263311487-ux/dsh-verify 预览 preview

263311487-ux/dsh-verify

代理构建Web应用的质量关卡。基于真实浏览器的验收检查——支持CLI、MCP(Claude Code / Cursor / Copilot)、GitHub Action。代理自测通过,真实浏览器方证真伪。

Project Overview项目介绍

dsh-verify, also known as Witness, is a quality gate tool for agent-built web applications, designed to run real browser checks after an AI agent claims a web build is done. It works across multiple AI agent platforms, including DeepSeek Harness, Claude Code, Cursor, Copilot, and Codex, and can integrate with any continuous integration (CI) workflow. Users write checks that match what a human would verify in a browser, and the tool returns pass/fail verdicts alongside screenshot receipts for any detected failures. It can be used three ways: as an MCP server for in-session agent verification, as a standalone CLI for local or CI checks, and as a reusable GitHub Action for automatic checks on every push.

This tool is built for developers who use AI agents to build web applications, addressing the common gap where AI agents grade their own work and miss issues that only appear in a real user’s browser. For example, after an AI agent finishes building a web page and claims all requirements are met, developers or the agent itself can use dsh-verify to run objective checks. It catches issues like missing CSS rules, broken interactive toggles, network errors, and missing text that agent self-reviews regularly miss, providing an independent second check. To get started with a local test, users can clone the repository, install dependencies, run the demo buggy and fixed builds to see how the tool catches issues.

dsh-verify is released under the permissive MIT open source license, so it is free to use, modify, and distribute without any cost or restriction. It requires Node.js and npm to run, and users need to install the Chromium browser dependency for Playwright after installing the npm package. First-time users can test the tool by cloning the GitHub repository, running npm install, then npx playwright install chromium, followed by npm run demo:fixed and npm run demo:buggy to see passing and failing results. The project verifies itself on every push via CI, so the main branch is always stable and working as expected.

dsh-verify(产品名为Witness)是一款针对AI代理构建的Web应用的端到端验证工具,核心能力是在真实浏览器中运行用户指定的检查,输出PASS/FAIL结果并附带截图凭证,不需要LLM来判断结果。它支持多个AI代理平台,包括DeepSeek Harness、Claude Code、Cursor、Copilot和Codex,也可以直接集成到任何CI流程中使用。

这款工具面向使用AI代理开发Web应用的开发者,解决了AI代理自我验证时无法发现实际浏览器运行问题的痛点。典型工作流程是:AI代理完成开发后声称任务已完成,用户或AI代理通过dsh-verify指定需要检查的交互、样式等项,工具在真实浏览器中执行点击、输入、检查文本等操作,最终给出客观的PASS/FAIL验证结果。

dsh-verify采用MIT许可协议,完全免费开源,使用前需要预先安装Node.js和npm,还需要安装Playwright的Chromium浏览器依赖。首次使用可以克隆GitHub仓库、安装依赖后运行官方提供的示例验证功能,也可以直接通过npx调用CLI、配置为MCP服务器或GitHub Action,没有额外的使用限制或付费要求。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:263311487-ux/dsh-verify

把 263311487-ux/dsh-verify 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-verify

中文 | English

Witness — The browser is the judge. The quality gate for agent-built web apps. Agents say done; the browser proves it. (Witness is the product name; dsh-verify is the package name — same thing.)

ci npm MCP server awesome-dsh-plugin GitHub stars self-acceptance

If Witness catches something for you, ⭐ star the repo — it's how this project stays alive.

You asked an AI to build a web app. It said "done." Does it actually work?

dsh-verify opens a real browser and checks — so you never have to take the agent's word for it.

dsh-verify — Agents say done. The browser proves it.

dsh-verify in action

The quality gate for agent-built web apps. Works with any agent — DeepSeek Harness (dsh), Claude Code, Cursor, Copilot, Codex — and with any CI. You write what a human would check in a browser; a real browser executes it and returns a PASS/FAIL verdict with receipts (screenshots + diff images).

No LLM judges the outcome. The browser is the judge.

Same task, same AI, two builds — only a real browser tells the difference

Same task. Same AI. Two builds. One missing CSS rule — the agent's self-review passed, a real browser caught it.


Why this exists

We ran a 4-agent web team (spec writer → frontend dev → QA → reviewer). Their own review said:

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-harness-ally 下一个 Next dsh-cyber-pet →