
hedgehog
HEDGEHOG codes Cleaner, Faster and with Fewer Tokens. Hedgehog's AI-driven development builds a task dependency graph from your spec-driven, BMAD-METHOD plan, so Claude Code, Cursor & Gemini CLI stay locked to it. A CLI-enforced state machine for agentic coding. Now builds DeepSeek DSH Plugins.
What it doesAI
HEDGEHOG is an AI-driven development tool that builds task dependency graphs from BMAD-METHOD plans to keep AI coding assistants on track.
- Builds task dependency graphs from spec-driven plans
- Enforces a state machine for agentic coding via CLI
- Works with Claude Code, Cursor, and Gemini CLI
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add @skyf0xx/hedgehogInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).
5.3.465bed01154282026-08-2165bed0115428suspicious · npmscore 29Vet is an AST static scan (npm artifact or git source).
`[](https://www.dsh.so/artifact/hedgehog/)`Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
Risk details
| Risk | Rule | Location | Description |
|---|---|---|---|
| high | R2 | dagre.min.js:2118 | Function() 动态构造函数 |
| medium | R9 | dagre.min.js:1903 | 正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯) |
| medium | R9 | dagre.min.js:2244 | 正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯) |
| medium | R2 | react-dom.production.min.js:13 | require() 动态模块加载(npm 包内能力触达) |
| medium | R9 | react-dom.production.min.js:85 | 循环内集合写入 map.set(无界增长信号) |
Activity
Last commit 2026-08-21 · activity: Active
• Repo created: 2026-08-21
• Stars: ★ 29 · Forks: 5
• Health: Active — committed within last 30 days
Source
GitHub: github.com/skyf0xx/hedgehog