aiworkskills/deepseek-harness-server
把原版 DeepSeek Harness 作为受管智能体 模块接入既有业务系统的树外扩展。不修改 Harness 源码,用 OAuth 委托身份、每用户独立 Runtime 和业务 API 对象级授权实现多用户共用。
catalog descriptioncatalog 简介 / catalog description:一个可以接入应用系统的deepseek harness插件,让原有的应用系统快速接入智能体能力
Project Overview项目介绍
This is a third-party extension built exclusively for DeepSeek Harness, designed to let developers integrate the official DeepSeek Harness as a managed agent module into existing business systems without modifying the original Harness source code. It enables multi-tenant, multi-user usage via OAuth identity delegation, per-user isolated runtime environments, and object-level access control for business APIs. The repository is split into 7 core npm packages covering integration logic, runtime gateway, user preferences, deliverable hosting, page embedding, custom branding, plus pre-built configuration with an enterprise profile and three agent presets for different roles.
The core problem this project solves is permission alignment when embedding an agent into an existing business system. It guarantees that the agent only has exactly the same business access permissions as the currently logged-in user, with all permission checks enforced invisibly to the end user. All identity data is stored in a signed runtime lease file written by the runtime manager, and every tool call exchanges the lease for a short-lived 120-second downscoped business token that follows the same scope policy as the user’s role, with final object-level authorization handled by the business system itself.
The project is developed for Node.js, requires Node.js 22.19 or newer and pnpm 11 for package management, and is released under the open source MIT license. You can run a full local validation with just two commands, and you do not need to prepare Harness source code, model credentials, or external network access to run the end-to-end test suite. When installing for production, you must pin DSH dependency versions exactly, because official DSH is currently pre-release, and the npm latest tag does not meet the project’s peer dependency requirements.
这是一个面向 DeepSeek Harness 的第三方扩展,作用是将原版 DeepSeek Harness 作为受管智能体模块接入现有业务系统的树外扩展,不需要修改 Harness 源码,通过 OAuth 委托身份、每用户独立 Runtime 和业务 API 对象级授权实现多用户共用。项目共分为7个核心包,覆盖集成、网关、偏好设置、产物管理、页面嵌入、品牌定制等功能,另外还包含部署方可用的企业配置文件与三套 Agent 预设。
本项目核心解决业务系统嵌入智能体时的权限对齐问题,目标是确保智能体的业务访问权限恰好等于当前登录用户本身的权限,整个权限校验过程对用户完全透明。实现上,所有身份信息来自 Runtime Manager 写入的租约文件,每次工具调用通过租约换取有效期120秒的降权业务 Token,申请权限从统一策略表派生,最终对象级授权由业务系统自身执行。
项目基于 Node.js 开发,要求 Node.js 版本不低于 22.19,使用 pnpm 11 做包管理,采用 MIT 许可开源。本地测试仅需执行两条命令即可完成全流程验证,不需要提前准备 Harness 源码、模型凭据或额外网络出口。安装时需要注意精确锁定 DSH 依赖版本,当前官方 DSH 仍为预发布版本,npm 的 latest 标签不满足依赖要求。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:deepseek-harness-server(aiworkskills/deepseek-harness-server)
仓库:https://github.com/aiworkskills/deepseek-harness-server
本站详情页:https://www.yhbd.top/plugins/aiworkskills-deepseek-harness-server/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-10-03 · 主语言 TypeScript · 未检测到 DSH 插件清单
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
- No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:aiworkskills/deepseek-harness-server
把 aiworkskills/deepseek-harness-server 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DeepSeek Harness Server
把原版 DeepSeek Harness 作为受管智能体 模块接入既有业务系统的树外扩展。不修改 Harness 源码,用 OAuth 委托身份、每用户独立 Runtime 和业务 API 对象级授权实现多用户共用。
一句话概括:用户在自己的业务系统里使用 Agent,Agent 用用户自己的身份和权限访问业务 数据。
本项目由 aiworkskills 维护,是 DeepSeek Harness 的 第三方扩展,与 DeepSeek 官方无关,也未获得其背书。
七个包
| 包 | 加载平面 | 作用 |
|---|---|---|
@dshserver/dsh-integration |
DSH Runtime | OAuth 委托的业务工具与执行前授权守卫 |
@dshserver/runtime-gateway |
宿主应用 | 每用户独立 Runtime 生命周期与 DSH 管理接口锁定 |
@dshserver/gateway-server |
宿主应用 | 把上面那层跑成服务:路径匹配、认证与策略顺序、RPC 拒绝、流量代理 |
@dshserver/dsh-preferences |
浏览器 | 个人偏好、连接器设置卡片、业务页面话术送入 |
@dshserver/dsh-deliverables |
Runtime + 浏览器 | 托管部署里,对话中的产物点开就在右侧面板里看 |
@dshserver/dsh-embed-chrome |
Runtime + 浏览器 | DSH 嵌在自己页面里时,由那个页面决定品牌、大标题与工作区切换 |
@dshserver/dsh-brand |
Runtime + 浏览器 | 独立打开时,部署方在 Profile 里填自己的标记、文字商标与空会话标题 |
外加 config/:部署方维护的企业 Profile 与三套 Agent Preset(员工、管理者、
审计员)。
60 秒看到它在做什么
只需要 Node.js >=22.19 和 pnpm 11,不需要 Harness 源码、模型凭据或任何网络出口:
pnpm install --frozen-lockfile && pnpm example
这条命令会在本机拉起一个假的 Token Broker 和一个假的业务 API,写入一份真实格式的 Runtime 租约,然后用真插件跑五个场景:授权读取、缺少 Scope 被守卫拒绝、租户写开关关闭、 写入携带幂等键、租约过期后失败关闭。输出是逐条的 PASS/FAIL。
它证明的是本仓库负责的那段边界;完整产品形态(登录、嵌入 UI、业务系统)见 https://dshserver.cn。
它解决什么问题
在业务系统里嵌一个智能体,难的从来不是接模型,而是让智能体的权限恰好等于当前用户的 权限,而且这件事要在用户看不见的地方被强制执行。本仓库的做法:
- 模型参数永远不含
userId、tenantId、角色或 Access Token。身份来自 Runtime Manager 写入的0600租约文件。 - 每次工具调用用租约换一张有效期 120 秒的降权业务 Token(RFC 8693 Token Exchange)。
- 申请的 Scope 恒等于守卫检查过的 Scope——两者从同一张策略表派生,不可能不一致。
- 最终的对象级授权由业务 Resource Server 执行,插件不直接连业务数据库。
- 平台管理员可以在不改 OAuth 的前提下一键停掉所有写操作。
文档
| 我想… | 文档 |
|---|---|
| 接入自己的业务系统 | 集成指南 |
| 理解 OAuth 委托、Runtime 隔离与 Token Exchange | 核心概念 |
| 查配置项与默认值 | 配置参考 |
| 查工具、接口与错误码 | 工具与 API 参考 |
| 了解模块划分与扩展检查表 | 插件架构 |
| 做安全评审 | 安全模型 |
| 确认支持的 DSH 版本 | 兼容性 |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
tt-a1i/archify
loopx-project/loopx
ZSeven-W/openpencil
omdsh-dev/DSH-better-sidebar
NanmiCoder/dsh-agent-teams
LiPu-jpg/Openwrite