安装
在 DeepSeek Harness 里通过 dsh-market 安装
dsh plugin --profile web add dshmarket
或使用命令行
dsh plugin --profile web add @perrylink/dsh-plugin-kit
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络。请先审阅源码,并尽量锁定 commit(github:owner/repo#sha)。
README
- 1024 商店渠道:先
npm i -g dsh1024,再dsh1024 plugin --profile web add @perrylink/dsh-plugin-kit(计入 deepseek1024.com 安装排行)。
English | 简体中文 | Español | Português | हिन्दी
面向 PerryLink DSH 插件仓库的共享零运行时依赖工具包。逐项审计发现 33 个插件中有 20+ 各自手写同样的 Provider seam、并重复相同的 sanitize/pricing/裁决形状,因此本包把 这一切——可插拔 Provider seam、fail-closed 审批门与自适应会话事件门、机械校验脚本、共享 的 sanitize/pricing/judge 纯函数模块——抽取进一个 ESM + TypeScript 包。
兼容性
- DSH harness:本包运行时零
@deepseek-ai/*import。@deepseek-ai/cordis(^4.0.4)、@deepseek-ai/schemastery(^3.18.4)与各@deepseek-ai/dsh-*包均声明为可选 peer 依赖,区间与 PerryLink 各插件仓一致(>=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0),仅用于 类型互通。已于 2026-09-11 针对dsh-v0.1.7-alpha.1master checkout 核验(全量门禁链 + profile 安装冒烟测试),并已于 2026-09-24 针对dsh-v0.1.7-rc.2checkout 复核。 - Node:
^22.19.0 || >=24.0.0,仅 ESM。 - 线级兼容:函数名与形状对齐
dsh-mask(sanitize)、dsh-budget(pricing)、dsh-auto-review(judge 与fallbackPolicy词汇),迁移是机械替换。
你能得到什么
- 零运行时依赖——纯核心(
seam/gates/shared)浏览器侧可用。 - ESM + 严格 TypeScript——每个模块带 JSDoc 契约;开启
strict、noUncheckedIndexedAccess、exactOptionalPropertyTypes。 - fail-closed 与自适应门——审批永不默认放行;会话事件追加在拒绝未知事件类型的 宿主上优雅降级。
- 新插件骨架——
template/含cordis.yml、三角色src/index.ts(Service Definition / Provider / Consumer)、最小测试与共享 Renovate 预设。
快速开始
npm 通道:
pnpm add @perrylink/dsh-plugin-kit
git 通道(prepare 脚本只用生产依赖构建 lib/):
pnpm add github:PerryLink/dsh-plugin-kit
一步替换手写注册表:
import { ProviderRegistry } from '@perrylink/dsh-plugin-kit/seam'
const registry = new ProviderRegistry<Detector>({
default: { name: 'regex', impl: new RegexDetector() },
})
ctx.effect(() => registry.register('ner', new NerDetector()))
const active = registry.use('ner') ?? registry.use()
安装与卸载
安装即 pnpm add(见快速开始)。本包还带一层有意留空的 dsh.bundle.patch(cordis.patch.yml),因此当某个 profile 想把本 kit 作为包挂载时,它也能走 harness 的 bundle 通道:
# npm 渠道(正式发布版)
dsh plugin --profile web add @perrylink/dsh-plugin-kit
# git 渠道(最新 master)
dsh plugin --profile web add "github:PerryLink/dsh-plugin-kit#master"
移除:
pnpm remove @perrylink/dsh-plugin-kit
不注册任何全局状态:卸载就是安装的精确逆操作。
配置
无运行时配置:门与辅助函数均为纯函数。唯一配置面是 cordis.patch.yml——随包发布的
bundle-patch 层,供 harness profile 组合使用;它不挂载插件行(本包是库),并说明消费
插件如何添加自己的行。
工具与表面
| 子路径 | 用途 |
|---|---|
seam |
ProviderRegistry<T>——可逆、重名响亮失败的具名 Provider 注册表。 |
gates |
applyFailClosed;makeEventGate / maybeAppendSessionEvent / probeIgnorableAppend。 |
shared |
sanitize(Stripper、redactText、redactMapping、sanitizeText、sanitizeUrl)、pricing(BUILTIN_PRICES、estimateUsageCost、tokenCarbon、latencyStats、formatMoney、formatTokens)、judge(parseVerdict、VERDICT_SCHEMA、riskExceeds)。 |
verify |
机械 CI 门(verify-license、verify-readme-languages、verify-seam),返回 VerifyReport 且 CLI 以非零码失败:node lib/verify/cli.js all . |
template/ |
新插件骨架(cordis.yml、三角色插件、测试、README、renovate.json5)。 |
| 根 barrel | 重导出以上全部。 |
权限与数据
本包自身不做任何 I/O、网络访问或子进程启动。Stripper 的占位符→原文映射只存内存,
stats()/redactMapping() 绝不输出明文;持久化映射的消费方自行承担该决策及其存储权限。
安全边界
sanitize/redact*是展示卫生,不是安全边界:它们降低日志与结果中的泄露, 不做认证或授权。- 审批门默认 fail closed(
rejected);唯一放行路径是显式allow-once选择。 - 宿主拒绝的会话事件追加会被跳过,绝不重试到破坏会话 resume 的程度。
- 漏洞请走 GitHub Security Advisories——见
SECURITY.md。
已知限制
Session.append第三参为SurfaceIntent的宿主(0.1.2-rc.1)会对 ignorable 信封探测抛validateNext;门退化为跳过未知类型,即该类宿主上审计事件被丢弃 (fail closed)而非写入。- 0.1.2-rc.1(2026-09-02 已适配):会话信封保留 ignorable 字段但仅用于存量日志读取兼容——Session.append 仍无法盖章,门控行为不变。
- 本包无浏览器 UI 半:它是被其他插件 Host(及可选 Client)半消费的库。
开发
pnpm install
pnpm run typecheck # tsc --noEmit
pnpm run typecheck:ci # CI 面:tsc -p tsconfig.ci.json --noEmit
pnpm test # vitest 单测
pnpm run build # 产出 lib/ 与声明(prepare 也会执行)
pnpm run verify:self-contained
pnpm run verify:artifacts
主题
本仓库同时是 33 个插件仓的维护枢纽:scripts/sync-peer-range.mjs 一条命令重钉所有仓的
共享 peer 区间,renovate/default.json5 是各仓统一继承的 Renovate 预设,
.github/workflows/npm-publish.yml 是可复用的 tag 触发发布工作流(只需一个
NPM_TOKEN secret),data/repos.json 是门户消费的生态注册表。见
docs/ecosystem-tooling.md。
关键词:dsh、dsh-plugin、deepseek-harness、deepseek、cordis、perrylink、provider、 seam、approval、sanitize、pricing、judge。
贡献者
由 PerryLink 维护,DSH 插件生态共建。
许可证
Apache-2.0——见 LICENSE。
PerryLink DSH Plugin Family
This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:
| Plugin | One-liner |
|---|---|
| dsh-auto-review | Second-model auto-review on the approval chain, fail-closed by default |
| dsh-autotier | Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command |
| dsh-background-agents | Durable background child agents with a Web UI sidebar, messaging and interrupt |
| dsh-budget | Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel. |
| dsh-catalog | DSH Desktop Market standard catalog source for the PerryLink family |
| dsh-cert-mcp | Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence |
| dsh-checkpoint-rewind | Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore |
| dsh-claude-move | Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH |
| dsh-click | Cross-platform native desktop control for DeepSeek Harness — Windows first. |
| dsh-composer-history | Terminal-style input history for the web composer: arrows, Ctrl+R search |
| dsh-data-quality | Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here) |
| dsh-defend | Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness. |
| dsh-doublecheck | Engineering-discipline guard: requirements grill, test gates, adversary review |
| dsh-draw | Unified static-image generation routing for DeepSeek Harness. |
| dsh-fast | Read-only performance diagnostics for DeepSeek Harness. |
| dsh-fund-research | Deterministic research reports for Chinese public mutual funds |
| dsh-github | GitHub PR/issues integration for DSH, every write gated by approval |
| dsh-industry-research | Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble |
| dsh-laya | Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools |
| dsh-library | Local document knowledge base for DeepSeek Harness. |
| dsh-local-ai | Local-model (Ollama) integration for DeepSeek Harness. |
| dsh-lsp-actions | LSP diagnostics, formatting, completion, code actions and rename over language servers |
| dsh-mask | PII masking middleware: anonymize at the model boundary, restore at the display layer |
| dsh-mcp-panel | Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors |
| dsh-memento | Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool |
| dsh-observe | OpenTelemetry and Langfuse observability exporter for DeepSeek Harness. |
| dsh-output-styles | Claude Code outputStyles-equivalent runtime style switching |
| dsh-permission-rules | Claude Code-style declarative allow/deny/ask permission rules with audit |
| dsh-plugin-certification | Community certification registry with repro-checkable grades and badges |
| dsh-plugin-doctor | Zero-dependency static + sandbox smoke detector for DSH plugins |
| dsh-plugin-guide | Plugin-development knowledge base as an on-demand agent skill |
| dsh-plugin-kit | Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins |
| dsh-plugin-upgrade | One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card |
| dsh-plugin-upgrade-015 | Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner |
| dsh-reach | Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console |
| dsh-research-report | Verifiable research-report engine: content-addressed evidence ledger and sealed versions |
| dsh-score | Multi-dimensional quality scoring for DeepSeek Harness plugins. |
| dsh-session-pin | Pin sessions in the Web sidebar with durable ordering |
| dsh-session-sync | Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store. |
| dsh-skill-pack-security | Security-audit skill pack: secret scan, dependency and supply-chain review |
| dsh-talk | Voice-first session loop for DeepSeek Harness: talk to it, hear it answer. |
| dsh-team-rooms | Cross-session team rooms: shared message bus, task board and timeline |
| dsh-test-drive | Isolated install-and-smoke test drives for DeepSeek Harness plugins. |
| dsh-ticktick | TickTick/Dida365 task bridge: session-header panel + 11 tools |
| dsh-translate | Vendor parameter translation and deterministic JSON repair for DeepSeek Harness. |
评论
评论存放在 GitHub Discussions。用 GitHub 账号登录后可发表评论或点表情。