MIT-licensed dsh plugin that bundles seven security-analysis domains into a single preset-scoped Agent package — 31 tools, an evidence-chain case workspace, and on-demand reference knowledge — activated with the `helmd` keyword inside dsh.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-09-06
License
MIT
01What can it help you accomplish?
Run all-domain security analysis inside DeepSeek Harness (Android / Web / Native / Protocol / Malware / AI-Security)
31 tools + a 7-domain router + an evidence chain; the model reads references/ on demand and returns severity/confidence-graded conclusions
Security researchers and reverse engineers running dsh who want every domain's tooling loaded in one pass
Build a reproducible evidence chain and case workspace
begin_case creates a disk workspace; tool output auto-enters evidence/, and conclusions must cite E-numbers via record_finding
Analysts who need auditable, reproducible forensic conclusions
02How to install into DeepSeek Harness
Prerequisites
- Already installed the dsh CLI and pnpm (README 前提:已安装 dsh CLI 与 pnpm)
- Node >= 22.19 (README badge: Node >=22.19)
Installation steps
- 01
Windows: double-click install.bat, or run `.\install.ps1` in PowerShell
- 02
macOS / Linux: run `./install.sh`
- 03
Start `dsh web`; send `helmd` in the session to activate
$ dsh web
Verify the integration
- Run `dsh --profile web --dump-config` — should show only the @dsh-security/helmd/dist/health.js global line
- Run `node packages/helmd/scripts/gen-preset.mjs --check` — preset check OK
- Settings → Plugins → Plugin config should show a green 「健康 Healthy」 helmd card
03DSH integration and capability boundaries
Single npm bundle `@dsh-security/helmd` mounts via cordis.patch.yml; one preset injects preset-scoped tools into the helmd Agent
Seven-domain routing & security analysis
user security-analysis request (Android / Web / Native / Protocol / Malware / AI-Security)→31 domain tools + deterministic router + E-numbered evidence-chain conclusions
On-demand reference knowledge base (references/)
domain reference-doc requests→read_reference reads references/<domain>/; the model judges autonomously, nothing injected into the system prompt
Evidence chain & case workspace (Case)
forensic / reproduction tasks→begin_case builds a disk workspace; tool output auto-enters evidence/; conclusions must cite E-numbers
04Who is it for? When not to use it?
Good for
- Security researchers and reverse engineers running dsh who want every domain's tooling loaded in one pass
- Analysts who need auditable, reproducible forensic conclusions
Not for
- A dsh host upgrade can break compatibility; helmd pins peer deps cordis/dsh-tools via overrides and exposes drift through a 3-layer preset fingerprint guard.
- README states it is for study/communication only; users must obey local laws and bear all consequences of using the project.
05Compatibility, maintenance and safety notes
- A dsh host upgrade can break compatibility; helmd pins peer deps cordis/dsh-tools via overrides and exposes drift through a 3-layer preset fingerprint guard.
- README states it is for study/communication only; users must obey local laws and bear all consequences of using the project.
- If python is absent on the host, the seam auto-detects python / py / python3 (Windows-compatible py -3).
readme_verified
06Frequently asked questions
What is helm-d and how does it integrate with DeepSeek Harness?
helm-d is a DeepSeek Harness plugin shipped as the single npm bundle `@dsh-security/helmd`. It mounts through a cordis.patch.yml bundle list and injects preset-scoped tools into a dedicated helmd Agent — no manual per-domain add or preset assembly.
How do I install helm-d into my dsh setup?
Run install.sh on macOS/Linux or install.ps1 on Windows; the installer downloads the latest helmd.tgz Release, loads the profile and writes the preset, then run `dsh web` and send `helmd` to activate. You can also add it from the plugin store via `dsh plugin --profile web add <tarball-or-source>`.
Which analysis domains and tools does it expose?
Seven domains — Android, Web, Native, Protocol, Malware, AI-Security plus Evidence/Case — across 31 tools, including apk_fingerprint, detect_packer, ioc_extract, yara_gen, pcap_parse, llm_sim and the deterministic route_task router.
How do I verify the installation succeeded?
Run `dsh --profile web --dump-config` (only the health.js global line should show), `node packages/helmd/scripts/gen-preset.mjs --check` (preset check OK), and confirm a green 「健康 Healthy」 helmd card under Settings → Plugins → Plugin config.
Does it stuff domain knowledge into the system prompt or require manual preset wiring?
No. The 209 reference docs live in references/ and are read on demand via read_reference; the model judges autonomously. The installer derives the preset live from your installed dsh standard host, so platform lines never drift after a host upgrade.
07Related DSH workflows
archify
by tt-a1i
Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
openviking
by volcengine
Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.
nocobase
by nocobase
NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of production-proven infrastructure and a WYSIWYG no-code interface, so you get both speed and reliability.
learn-harness-engineering
by walkinglabs
Harness engineering beginner tutorial, from 0 to 1
08Data and sources
DeepSeek Harness 破甲一体化安全分析插件
全部能力收敛进一个 `@dsh-security/helmd` 包
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-09-06. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
