跳到正文
dsh-market 浏览插件 GitHub EN

PerryLink/dsh-click

Windows 桌面电脑操作工具(点击、输入、按键、截屏):每次动作都带新鲜度校验、审批门、进程身份核验与脱敏审计。

Star 数 ★ 16 分类 工具与能力 收录于 2026-09-03 npm dsh-click

安装

在 DeepSeek Harness 里通过 dsh-market 安装

dsh plugin --profile web add dshmarket

或使用命令行

dsh plugin --profile web add dsh-click

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络。请先审阅源码,并尽量锁定 commit(github:owner/repo#sha)。

README

🖱️ dsh-click

  • 1024 商店渠道:先 npm i -g dsh1024,再 dsh1024 plugin --profile web add dsh-click(计入 deepseek1024.com 安装排行)。

DeepSeek Harness 的跨平台原生桌面控制 —— Windows 优先。

先看清屏幕,再动手 —— 每次点击都过审批,每次操作都留审计。

dsh-doctor DSH Market

English · 简体中文 · Español · Português · हिन्दी


⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

兼容性

方面 状态
Harness DeepSeek Harness dsh-v0.1.7-rc.2(GitHub tag,2026-09-24 已核验)。已于 2026-09-11 对照 dsh-v0.1.7-alpha.1 master checkout 核验(完整门禁链 + profile 安装冒烟)。
Node ^22.19.0 || >=24.0.0
平台 Windows 优先(UIAutomation + Win32 输入,经由内置 PowerShell 辅助进程);macOS/Linux 后端已预留,失败时以明确原因关闭
模型 纯文本模型完整可用(screen_read 输出结构化文本);视觉模型额外获得 screen_shot 图像

你能得到什么

dsh-click 为 harness 提供完整的「观察 → 行动」闭环,作用于原生桌面应用:

  • screen_shot —— 截取窗口(或主屏幕)截图,按可配置上限缩放。视觉模型会附带图像;纯文本模型则获得文字描述,照常可用。
  • screen_read —— 结构化观察:窗口的无障碍树(元素 id、类型、名称、矩形、支持的模式)加像素位置提示与颜色 —— 纯文本,无需图像模型。
  • click / type / scroll / key —— 以元素 id 或坐标寻址的窗口级操作。优先 UIA invoke,回退到 post 窗口消息 —— 且绝不抢占前台焦点。
  • app_list / app_launch —— 枚举运行中的应用及其窗口;按名称或路径启动应用。

每个变更性操作都穿过同一条安全边界:

  1. 新鲜度 —— 操作必须引用 basedOn 观察;执行前重新捕获窗口,屏幕变化(像素哈希 + 最大时限)即拒绝。
  2. 审批 —— 默认经 ctx.approval 门禁;可用窗口标题/可执行路径正则放行特定窗口(仍记录审计)。
  3. 进程身份 —— 操作前后分别校验所属进程 pid 与可执行路径;发生变化即大声拒绝。
  4. 审计 —— 观察与操作以 dsh-click/observed / dsh-click/action 事件写入会话日志(脱敏、仅日志)。
模型                           harness
  │ screen_read ──▶ observationId (+ 元素、像素)              ← 结构化文本
  │ click {basedOn, target} ──▶ 新鲜度校验 ──▶ 审批 ──▶ helper (UIA)
  │                             像素哈希变化? ── 拒绝并要求重新观察
  │                             操作后 pid/exe 变化? ── PROCESS_CHANGED
  │ ◀── 规范 JSON + 审计事件 (dsh-click/action)

快速开始

# 1. 把 bundle 装进你的 profile
dsh plugin --profile web add "github:PerryLink/dsh-click#main"

# 或从 npm 安装(正式发布版)
dsh plugin --profile web add dsh-click

# 2. 重启并核实行
dsh --profile web --dump-config | grep -A2 'id: dsh-click'

然后让 agent 观察窗口并操作 —— 每次变更性操作都会弹出审批:

> 打开记事本,输入 "hello",再读回屏幕上的内容。

安装与卸载

  • git 通道(最新 main):dsh plugin --profile web add "github:PerryLink/dsh-click#main" —— prepare 脚本仅用生产依赖构建。
  • npm 通道(正式发布版):dsh plugin --profile web add dsh-click。
  • tarball 通道:在本仓库执行 pnpm pack,然后 dsh plugin --profile web add ./dsh-click-<version>.tgz。
  • 卸载:dsh plugin --profile web remove dsh-click(或从 profile patch 中删除该行)。

如果 pnpm 对本包报 ERR_PNPM_IGNORED_BUILDS(esbuild 的平台二进制无害校验),在你的 pnpm-workspace.yaml 中加入 allowBuilds: { esbuild: true } —— dsh CLI 会打印确切片段。

配置

所有可调项都是 Schemastery Config 字段(可在 cordis.yml 中修改)。按 id 定向覆盖会替换整行 —— 需要重新声明每个键。cordis.patch.yml 内联说明了每个键。

键 默认值 含义
requireApproval true 每个变更性操作都过审批;观察类工具从不询问
autoApproveWindows [] 跳过审批询问的窗口标题/可执行路径正则(仍做新鲜度校验并审计)
auditSessionEvents true 是否向会话追加 dsh-click/observed/dsh-click/action 审计事件。自适应门已在无信封宿主(rc.6–rc.8、0.1.1-rc.2,以及对未知类型读取即失败的 0.1.2-rc.1)上自动跳过追加;设为 false 可完全停止审计追加 0.1.2-rc.1(2026-09-02 已适配):会话信封保留 ignorable 字段但仅用于存量日志读取兼容——Session.append 仍无法盖章,门控行为不变。
focusFallback never 操作是否可在最后手段下把目标窗口带到前台(never / allow)
imageMode auto screen_shot 渲染:auto(模型支持图像时附图像,否则文字)或 text
helperTimeoutMs 30000 每次 helper 调用的超时(毫秒,1..300000)
maxHelperOutputBytes 25165824 单次 helper 响应的字节上限(1024..67108864)
maxScreenshotSide 2560 截图最长边像素(320..7680);超出即缩放
staleCheckPixels true 每次操作前对比新像素哈希,变化即拒绝
maxObservationAgeMs 30000 操作可引用观察的最大时限(毫秒,1000..600000)
maxCachedObservations 8 观察缓存 LRU 上限(1..64)
maxElements 500 每次 screen_read 的无障碍元素上限(1..2000)
maxTreeDepth 32 无障碍树遍历最大深度(1..64)
maxTextLength 200 脱敏后模型可见字符串的截断长度(16..10000)
rollbackEnabled true type 失败时备份并还原控件文本
ocr.enabled / command / language true / tesseract / eng screen_find 的可选 OCR(挂载时探测;无 tesseract 时降级为不可用)

profile patch 中的覆盖示例:

- insert:
    - id: dsh-click
      name: dsh-click
      config:
        requireApproval: true
        autoApproveWindows: ['^Notepad']
        focusFallback: never

工具与界面

工具 只读 需要审批 说明
screen_shot ✅ — 返回 observationId 供后续操作在 basedOn 中引用;模型支持图像时附带图片
screen_read ✅ — 无障碍树 + 像素提示;元素 id 是操作的寻址方式
click ✅ elementId 与 (x, y) 二选一;优先 UIA invoke,回退 post 消息
type ✅ 仅限 value 模式元素;失败时备份并还原控件文本
scroll ✅ 元素(scroll 模式)或窗口(post 滚轮)
key ✅ post 按键组合("Ctrl+S");忽略 post 输入的应用会大声拒绝
app_list ✅ — 运行中的应用及其可见窗口
app_launch ✅ 按名称或可执行路径启动,可带参数

权限与数据

  • 权限:变更性操作走官方 ctx.approval 接缝 —— 插件从不重实现或绕过它。白名单只会对特定窗口跳过询问,不能关闭新鲜度或进程身份校验。
  • 数据:除 attachment store 保存的截图(内容寻址、受 harness 自身附件策略约束)外,插件不落盘任何东西。观察仅存内存(有界 LRU)。无网络请求,不存凭据。
  • 会话日志:dsh-click/observed 与 dsh-click/action 是仅日志的审计事件,携带脱敏后的窗口/进程事实 —— 标题、路径与自由文本在写入或展示前均先脱敏并截断。

安全边界

  • 先观察后行动,每次如此。 操作必须引用新鲜观察;屏幕变化(像素哈希)或观察过期即拒绝,并以模型可读的原因要求重新观察。
  • 审批是默认。 除非你显式放行特定窗口,否则 requireApproval: true;每次操作 —— 无论放行与否 —— 都记录审计。
  • 不抢前台焦点。 helper 从不把目标窗口带到前台(默认 focusFallback: 'never');输入经 UIA 或 post 消息送达,不打扰后台窗口。
  • 进程身份前后复验。 每个操作前后立即校验进程身份;操作中途进程被替换则判失败(PROCESS_CHANGED)。
  • 输出脱敏。 控制字符被剥离、制表符折叠、凭据形态内容(密钥、token、JWT、bearer 头)在到达模型或日志前一律打码。
  • 失败关闭。 不支持的平台、缺失的 subprocess 服务或不可用的 helper 都会大声拒绝每个调用 —— profile 在任何地方都能正常启动。

已知限制

  • Windows 优先。 macOS 与 Linux 后端已预留;在这些平台上每次调用都以明确原因失败关闭。
  • 纯文本保真度。 screen_read 依赖应用暴露 UIAutomation;没有无障碍树的应用只有像素提示。坐标点击仍然可用。
  • post 输入类应用。 部分应用忽略 post 窗口消息(游戏、部分 Electron 界面);key 会如实报告而非假装成功。
  • 无信封 harness 构建上的会话审计。 审计事件走自适应门:认识该词汇的宿主直接追加,带 ignorable 信封的宿主带标记追加,无信封宿主——0.1.0-rc.6–0.1.0-rc.8、0.1.1-rc.2 以及无法盖章 ignorable 标记——信封字段仅为存量日志读取兼容而保留——且对未知类型读取即失败的 0.1.2-rc.1——不追加审计事件;工具结果仍是可重建的审计轨迹。设 auditSessionEvents: false 可完全停止审计追加。

开发

pnpm install        # node ^22.19 || >=24
pnpm run typecheck  # tsc:src + tests,对照本地 harness checkout
pnpm run typecheck:ci  # tsc:对照已发布的 0.1.7-rc.2 类型(无 paths)
pnpm test           # vitest:66 个测试、11 个文件(helper 冒烟在 Windows 上运行)
pnpm run build      # tsdown bundle + tsc 声明(lib/)
pnpm run verify:self-contained  # 依赖声明全部来自 registry
pnpm run verify:artifacts       # 构建产物 ESM 面 + 原生 helper 齐全
pnpm pack           # 发布用 tarball

Topics

dsh, dsh-plugin, deepseek-harness, deepseek, cordis, computer-use, windows-automation, uiautomation, desktop-control, screen-reader

Contributors

  • @PerryLink —— 创建者与维护者:工具面、操作安全边界、Windows 原生 helper、脱敏层与五语文档。
  • @Mchsd —— 新增 auditSessionEvents 开关,供会话读取器拒绝 dsh-click 审计事件的主机退出审计追加(#2)。

PerryLink DSH Plugin Family

This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

Plugin One-liner
dsh-auto-review Second-model auto-review on the approval chain, fail-closed by default
dsh-autotier Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-background-agents Durable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budget Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-catalog DSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcp Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-checkpoint-rewind Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-move Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-click Cross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-history Terminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-quality Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defend Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheck Engineering-discipline guard: requirements grill, test gates, adversary review
dsh-draw Unified static-image generation routing for DeepSeek Harness.
dsh-fast Read-only performance diagnostics for DeepSeek Harness.
dsh-fund-research Deterministic research reports for Chinese public mutual funds
dsh-github GitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-research Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-laya Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools
dsh-library Local document knowledge base for DeepSeek Harness.
dsh-local-ai Local-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actions LSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-mask PII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panel Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-memento Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-observe OpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-styles Claude Code outputStyles-equivalent runtime style switching
dsh-permission-rules Claude Code-style declarative allow/deny/ask permission rules with audit
dsh-plugin-certification Community certification registry with repro-checkable grades and badges
dsh-plugin-doctor Zero-dependency static + sandbox smoke detector for DSH plugins
dsh-plugin-guide Plugin-development knowledge base as an on-demand agent skill
dsh-plugin-kit Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-upgrade One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card
dsh-plugin-upgrade-015 Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-reach Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-report Verifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-score Multi-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pin Pin sessions in the Web sidebar with durable ordering
dsh-session-sync Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-security Security-audit skill pack: secret scan, dependency and supply-chain review
dsh-talk Voice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-team-rooms Cross-session team rooms: shared message bus, task board and timeline
dsh-test-drive Isolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktick TickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translate Vendor parameter translation and deterministic JSON repair for DeepSeek Harness.

License

Apache License 2.0 © 2026 dsh-click contributors

从 DSH Desktop 市场安装

所有 PerryLink 插件均可在 DSH Desktop 内置市场中浏览:市场 → 来源 → 添加来源 → 粘贴 https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → 选中。安装仍需通过市场的 npm 身份校验与你的确认。

内容来自项目 README(GitHub)↗

评论存放在 GitHub Discussions。用 GitHub 账号登录后可发表评论或点表情。