What Is dsh-pentest? Authorized Pentest for DeepSeek Harness

GuidePublished 2026-08-30Author: DeepSeek Plugin Market
dsh-pentestpentestguide
dsh-pentest is an authorized pentest plugin for DeepSeek Harness that records goals, leads, findings, assets, and vulnerabilities across exploration chains.

The following positioning and facts for dsh-pentest come from the official README (source):

What Is dsh-pentest?

dsh-pentest is an authorized pentest mode plugin for DeepSeek Harness (DSH) that turns scattered pentest work into a traceable exploration chain. Its goal is to fix a real gap: a model can run pentests in API scenarios, but there is nowhere to store targets, leads, verified results, and vulnerability assets, so results are hard to verify and reports are hard to produce. dsh-pentest records goals, exploration leads, verified findings, assets, and vulnerabilities inside a DSH session with a set of pentest_* tools, and presents them in the web UI as exploration chain, vulnerability, asset, and report views. Maintained by howmp, it ships as a self-contained bundle package @howmp/dsh-pentest that distributes the host plugin, the web interface, and the sqlite backend together, so it can be connected from the plugin detail page right after install (source).

What Are the Core Features of dsh-pentest?

dsh-pentest brings the full record-verify-report workflow of authorized pentesting into DeepSeek Harness (source). As a dedicated pentest mode within the DSH Plugin ecosystem, it offers these real capabilities:

  • Goal and lead recording: set a target and record authorization with pentest_add_goal, add an exploration intent with exactly one anchor via pentest_add_intent, and let sub-agents write directly to a parent intent through pentest_submit.
  • Fact and finding capture: log exploration discoveries with pentest_add_fact and register vulnerabilities with pentest_add_finding; every finding requires at least one reproducible step and may link affected assets.
  • Asset modeling: maintain the asset inventory with pentest_add_asset, using an optional parentId to express parent-child hierarchy, with an empty string treated as a root asset.
  • Exploration chain visualization: the web UI renders the goal → intent → fact → finding progression with an @xyflow/react graph whose edges carry relationship capsules for intent chain, yield, derived-from, and proves.
  • Test report generation: produce a Markdown report with pentest_report that supports copy and save, leaving vulnerabilities, assets, and authorization details traceable in the output.
  • Deterministic ids and session projection: nodes and edges use deterministic <kind>-<n> ids so tools can return references across calls, and the session projection replays the same graph purely from logs.

How to Install and Enable dsh-pentest?

dsh-pentest installs from a Release tarball with one command, and takes effect after restarting dsh and selecting Pentest Mode in a new session (source). The install, update, uninstall, and enable steps are as follows:

1. Install from the Release URL. Run the install command from the official README in the DeepSeek Harness terminal to install directly from the Release asset:

bash
dsh plugin --profile web add https://github.com/howmp/dsh-pentest/releases/latest/download/dsh-pentest.tar.gz

2. Or install from a local file. Download dsh-pentest.tar.gz first, then point to the local file with a file: prefix:

bash
dsh plugin --profile web add file:C:\path\to\dsh-pentest.tar.gz

3. Enable: restart dsh after installing, then choose the auto-registered Pentest Mode in a new session to see the exploration chain, vulnerability, asset, and report tabs.

4. Update. Rerun the update command to overwrite the current version with the latest Release:

bash
dsh plugin --profile web update @howmp/dsh-pentest

5. Uninstall. Remove the plugin by its installed package name:

bash
dsh plugin remove @howmp/dsh-pentest

Typical dsh-pentest Usage

A complete authorized pentest starts with pentest_add_goal, proceeds step by step along the exploration chain, and finishes with pentest_report (source). The core call sequence is:

1. Set the goal and record authorization. This resets and establishes a new exploration graph:

bash
pentest_add_goal(target: "example.com", authorization: "customer written consent #A-2026-08")

2. Add an exploration intent. Use exactly one anchor each time, clarifying the next probing direction:

bash
pentest_add_intent(anchor: "<goal-or-fact-id>", summary: "enumerate subdomains and confirm exposure")

3. Record facts and assets. Sub-agents may write directly to a parent intent via pentest_submit; assets go parent-first:

bash
pentest_add_fact(intentId: "<intent-id>", summary: "admin subdomain is reachable")
pentest_add_asset(name: "admin.example.com", parentId: "")

4. Register a finding with reproducible steps. Every finding requires at least one reproducible path:

bash
pentest_add_finding(intentId: "<intent-id>", title: "unauthorized access to admin panel", severity: "high",
  reproducibleSteps: ["visit https://admin.example.com/login", "GET /api/users directly returns 200"])

5. Generate the test report:

bash
pentest_report()

dsh-pentest Troubleshooting

The common issues with dsh-pentest center on session scope, graph window limits, required finding steps, and the runtime version (source). Each troubleshooting point is listed below:

1. symptom: Pentest Mode does not appear in a new session after installing. Cause: dsh was not restarted after install, or the host runtime is below Node.js 22.5 so the sqlite backend (node:sqlite) cannot load. Fix: restart dsh and open a new session; if it still fails, upgrade Node.js to 22.5 or higher and try again.

2. symptom: earlier nodes are missing from the web exploration graph, or the node count does not match the full record. Cause: the session projection keeps only the latest 200 nodes, assets, and edges each; older entries are evicted, and the UI only reflects this window. Fix: read the storage layer with pentest_state or pentest_report for the full record instead of relying on the UI graph.

3. symptom: adding a finding is rejected and the record cannot be written. Cause: the domain model requires at least one reproducible step per finding, and the tool refuses writes without steps. Fix: retry with a reproducibleSteps array containing at least one executable path.

4. symptom: the previous exploration graph disappears after starting a new task. Cause: records are scoped to a single session, and pentest_add_goal resets the whole graph; this is a designed boundary, not a fault. Fix: run pentest_report to export the report first, then start a new engagement.

Use Cases and Notes

dsh-pentest fits teams that want to run authorized pentesting, vulnerability verification, and report capture systematically inside DeepSeek Harness (source). Typical scenarios include red team record keeping, lead and evidence management for pentest engagements, and assessment work that must deliver structured reports to clients. Keep these notes in mind: only test authorized targets, since the authorization parameter is an audit fact while scanning and exploitation remain constrained by the deployment sandbox and approval; records are scoped to a single session with no cross-session continuation; the exploration graph uses a static layered layout that supports pan and zoom but not node dragging; Node.js 22.5 or higher is required; and the plugin interacts with users in Chinese by default.

dsh-pentest is an open-source project maintained by howmp for authorized pentesting on DeepSeek Harness. For the full introduction, see the plugin detail page on this site: dsh-pentest plugin details.

This page is an independent guide rewritten from the plugin's official README — for the authoritative documentation and the latest changes, defer to the source: howmp/dsh-pentest. A plugin is third-party code that runs on your machine once installed; inclusion is not an endorsement — review the source before installing.

FAQ

Does dsh-pentest continue pentest records across sessions?

No. dsh-pentest scopes all pentest records to a single session with no cross-session or cross-project continuation; to start a new engagement you call pentest_add_goal, which resets the entire exploration graph.

How many nodes can the dsh-pentest web exploration graph show at most?

The session projection of dsh-pentest keeps the latest 200 nodes, assets, and edges each; when exceeded, the oldest are evicted and dangling edges are cleaned up. The UI count and graph reflect this window, while the full record is available via pentest_state or pentest_report.

Why must findings in dsh-pentest include reproducible steps?

The domain model of dsh-pentest requires every finding to provide at least one reproducible step so each vulnerability discovery has a verifiable reproduction path, aiding verification and report traceability; the tool rejects writes without steps.

Is the authorization parameter in dsh-pentest a security gate?

No. The dsh-pentest authorization parameter in pentest_add_goal is an audit fact written to state and the final report; it does not block any action. Scanning and exploitation remain constrained by the deployment sandbox and approval, so only test authorized targets.

What Node.js version does dsh-pentest require and why?

dsh-pentest requires Node.js 22.5 or higher because its sqlite backend uses the node:sqlite module; with a lower host runtime the plugin may fail to read or write pentest records or fail to start pentest mode.

How do I start a pentest in dsh-pentest within DeepSeek Harness?

After installing dsh-pentest and restarting dsh, select the auto-registered Pentest Mode in a new session, then use pentest_add_goal to set the target and fill in authorization details to begin; record along the chain with pentest_add_intent, pentest_add_fact, and pentest_add_finding, and finish with pentest_report.

Related Terms

dsh-pentest
dsh-pentest is an authorized pentest mode plugin for DeepSeek Harness that records targets, exploration leads, verified results, assets, and vulnerabilities, shown in web views for exploration chain, vulnerability, and assets.— dsh-pentest README
Exploration chain
An exploration chain is the causal progression that dsh-pentest builds with edge vocabularies spawns, yields, derived_from, and proves to connect goals, intents, facts, and findings.— dsh-pentest README
pentest_add_goal
pentest_add_goal is the dsh-pentest tool that sets a pentest target, resets the entire exploration graph, and can record an authorization note into state and the final report.— dsh-pentest README
Session projection
A session projection is the graph structure dsh-pentest rebuilds by replaying logged pentest_* calls, containing goal, nodes, assets, edges, and counts, with a window of the latest 200 each.— dsh-pentest README

Sources

View all articles