dsh-pentest: An Authorized Pentest Mode Plugin for DeepSeek Harness
howmp/dsh-pentest
A pentest mode for DeepSeek Harness that records targets, exploration leads, verified findings, assets and vulnerabilities, visualized via exploration graph, vulnerability and asset views in the web UI.
dsh-pentest is a pentest mode plugin for DeepSeek Harness that organizes authorized penetration testing into an actionable exploration chain. It lets you record targets, explore clues, and verify results directly in DSH, visualized in the web UI with exploration chain, vulnerability, asset, and report views. Maintained by howmp and written in JavaScript, it requires Node.js 22.5 or higher, ideal for teams needing systematic authorized pentesting within DSH.
How to Install
dsh plugin --profile web add github:howmp/dsh-pentest- Category
- Development & Operations
- Platform
- DSH Plugin
- Author
- howmp
- Distribution
- Plugin
dsh-pentest Key Features
dsh-pentest Repo Summary
What Does It Do?
dsh-pentest is a DSH plugin for DeepSeek Harness that turns authorized penetration testing into an actionable exploration chain. It solves the problem of scattered goal recording, clue exploration, result verification, and asset/vulnerability management, letting you record targets, explore clues, verify results, and visualize them in the web UI with exploration chain, vulnerability, and asset views. Maintained by howmp, written in JavaScript, and recently updated in 2026-08, it requires Node.js 22.5 or higher.
Core Features
- Domain model: based on storage domain
pentest(version 2) with six tables (goals/intents/facts/findings/assets/edges), edges as chain vocabulary, findings require reproducible steps. - Deterministic IDs: node/edge IDs are session-counted, tool returns IDs for cross-call reference, session projection replays the same graph from logs.
- Toolset: provides
pentest_submit,pentest_add_goal,pentest_add_intent,pentest_add_fact,pentest_add_finding,pentest_add_asset,pentest_state,pentest_graph,pentest_reportcovering the full pentest workflow. - Session projection: collapses logged
pentest_*calls into{ goal, nodes, assets, edges, counts }, mirroring store's reference rejection, with a cap of 200 each. - Web tabs: registered per session, four sub-tabs—exploration chain (@xyflow/react graph with relationship capsules), vulnerabilities (severity/description/reproducible steps/affected assets), assets (list/graph modes), and report (Markdown rendering, copy and save).
- Protocol injection: system prompt segment
pentest:protocol(order 50), advancing along the chain, sub-agents write directly to parent intents viapentest_submit, assets parent-before-child, and user interaction in Chinese.
How to Use This Plugin?
After enabling it in DSH, restart dsh and select the auto-registered "Pentest Mode" in a new session. Use pentest_add_goal to set the target and fill in authorization details (authorized entity/written permission reference), then advance along the chain: add intents, facts, findings (with reproducible steps), and assets (optionally linked to a parent). All records are written to $DSH_HOME/storages/pentest-sessions.db (sqlite), and the web UI provides exploration chain, vulnerability, asset, and report views; reports can be copied or saved. Note that records are scoped to a single session—no cross-session continuation; starting a new engagement requires a new pentest_add_goal.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: howmp/dsh-pentest. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
