anweat/dsh-browser
DeepSeek Harness 的自包含浏览器运行时插件——将 Playwright(chromium)和 OpenCLI 打包为插件本地依赖,提供浏览器服务和交互式浏览器工具。
Project Overview项目介绍
dsh-browser is a native browser runtime plugin built exclusively for DeepSeek Harness (DSH). It bundles Playwright, optional Patchright Chromium driver, and OpenCLI as its own npm dependencies, prioritizing local plugin dependencies and falling back to globally installed versions if they are not available locally. To install the plugin, run dsh plugin --profile web add @anweat/dsh-browser from the command line, or install it from a local directory or tarball, then restart the web profile to complete the setup. It exposes a browser service and a set of interactive browser tools that other DSH plugins like dsh-web-search-pro can inject and use.
After installation and restarting the DSH web profile, users can have the LLM first call browser_status to check the current runtime status before selecting tools based on the task at hand. The plugin supports a wide range of use cases, including public web page reading, form interaction, SPA condition waiting, file uploads, troubleshooting, authenticated site access, controlled crawling, and OpenCLI-powered social platform search. It offers different automation modes that control approval requirements for operations, starting with standard mode by default that requires one-time approval for all write operations. This plugin is intended for DSH users that need to enable automated browser interactions for web search and data extraction workflows.
This plugin is released under the open source MIT license. Chromium binaries are always reused from the system’s shared Playwright cache and are not bundled with the plugin, so if no cache exists users can run the browser_install command to download it in one click. Patchright, the anti-detection Chromium driver, is only enabled when explicitly configured in the plugin settings, and Camoufox is not currently integrated due to version compatibility issues. All browser operations must comply with the target website’s terms of service, and users upgrading from older versions must upgrade dsh-web-search-pro at the same time then fully restart the DSH profile for changes to take effect.
这是一个专为 DeepSeek Harness (DSH) 开发的原生浏览器运行时插件,它将 Playwright/Patchright(可选 Chromium 驱动)和 OpenCLI 作为自身 npm 依赖打包,优先使用插件本地依赖,缺失时回退复用全局安装版本。它对外提供 browser 服务和一组交互式浏览器工具,供 dsh-web-search-pro 注入依赖使用,让该插件的浏览器和 OpenCLI 后端不再依赖全局 CLI。
安装完成重启 DSH 后,用户可让模型先调用 browser_status 检查运行状态,再根据具体任务选择对应工具。插件提供网页打开、内容读取、截图、交互、条件等待、脚本执行、站点爬取等多种工具,覆盖公开网页读取、表单交互、SPA 等待、文件上传、故障排查等多种场景,适合需要让 DSH 模型自动化操作浏览器的开发者。
插件遵循 MIT 许可,Chromium 内核始终复用系统共享缓存,不内置下载,缺失时可通过 browser_install 一键补全。补丁驱动仅在配置开启后启用,Camoufox 暂未集成,所有操作需要用户自行遵守目标网站规则,插件不承担合规责任。升级时需同步升级 dsh-web-search-pro,升级后需完整重启 DSH 配置文件才能生效。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-browser(anweat/dsh-browser)
仓库:https://github.com/anweat/dsh-browser
本站详情页:https://www.yhbd.top/plugins/anweat-dsh-browser/
本站登记:类型 bundle · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 27 · 最近提交 2026-10-03 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 27 stars - an early-stage project星标 27,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @anweat/dsh-browser@0.2.0
把 anweat/dsh-browser 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-browser
本地整合候选的修复、工具清单与安全边界见 AUDIT.md。allowedDomains 只限制认证状态装载,不是网络防火墙或 Agent 隔离边界。
自包含的浏览器运行时插件 for DeepSeek Harness(DSH)。
把 Playwright / Patchright(可选 Chromium 驱动) 与 OpenCLI 作为插件自身的 npm 依赖打包(优先插件本地,缺省回退全局复用),对外提供一个 browser 服务 + 一组交互式浏览器工具。dsh-web-search-pro 通过 inject: ['browser'] 注入该服务,驱动它的浏览器 / OpenCLI 后端——不再依赖全局 CLI。
兼容与发布通道
| 插件发布通道 | DSH 基线 | 兼容承诺 |
|---|---|---|
0.1.12 及更早的维护版本 |
dsh-v0.1.1-rc.2 至 dsh-v0.1.2-rc.1 |
旧基线;不与新插件混装 |
0.1.15 |
dsh-v0.1.7-rc.2 |
精确锁定该宿主版本;组合安装、真实 Web profile 与设置持久化已验证 |
0.1.17 |
dsh-v0.1.7-rc.2 ~ dsh-v0.2.0-rc.2 |
peer 收口为「实测过的两条线」(上界 <0.2.1-0);在 0.2.0-rc.2 上完成 typecheck、构建、52 项测试与真实挂载验证;补充浏览器缓存路径配置说明,并新增 peer 双解析模式检查 |
0.2.0-rc.1(预发布,历史记录) |
dsh-v0.1.7-rc.2 ~ dsh-v0.2.0-rc.2 |
破坏性变更:30 个 browser_* 工具改为 browser_index / browser_call 两个入口加动作目录(常驻约 325 token,原约 8.8k);随包提供 dsh-browser skill;recipe v2、资产版本与激活保护、结构化观察、探索记录生成草稿、提示文本可配置。并入按 session 隔离浏览器状态(#36)与 dialog 竞态修复(#30)。在 0.2.0-rc.2 上完成 325 项测试、64 项真实浏览器 e2e 与真实 Web profile 验证 |
0.2.0 |
dsh-v0.2.0-rc.2 |
第一个面向 DSH 桌面版 0.2.0 线的正式版,也是后续开发的基底。只支持 dsh-v0.2.0-rc.2 这一条线(peer >=0.2.0-rc.2 <0.2.1-0):去掉为更旧宿主保留的兼容分支(settings.register 的 live scope 回退等),并去掉对 settings 服务的必需依赖(只声明 inject: ['tools'],没有 Settings 服务的组合里也能启动);不改工具、动作、schema、文本与审批规则。在 0.2.0-rc.2 上完成 327 项测试、64 项真实浏览器 e2e 与 peer 双解析模式检查。旧宿主(0.1.7 线,dsh-v0.1.7-rc.2)继续使用 0.1.17 |
0.1.17 把 DSH 运行时依赖由精确锁定改为范围声明(^0.1.7-rc.2 || >=0.2.0-rc.1 <0.2.1-0),
使同一份包可装在 0.1.7-rc.2 与 0.2.0-rc.2 两代宿主上。0.2.0-rc.1 起的新功能(动作体系、skill、recipe v2、
资产版本、提示文本配置等)只在 0.2.0-rc.2 上验证过,没有在 0.1.7-rc.2 上跑过,所以 0.2.0 把范围收成只覆盖
0.2.0-rc.2 这条线:>=0.2.0-rc.2 <0.2.1-0,正式版 0.2.0 起即采用这个范围。0.1.17 的范围不变,旧宿主继续用它。
这个写法同时满足两种解析,缺一不可:
- 宿主的组装期校验用的是
semver.satisfies(host, range, { includePrerelease: true }),所以「单范围能不能过宿主」不是关键。 真正决定装机成败的是 npm/pnpm 的默认 semver:预发布版本只有在某个比较符自带同号(同 major.minor.patch)预发布时才被判为满足。 于是>=0.1.7-rc.2 <0.2.1-0这种写法过得了宿主校验,却会让dsh plugin add报 ERESOLVE(下界 tuple 是 0.1.7,接不住 0.2.0-rc.2);>=0.2.0-rc.2这个比较符自带0.2.0的预发布,是承重的,必须保留。 - 上界是
<0.2.1-0而不是<0.2.1:后者放行0.2.1-alpha.1这类 0.2.1 的预发布。收口后,若 0.2.1 真出现破坏, 会在组装期直接报is incompatible with dsh 0.2.1并点名,而不是拖到用户机器上变成运行期怪错 (0.1.5 → 0.1.7曾一次性打断所有按0.1.5-alpha.1构建的插件)。 - 范围只表示「测过哪些」,不等于承诺不破坏;真正的防线是每换一个 DSH 版本重跑一遍这套验证。
pnpm run test:peers(已并入pnpm verify)用两种解析模式逐个断言受管 peer:0.2.0-rc.2必须通过,0.1.7-rc.2、0.2.0-rc.1、0.2.1-alpha.1必须被拒绝;并自带--selftest已知行为自校验。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Tencent/BrowserSkill
YaoApp/yao
anbeime/skill
Jesseovo/last30days-skill-cn
bowenliang123/dsh-context
platonai/Browser4
liustack/modsearch