精选
为什么选中它
待人工精选——以下事实来自源码仓库。
它能做什么
Live CVE/supply-chain audit for your workspace's own dependencies (npm/pip/go), backed by OSV.dev. A DeepSeek Harness (dsh) Cordis plugin.
适合谁
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
风险提示
- 没有明确许可证,使用前确认授权。
Live CVE/supply-chain audit for your workspace's own dependencies (npm/pip/go), backed by OSV.dev. A DeepSeek Harness (dsh) Cordis plugin.
待人工精选——以下事实来自源码仓库。
Live CVE/supply-chain audit for your workspace's own dependencies (npm/pip/go), backed by OSV.dev. A DeepSeek Harness (dsh) Cordis plugin.
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
dsh plugin --profile web add github:SARTHAK2511/dsh-cve-audit 仓库没有提供 GitHub Topics。
作者没有声明支持的平台。
dsh-plugin-vetting, dsh-plugin-sentinel, upstream-radar) audit the plugin ecosystem itself. None of them scan the dependency lockfiles of the codebase you're actually working in. dsh-cve-audit fills that gap: it reads package-lock.json / requirements.txt / go.sum in the workspace, batch-queries OSV.dev (free, no API key), and reports known CVEs sorted by severity — as a real tool the agent can call, and optionally re-run automatically whenever a lockfile changes. ## Install sh dsh plugin add @dsh-plugins/dsh-cve-audit ## Usage Ask the agent to "audit dependencies for CVEs" — it will call the cve_audit tool. Or trigger it directly: cve_audit({ path: "." }) ## Config yaml watch: true # re-scan automatically on lockfile changes ecosystems: [npm, PyPI, Go] osvEndpoint: https://api.osv.dev/v1/querybatch ## Status Early scaffold — built against the publicly documented Cordis plugin API (ctx.tools.register, defineTool, Schema.object, ctx.effect). Not yet run against a live dsh install; the lockfile watch currently uses Node's fs.watch rather than a harness-native workspace-change event, since that event name isn't in the public docs yet — swap in the native hook once confirmed. PRs welcome.不看 Star,人工一条条挑的。
把 DSH 的 settings.yaml 做成可视化看板:所有已注册的 settings namespace——包括官方界面从未覆盖的第三方插件配置——都渲染成可编辑表单。项目还早,但方向很对:告别手改 YAML。
给 DSH 的 DIY 轨迹可视化:把 agent 的计划与执行画成图,不用翻原始日志也能看清它在干嘛。项目还早,但补上了「一眼看懂 agent 在做什么」这个真实缺口。
从 Claude Code / Codex 把活派给 DSH:在宿主内拉起带分级预设的 DSH agent 会话,看原生子代理进度,还能借它的多模态桥给纯文本的 DSH 补上视觉和生图。编排型插件,把 DSH 变成其他编码 agent 的后端。