@gpzhang2001/sharpkit-bundle
v0.2.2
Published
sharpkit pentest suite install bundle: assembles every suite package behind one dsh profile patch layer
Readme
@gpzhang2001/sharpkit-bundle
安装入口:dsh plugin --profile pentest add @gpzhang2001/sharpkit-bundle 后由 dsh.bundle.patch 声明自动进入 profile bundles 层。
组合前提
- 本 bundle 只挂套件自身的 10 个包。subagent 服务、spawn/fork provider、delegation 工具、jobs、approval、skill、attachment、web 全部随
@deepseek-ai/dsh-base进入(所有 base-backed profile 的第一层),tool-team 直接消费ctx.subagents,无需在本层重复挂载。 - 沙箱镜像不随 bundle 分发:用户按
sandbox-image/README.md构建或从 registry 拉取。
配置覆盖示例
各包的 Config 通过 profile 自己的 cordis.patch.yml 按 row id 覆盖(patch 行支持 config,整块替换而非合并):
# $DSH_HOME/profiles/pentest/cordis.patch.yml
- id: pentest-tool-reporting
config:
scanMode: quick
authMode: none
instruction: "weekly re-scan of staging"
- id: pentest-tool-proxy
config:
authorizedTargets: ["https://staging.example.com"]
- id: pentest-tool-team
config:
maxBudgetUsd: 8Known Limitations and Deferred Work
apply_patch工具有意未提供:模型可用 exec_command 或 dsh 原生 fs 工具等价完成。
