration testing with 40+ skill packs, from recon to PoC.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals392 starsdsh-adversarial-reviewmario03690/dsh-adversarial-reviewCatalog AnalyzedAdversarial review for code, MCP configs and system prompts: every finding carries a repro path and confidence, and anything unreproducible is marked suspected rather than presented as confirmed.Tools & CapabilitiesGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-agent-observedsh-plugin-evaluation/dsh-agent-observeCatalog AnalyzedDSH plugin for agent observability and security evaluationSecurity & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals1 starsdsh-burpsuite-mcp6jeffr3y/dsh-burpsuite-mcpCatalog AnalyzedNative Burp Suite MCP tools and live settings for DeepSeek HarnessUI EnhancementsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-code-securitydsh-code-securityCatalog AnalyzedDeterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance, SBOM-lite dependency inventory and health self-check.Security & PermissionsnpmGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.3.2Evidence updated2026-09-07Public signals2 stars · 874 downloadsdsh-cve-auditSARTHAK2511/dsh-cve-auditCatalog AnalyzedLive CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals1 starsdsh-cyber-seccyzlmh/dsh-cyber-secCatalog AnalyzedAuthorized security-assessment profile for DeepSeek Harness: scoped network tools, container-backed shell, authorization guard, durable evidence, 21 security skills, 7 specialist subagentsSecurity & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals3 starsdsh-dep-vuln-scan988hj7tczd-oss/dsh-dep-vuln-scanCatalog AnalyzedScan project lockfiles (npm/pnpm/yarn/pip/go/cargo/maven/gradle/...) against the free OSV API and report confirmed dependency vulnerabilities with fix versions and remediation commands.Tools & CapabilitiesGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals1 starsdsh-dependency-audituckkk/dsh-dependency-auditCatalog Analyzed依赖Security审计:OSV.dev 漏洞扫描 + npm 过期依赖检测,返回严重级/修复Version/升级幅度Tools & CapabilitiesGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals0 starsdsh-dolphin-securitydsh-dolphin-securityCatalog Analyzed此为 DSH 生态Plugin。Dolphin - 主动巡检型Security防御Plugin,支持本地扫描与远程 SSH 巡逻。将渗透测试方法论(信息收集→漏洞探测→利用验证→报告)转化为主动防御巡检流程:基于 Semgrep 的扫描层与基于 SSH 的执行层相融合,可对本地目录做静态扫描,也可将扫描命令经 SSH 下发至远程主机执行并回收结构化结果。Security & PermissionsnpmGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency audit0 reported in bounded auditArtifact0.2.2Evidence updated2026-09-08Public signalsNo public usage signalsdsh-fleet-auditLeslieWylie/dsh-fleet-auditCatalog AnalyzedRead-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-hawkeye-scanliuqingman/dsh-hawkeye-scanCatalog AnalyzedHawkeye Scan Workbench - AI-driven source-code security scanning for DeepSeek Harness (DSH): 5 model tools + /hawkeye web UI + JSON/Markdown/HTML vuln reports. Zero-dependency Cordis plugin.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 starsdsh-hawkeye-scan#npmliuqingman/dsh-hawkeye-scanCatalog AnalyzedAI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.Security & PermissionsGitHubCompatibilityDSH 0.1.2-rc.1 · webDependency auditNot testedArtifactUnresolvedEvidence updated2026-09-10Public signals2 stars

Categories are public semantic index facts, not a final recommendation. Compatibility, permissions, and source evidence remain separate.