dshplugin.devDeepSeek Harness Plugins
DSH Security Suite plugin logo
DeepSeek Harness Plugin

DSH Security Suite

1
Published by Zenquiem

Security assessment workflows for DeepSeek Harness

Security

Get this plugin

Review the source, then continue to the publisher.

dsh plugin add dsh-security-suite@latest
Get this plugin
Share on X ↗

About this plugin

Source snapshot 8/13/2026

DSH Security Suite

dsh-security-suite brings the security-review methodology of OpenAI Codex Security to DeepSeek Harness as a native Cordis bundle.

DeepSeek Harness is in developer preview; its plugin API may introduce breaking changes.

It is an independent implementation, not a wrapper around Codex Security's CLI. It migrates the Codex Security methodology and artifact model to DSH's Cordis runtime. The DSH agent supplies source-level reasoning and validation; tools persist the evidence, findings, reports, and review state.

Capability Matrix

Codex Security workflowDSH Security Suite capability
Standard and scoped scansecurity_scan (standard) and security_assess
Git diff scansecurity_review_diff
Deep scansecurity_scan (deep) plus the guided multi-pass workflow
Threat model and policysecurity_threat_model_template and the security workflow prompt
Discovery, validation, attack paths, triageCanonical findings from security_get_scan, persisted with security_update_finding
False-positive state and scan historysecurity_update_finding, security_scan_history, security_compare_scans
Vulnerability reportssecurity_finding_writeup and security_export_scan (Markdown/JSON/SARIF/CSV)
Fix and hardening proposalsGuided DSH workflow. Source edits remain explicit user-authorized actions.
GitHub, Jira, Linear trackingsecurity_tracking_preview; it produces an exact payload but never writes externally without a separate user-approved integration.

The plugin does not embed OpenAI's proprietary Codex scanning service, credential handling, or hosted external connectors. It therefore does not claim to reproduce their execution environment or create third-party tickets automatically. It retains the workflow, evidence, canonical result, export, and approval boundaries in DSH.

Install

Build the package, then add it to every profile where it should be available:

npm install
npm run build
dsh plugin --profile web add /absolute/path/to/dsh-security-suite
dsh plugin --profile headless add /absolute/path/to/dsh-security-suite

Verify the profile composition and run a scan:

dsh --profile web --dump-config
dsh run "Run a deep security scan, validate candidates, trace attack paths, and produce a report for this workspace."

Configuration

The bundle row accepts these settings:

config:
  enabled: true
  maxFiles: 500
  maxFileBytes: 262144

Scans only read source files inside the current workspace. They ignore dependency and build directories, limit file count and size, reject paths outside the workspace, and write state under the system temporary directory by default. Set DSH_SECURITY_SUITE_STATE_DIR or stateDir to retain scan history in a selected directory outside the target repository. Pattern-discovered results are candidate evidence, not vulnerability verdicts: validate them with source-backed attacker-to-sink analysis before reporting or tracking.

Attribution

This project adapts the workflow concepts of OpenAI Codex Security, which is licensed under Apache-2.0. No upstream source code is copied into this repository.

License

Apache-2.0.