beijingwahw/dsh-companion-enterprise

DeepSeek Companion Enterprise — DeepSeek Harness 企业级伴侣插件:安全审计与DLP、团队协作与知识管理、任务编排与断点续跑、多模型竞技场、执行轨迹分析、Prompt工程工作台。

Project Overview项目介绍

DeepSeek Companion Enterprise is a native plugin built exclusively for DeepSeek Harness (DSH), targeted at enterprise development teams that need AI-driven development workflows with security and compliance guarantees. It follows DSH's plugin packaging specification and can be installed directly via the DSH command line interface with a single command: dsh plugin add beijingwahw/dsh-companion-enterprise --profile web. After installation, it automatically loads into DSH's web interface panel, and all user data is stored locally in the DSH sandbox with no telemetry or data reporting to external servers.

This plugin ships with more than 10 individually toggleable feature modules that cover all key stages of enterprise AI development with DSH. Key modules include security auditing, DLP data leakage prevention, prompt injection detection, team experience management, task orchestration, adaptive model routing, prompt optimization, and multi-format conversation export. Enterprise teams can use this plugin to manage sensitive information risks, accumulate team development knowledge, and optimize the cost and efficiency of LLM calls, while enabling multi-round review collaboration between team members.

To run this plugin, you need to have DeepSeek Harness version 0.1.0 or higher installed, along with Node.js version 22.19 or newer and the pnpm package manager. Regular end users can install it via the DSH CLI in one step, while developers or offline users can clone the source code, build it locally, then install it via dsh plugin add . --profile web. It is released under the permissive MIT open source license, and only accesses explicitly allowed external network endpoints for model calls and dynamic pricing.

这是一款专为 DeepSeek Harness 开发的原生企业级插件,为企业开发团队提供覆盖安全合规、团队协作、任务编排与开发者效率的完整能力矩阵。插件符合 DSH 插件打包规范,可通过 DSH CLI 一键安装,安装后自动加载到 DSH 的 Web 面板中。所有用户数据仅存储在本地 DSH 沙箱,无用户行为追踪、遥测或数据上报,满足企业隐私合规要求。

插件包含十余个可独立开关的功能模块,覆盖安全审计、DLP 数据防泄漏、提示注入检测、团队经验沉淀、任务编排、多模型路由、Prompt 优化与对话导出等场景。企业开发团队可通过该插件统一管控 AI 开发流程中的敏感信息泄露风险,沉淀团队开发经验,优化模型调用成本与效率。团队成员还可基于插件完成多轮评审协作,统一团队配置与策略。

运行该插件要求预先安装版本不低于 0.1.0 的 DeepSeek Harness,同时需要 Node.js 22.19 以上版本以及 pnpm 包管理器。普通用户可通过 DSH CLI 执行一键安装命令,开发者也可从源码构建后完成本地安装。插件采用 MIT 许可证开源,允许自由使用修改,仅会访问合规的外部网络地址。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin add beijingwahw/dsh-companion-enterprise --profile web

把 beijingwahw/dsh-companion-enterprise 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DeepSeek Companion Enterprise

DeepSeek Harness 企业级伴侣插件 —— 面向企业开发团队的 AI 工程效率与安全平台。

License: MIT dsh-plugin DeepSeek Harness

English | 中文

DeepSeek Companion Enterprise 是构建于 DeepSeek Harness 之上的企业级伴侣插件,为开发团队提供从安全合规到协作效率的完整能力矩阵。所有数据仅存于本地 Harness 沙箱,零遥测、零追踪。


核心能力

安全与合规

  • 安全审计:全量操作审计日志,支持导出与检索
  • DLP 数据防泄漏:内置规则引擎自动识别 API Key、手机号、邮箱、密码等敏感信息,支持自定义规则与开关
  • 提示注入检测:六类攻击语义模式识别(指令覆写/角色越狱/系统提示词窃取/工具劫持/分隔符混淆/编码逃逸),风险评分三档判定,严格模式自动拦截
  • 密钥管理:命名密钥库、作用域控制、轮换提醒、泄露检测

团队协作与知识管理

  • 团队配置:成员偏好、默认策略、配置导入/导出/差异对比
  • 知识快照:会话快照存档与检索
  • 经验库:团队经验沉淀、笔记、智能推荐
  • 经验自动蒸馏:从会话轨迹自动挖矿"错误→修复"经验卡——信号挖矿、元提示蒸馏、语义去重合并、证据链回溯,复发度加权排序 + 人工晋升把关闭环
  • 评审流:多轮评审、评论、决策、合并

任务编排与自动化

  • 任务编排器:多步 Pipeline 定义、条件分支、超时重试、依赖管理
  • 自愈执行:错误分类(不可重试/限流/超时/瞬态)、指数退避全抖动、三态模型断路器(熔断冷却 + 半开探针)、主模型失败自动降级备跑
  • 定时任务:Cron 调度、空闲时段执行、断点续跑
  • 任务队列:运行中/排队/完成/失败状态追踪

开发者效率

  • 多模型竞技场:多模型并行对比、历史评测记录
  • 模型漂移监控:确定性金丝雀探针组 + 三维分布距离(成功率 z 检验 / 时延 KS 检验 / 输出风格 Jaccard),检测厂商静默更新导致的行为漂移
  • 执行轨迹分析:耗时/Token/异常检测、最慢步骤定位
  • SPC 统计过程控制:EWMA 控制图 + Western Electric 规则监控轨迹指标漂移,区分缓慢漂移与突发波动
  • Prompt 工程工作台:版本管理、模板库、变量插值
  • Prompt 自动优化:元提示生成候选变体 + 配对符号检验(McNemar 精确法)判定统计显著性,仅显著胜者晋升版本库
  • API 成本治理:实时计价(动态抓取官方定价页)、预算控制、用量报表
  • 自适应模型路由:滑动窗口 UCB1 多臂赌博机从调用结果中学习最优模型(成功率/成本/时延加权奖励),探索-利用平衡 + 非平稳漂移自动遗忘

基础能力

  • 对话智能导出:Markdown / PDF / JSON / 交互式 HTML,单会话与批量 ZIP
  • 交互式 HTML 导出:单文件自包含交互档案——全文搜索、角色筛选、长轮折叠、零外部依赖(无 CDN/无框架),JSON 安全嵌入免疫 XSS
  • 上下文交接摘要:自动生成会话交接摘要,武装给下一个对话
  • 结构化分级交接:四级信息分层(锚定/活动/参考/归档)+ 锚定约束强制继承守门(静默丢失在结构上不可能)+ 世系链溯源(传承 N 代告警)
  • 全局对话检索:全文检索 + 标签管理
  • 语义邻域检索:字符 shingle 邻域 + 伪相关反馈查询扩展 + 多源 RRF 融合,无向量库即可语义召回;相似会话(more-like-this)

安装

前置要求

  • DeepSeek Harness >= 0.1.0
  • Node.js ^22.19 || >=24
  • pnpm(npm install -g pnpm)

一键安装

dsh plugin add beijingwahw/dsh-companion-enterprise --profile web

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-context-lens 下一个 Next dsh-coding-plans →