Bundle
xby-scan-code
CodeGuard MCP是一款实时AI代码安全扫描工具,用于检测AI生成代码中的漏洞、密钥和合规性问题,适用于开发环境中的代码安全审查。
- Source
- xby-skill
- License
- MIT
- Updated
- Updated 6 days ago
Readme
# xby-scan-code DeepSeek Harness (DSH) 的插件:代码安全扫描工具 CodeGuard MCP是一款实时AI代码安全扫描工具,用于检测AI生成代码中的漏洞、密钥和合规性问题,适用于开发环境中的代码安全审查。 ## 功能 - **set_xby_apikey** — 在聊天中设置 API 密钥(自动持久化,重启有效) - **scanCode** — Scan code for security vulnerabilities, secrets, and compliance issues - **scanVulnerabilities** — Quick scan for code vulnerabilities only - **detectSecrets** — Detect exposed secrets, API keys, and credentials - **suggestSecureFix** — Generate secure code fixes for vulnerabilities - **checkCompliance** — Check code for regulatory compliance (GDPR, HIPAA, SOC2, PCI DSS) ## 安装 ### 方式一:从 GitHub 直接安装(推荐) ```bash # 格式: dsh plugin --profile <profile> add github:<owner>/<repo> dsh plugin --profile web add github:xby_skill/xby-scan-code ``` ### 方式二:从本地目录安装(开发模式) ```bash # 仅用于本地开发调试 dsh plugin --profile web add /absolute/path/to/xby-scan-code ``` ### 方式三:通过 cordis.patch.yml 开发调试 ```bash dsh web --profile web --patch /absolute/path/to/dsh-ocr-plugin/cordis.patch.yml ``` ## 配置 ### 获取 API 密钥 前往 [小笨羊官网](https://xiaobenyang.com) 注册并获取 API 密钥。
Install
dsh plugin --profile web add github:xby-skill/xby-scan-code
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install xby-scan-code from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.