Skip to content
dsh.fish
Bundle

xby-scan-code

CodeGuard MCP是一款实时AI代码安全扫描工具,用于检测AI生成代码中的漏洞、密钥和合规性问题,适用于开发环境中的代码安全审查。

Source
xby-skill
License
MIT
Updated
Updated 6 days ago

Readme

# xby-scan-code

DeepSeek Harness (DSH) 的插件:代码安全扫描工具

CodeGuard MCP是一款实时AI代码安全扫描工具,用于检测AI生成代码中的漏洞、密钥和合规性问题,适用于开发环境中的代码安全审查。

## 功能

- **set_xby_apikey** — 在聊天中设置 API 密钥(自动持久化,重启有效)
- **scanCode** — Scan code for security vulnerabilities, secrets, and compliance issues
- **scanVulnerabilities** — Quick scan for code vulnerabilities only
- **detectSecrets** — Detect exposed secrets, API keys, and credentials
- **suggestSecureFix** — Generate secure code fixes for vulnerabilities
- **checkCompliance** — Check code for regulatory compliance (GDPR, HIPAA, SOC2, PCI DSS)

## 安装

### 方式一:从 GitHub 直接安装(推荐)

```bash
# 格式: dsh plugin --profile <profile> add github:<owner>/<repo>
dsh plugin --profile web add github:xby_skill/xby-scan-code
```

### 方式二:从本地目录安装(开发模式)

```bash
# 仅用于本地开发调试
dsh plugin --profile web add /absolute/path/to/xby-scan-code
```

### 方式三:通过 cordis.patch.yml 开发调试

```bash
dsh web --profile web --patch /absolute/path/to/dsh-ocr-plugin/cordis.patch.yml
```



## 配置

### 获取 API 密钥

前往 [小笨羊官网](https://xiaobenyang.com) 注册并获取 API 密钥。

Install

dsh plugin --profile web add github:xby-skill/xby-scan-code

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source