dshbase

Plugin directory / Automation / securstack-dsh-plugin

securstack-dsh-plugin

Verified · install-tested on dsh securstack

✓ Actively maintained 2 contributors Builds on 1 official DSH packages Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

3Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-13Last push
Cross-platformPlatform

What it does

SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and JSON CLI results from safe AI…

✅
Our take
Works — verified, early-stage project

SecurStack adapter for DeepSeek Harness: run repository security scans, policy gates, doctor diagnostics, and JSON CLI results from safe AI… It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

SecurStack DeepSeek Harness Plugin

SecurStack DeepSeek Harness Plugin

SAST SCA DAST Secrets detection IaC security Policy as code

DeepSeek Harness plugin for running SecurStack security checks directly from an AI-agent workflow.

The plugin registers safe, non-destructive Harness tools that call the official securstack CLI to scan repositories, return structured JSON results, run environment diagnostics, and evaluate scan output against repository policy gates. It lets DeepSeek Harness ask SecurStack what is risky, what is misconfigured, and whether a codebase passes policy without reimplementing SecurStack product logic inside the plugin.

This package is intentionally a thin adapter. It does not implement scan engines, encryption, upload logic, API contracts, or Shielding operations. Those responsibilities stay in @securstack/cli and the SecurStack SaaS.

Capabilities

  • Repository security scans via securstack scan --format json.
  • Policy gates for CI-like pass/fail decisions with securstack policy check.
  • Local setup and credential diagnostics through securstack doctor.
  • Harness-friendly tool responses with parsed JSON where the CLI promises JSON output.
  • Existing SecurStack authentication through securstack login, SECURSTACK_API_KEY, and SECURSTACK_API_URL.
  • Adapter-only design that avoids destructive hooks, Shielding writes, or duplicated product contracts in v1.

Security Coverage

SecurStack coverage is represented through the CLI contract exposed to Harness, including SAST-style code analysis, SCA dependency checks, secrets detection, IaC/security configuration review, policy-as-code gates, and CLI diagnostics. DAST-oriented workflows can be surfaced through SecurStack scan output and policy checks when supported by the configured SecurStack project.

Requirements

  • Node.js 20 or newer.
  • DeepSeek Harness developer preview.
  • SecurStack credentials configured with either:
    • securstack login --api-key <key>
    • SECURSTACK_API_KEY and optional SECURSTACK_API_URL

Install

dsh plugin --profile securstack add @securstack/dsh-plugin
dsh --profile securstack

Tools

  • securstack_scan: runs securstack scan --format json for a repository path.
  • securstack_doctor: runs securstack doctor.
  • securstack_policy_check: runs securstack policy check --input <scan.json> with optional risk and severity limits.

Examples

Ask DeepSeek Harness:

Run a SecurStack scan on this repository and summarize critical findings.
Check whether the last SecurStack scan passes the repository policy.
Run SecurStack doctor and tell me what is misconfigured.

Development

npm install
npm run build
npm test
npm pack --dry-run

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install securstack-dsh-plugin for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:securstack/securstack-dsh-plugin

Headless (CLI) profile:

dsh plugin --profile headless add github:securstack/securstack-dsh-plugin

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Automate a repetitive job — scheduling, chaining tasks, or reacting to events — so it runs without you starting it.

Who it's for

Users with recurring work who want it cron-style and hands-off rather than manually triggered.

For developers — extending it

Triggers and task templates are the seams — add event-driven or file-watch triggers, and richer workflow composition.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Automation

Browse all 7797 plugins →