dsh-skill-pack-security¶
⭐ 2 · ✅ active · skill
| Type | skill | Category | Security |
| Stars | ⭐ 2 | Status | ✅ active |
| Author | PerryLink | Updated | 2026-08-21 |
One-liner¶
Security-audit skill pack: 5 agent skills covering secret scan, dependency audit and more.
About¶
- 1024 store channel:
npm i -g dsh1024once, thendsh1024 plugin --profile web add dsh-skill-pack-security(counts toward the deepseek1024.com install ranking). Eight security-audit skills plus an automated plugin supply-chain gate for DeepSeek Harness. The skills teach the audit methodology; theplugin_vettool executes the pre-install scan — license / SBOM / commit pinning / malicious patterns / five-dimension risk card. English · 简体中文 · Español · Português · हिन्दी ---
✨ Key Features¶
- 1024 store channel:
npm i -g dsh1024once, thendsh1024 plugin --profile web add dsh-skill-pack-security(counts toward the [deepseek1024.com](https://d
📦 Install¶
# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-skill-pack-security#main"
# or from npm (published releases)
dsh plugin --profile web add @perrylink/dsh-skill-pack-security-provider
# 2. restart and verify the row
dsh --profile web --dump-config | grep -A3 'id: skill-pack-security'
🚀 Quick Start¶
./scripts/install.ps1 -Target user-agents -Language zh # Target: project-dsh | project-agents | user-dsh | user-agents; Language: zh (default) | en
📚 Learn more¶
plugin_vet — the automated pre-install gate
plugin_vet is the pack's automated complement: a zero-dependency scanner registered by the provider/ plugin on ctx.tools. Point it at a GitHub owner/repo or a local package path — it downloads the tarball once (timeout + AbortSignal respected), scans within budget limits, and returns a render card. Install gate. The verdict feeds an installation gate — gate.policy: warn (default, n
Installing the skills by hand
DSH's local skill provider scans four roots by rank (lower rank wins same-name conflicts within a layer): Ranks (lower wins same-name conflicts within a layer): project-dsh 100 < project-agents 200 < custom 300 < user-dsh 400 < user-agents 500. Custom rank 300 is plugin-registered (such as this pack's optional provider/), not a disk root. ./scripts/install.ps1 -Target user-agents -Language zh
Configuration
All tunables are Schemastery Config fields (changeable from cordis.yml). provider/cordis.patch.yml documents each key inline.