Skip to main content

dsh-pentest

141Stars18Forks1Issues0Watchers

Adds a "Penetration Mode" to DeepSeek Harness: records targets, exploration paths, vulnerabilities, and assets within authorized scope, displaying the full graph in real-time on the web with a zoomable view.

Evidence4/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
JavaScript
Branch
master
deepseek-harnessdsh-plugindsh-pluginspentest

Install

cmdweb profile
$ dsh plugin --profile web add github:howmp/dsh-pentest

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin howmp/dsh-pentest for me: review the repository at https://github.com/howmp/dsh-pentest first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Positioning

Switch DeepSeek Harness into "Penetration Mode": the decision agent advances along the exploration chain goal → intent → fact → finding, sub-agents write discoveries back to persistent storage, and the Web end presents real-time scalable exploration graphs, vulnerability cards, asset relationship graphs, and the final Markdown report.

Core Capabilities

  • Record penetration targets, authorization declarations, and the purpose of each engagement within authorized scope, serving as root nodes of the entire graph
  • Advance along the "goal → intent → fact → derived intent → finding" chain, with all nodes and edges persisted, sub-agents write discoveries back in real-time via dedicated tools
  • Record assets (root domain, subdomains, IP, services, applications, endpoints) and support parent-child ownership relationships, forming an asset graph
  • The "Penetration" tab on Web end presents target summary, exploration chain, vulnerabilities, assets, and final report in real-time
  • Vulnerability records require reproducible steps (ordered list of commands/requests/actions), which can be linked to affected assets
  • One-click generation of Markdown reports with authorization declarations, exploration chain, vulnerability details with reproducible steps, and asset list, supporting copy and download

Technical Implementation

  • Language: TypeScript (host-side ESM) + React + CSS Modules (Web side), bundled as single package @howmp/dsh-pentest
  • Key Dependencies: zod (persistent record validation), @xyflow/react (exploration graph and asset graph rendering), @deepseek-ai/schemastery (sqlite backend table structure), React 18 (Web runtime)
  • Architecture Pattern: Cordis patch layer bundle—cordis.patch.yml simultaneously inserts Web UI entry (ui-pentest), sqlite backend entry (storage-sqlite, path $DSH_HOME/storages/pentest-sessions.db) and storage-domain route override (only pentest domain goes to sqlite, other domains maintain host default json), and mounts a pentest-preset-root to auto-register "Penetration Mode" preset; host side injects pentest:protocol system prompt segment and registers eight pentest_* tools, client side dynamically mounts "Penetration" tab based on current session's agent preset
  • Entry Files: src/index.ts (host placeholder), src/dsh-pentest/src/index.ts (real plugin apply), src/dsh-client-ui-pentest/src/client/index.ts (browser-side session-aware tab registration)

Use Cases

When security engineers run authorized penetration tests within DSH, they want the main agent to systematically advance reconnaissance, gather facts, confirm vulnerabilities, and record each step for easy review and reporting, without manually organizing logs or switching between multiple tools.

Prerequisites and Compatibility

DependencyMinimum VersionDescription
DeepSeek Harness0.1.0-rc.6Bundle built on this version; peerDependencies all pinned to 0.1.0-rc.6
Node.js>=22.5SQLite backend uses Node's built-in node:sqlite, requires host runtime ≥ 22.5
PlatformmacOS / Windows / LinuxHost itself is cross-platform; preset disables bash on Windows, disables pwsh on macOS/Linux
Native Modulenode:sqliteBuilt into Node, no extra installation needed, but requires host Node version to meet minimum above
React^18.2.0Runtime requirement for Web bundle

Installation

dsh plugin --profile web add github:howmp/dsh-pentest

Configuration

This plugin requires no additional configuration. After installation, DSH automatically registers the "Penetration Mode" preset and mounts the sqlite backend, storage-domain routing, and Web tab all at once; select "Penetration Mode" when creating a new session to use it.

FAQ

Q: Who is really responsible for writing discoveries to persistent storage? Main agent or sub-agent?

A: The main agent (decision agent) maintains the entire graph through five write tools: pentest_add_goal, pentest_add_intent, pentest_add_fact, pentest_add_finding, pentest_add_asset; execution/exploration sub-agents can only call pentest_submit, the service looks up the parent session from the parent-child session relationship and writes to it, the main agent does not transcribe again.

Q: Where are penetration records stored? Will other feature data be affected?

A: All go through the bundle's built-in sqlite backend, file located at $DSH_HOME/storages/pentest-sessions.db; storage-domain routing only switches pentest domain to sqlite, other storage domains keep host's default json backend, chat/skills data not affected.

Q: Can vulnerabilities be submitted without reproducible steps?

A: No. Both pentest_add_finding and pentest_submit require at least one reproducibleSteps, less than one will be rejected by schema at the persistence layer; this is to avoid recording "unconfirmed guesses" as vulnerabilities.

Q: Can I continue running the same penetration record across sessions?

A: No. The record's physical key is sessionId:id, and every call to pentest_add_goal within the same session clears the entire graph and resets the id counter; to preserve results, first export using pentest_state / pentest_graph / pentest_report.

Q: Will the plugin itself intercept "unauthorized targets" for me?

A: No. The authorization field of pentest_add_goal is declarative information written into the goal, appears in the final report for traceability, but the plugin itself does not do access control; real scan/exploitation interception depends on deployment-side sandboxing, approval, or network isolation.

Q: When does the "Penetration" tab appear on Web? Will regular sessions see it too?

A: No. The tab only registers when the current session (or ancestors in its session list) uses the pentest agent preset; regular sessions won't see this tab even with the bundle installed.

Q: Can I use it on Windows? How are shell tools handled?

A: Yes. The bundle itself is cross-platform, but the preset disables bash tools and enables pwsh tools, so Windows users directly use PowerShell; the sqlite backend also works because host Node >= 22.5 includes node:sqlite.

Q: If I want to completely uninstall this plugin, what about the records?

A: Just uninstall the plugin with dsh plugin --profile web remove howmp/dsh-pentest; the sqlite database file $DSH_HOME/storages/pentest-sessions.db won't be automatically deleted, need manual cleanup.

Difficulty Level

Advanced — requires familiarity with DSH's agent presets, sub-agent delegation, and the "proposal → decision → execution" workflow; select authorized target and purpose before first enable, subsequent sub-agent delegation templates are built into the preset making the threshold relatively low, but truly running it still requires understanding DSH's session and storage concepts.

Known Issues and Limitations

  • Each session can only keep the latest 200 nodes / 200 edges / 200 assets, after exceeding the oldest will be evicted along with dangling edges; what Web sees is just the window view, full records should be read from persistence layer via pentest_state / pentest_report (source: src/dsh-pentest/src/projection.ts:88-90, README.md:78-79)
  • pentest_add_goal is a privileged operation within a session, any agent with the tool calling it once will clear the entire graph and reset the id counter; accidentally calling it during execution is equivalent to deleting all penetration data for this session (source: src/dsh-pentest/src/store.ts:241-256, docs/goal-reset.md:1-9)
  • Does not support continuing the same record across sessions or projects—records are isolated by session, starting a new engagement can only create new goal (source: src/dsh-pentest/README.md:115-118, README.md:77)
  • Plugin does not do authorization gatekeeping: authorization is only written as audit field into goal and final report, sandbox/approval remains the deployment side's responsibility (source: src/dsh-pentest/src/spec.ts:42-46, README.md:74-76)
  • Sub-agent write-back currently has no mechanism to verify whether the main agent "fully transcribed" the discoveries, depends on decision agent's conscientiousness (source: src/dsh-pentest/README.md:121)
  • Exploration graph and asset graph on Web use static layered layout, only supports pan and zoom, nodes are not draggable (source: README.md:80, src/dsh-client-ui-pentest/README.md:55-56)
  • SQLite backend relies solely on storage-domain's single-domain serialization guarantee when multiple agents simultaneously write to the same session, concurrent multi-agent writes to the same session won't be additionally queued (source: src/dsh-pentest/README.md:122-123)
  • Persistence backend depends on Node's built-in node:sqlite, therefore host Node must be >= 22.5; sqlite entry on older Node versions will fail when opening database (source: packages/dsh-storage-sqlite/lib/index.js:3, docs/storage.md:4)
  • Web "Penetration" tab is read-only view, pausing, resetting, continuing engagement still needs to go back to main agent's pentest_* tools or future command surface (source: src/dsh-client-ui-pentest/README.md:50-52)

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/howmp/dsh-pentest)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory