c3ll256/dsh-toy 预览 preview

c3ll256/dsh-toy

Plugin插件 Native原生 ⭐ 67 BSD-3-Clause Approval & Security审批与安全Dev Workflow开发与代码工作流

玩具控制协议(DSH)

Project Overview项目介绍

dsh-toy is a native DeepSeek Harness plugin that lets users connect compatible toys to the DSH agent. It automatically selects the right connection method based on the user-provided brand and model, so users do not need to manually start backend services like Intiface or understand underlying protocols. To install the plugin, users need Node.js 22.19 or newer and pnpm on their system PATH, then run npx -y @deepseek-ai/dsh plugin --profile web add github:c3ll256/dsh-toy to add it to their DSH profile. On macOS, raw BLE discovery additionally requires the Swift compiler from Xcode Command Line Tools.

For users who know their toy’s brand and model, the workflow runs toy_connect → toy_scan → toy_list → toy_control → toy_stop → toy_disconnect automatically. For users who do not know the brand or model, the plugin triggers an automatic discovery process that starts with raw BLE scanning on macOS before falling back to Intiface. The plugin includes multiple guardrails to keep users safe: sharing tokens are never exposed to the model, output stops automatically after 30 seconds by default, and intensity and duration limits are enforced before any commands are sent. It is intended only for use with hardware that the user owns or has explicit authorization to control.

This plugin is released under the open-source BSD-3-Clause license, and it draws on protocol documentation from the Chemtrails and Buttplug projects. It has several documented limitations: raw BLE discovery is only available on macOS, only the RoomFun RF_CANNON_PT3 model has a verified built-in mapping, and Buttplug connections only support scalar vibration controls currently. MonsterParty connections rely on vendor protocols that may change over time, requiring plugin updates to maintain compatibility. Users should keep sharing tokens out of Git, logs, and conversations to avoid unauthorized access, and can troubleshoot common issues by following steps outlined in the project README.

dsh-toy 是专为 DeepSeek Harness 开发的原生插件,用于将各类情趣玩具连接到 DSH 智能代理。插件会自动根据用户提供的品牌和型号选择合适的连接方式,无需用户手动选择底层协议或启动相关后端服务。对于未知品牌型号的设备,macOS 平台会优先通过 CoreBluetooth 进行只读蓝牙广播发现,之后再自动回退到其他可用连接方式,支持 Buttplug/Intiface、MonsterParty 等多种后端协议。

用户只需告知 DSH 代理玩具的品牌和型号,即可按照已知模型工作流完成连接、扫描、控制和停止全流程操作。如果用户不清楚品牌型号,可触发自动发现流程,插件会自动一步步完成扫描和连接。该插件面向拥有合法合规自有设备的个人用户,所有连接凭证都仅保存在本地插件配置中,不会暴露给大模型,内置安全防护机制,包含默认 30 秒自动停止输出、强度和时长上限限制,还支持一键全局停止所有设备。

该插件使用 BSD-3-Clause 许可证开源,依赖 Node.js 22.19 或更新版本以及 pnpm 包管理器,可通过 DSH 官方插件命令直接从 GitHub 安装配置。macOS 原始蓝牙发现需要 Xcode 命令行工具中的 Swift 编译器,且仅支持只读发现,不控制设备。已知局限包括 MonsterParty 可能需要协议更新,仅公开了 RoomFun 特定型号的验证映射,Buttplug 目前仅支持标量控制功能。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 no risk signal found未发现风险信号
  • This site's static screen found no obvious risk signal (stars, license, activity, manifest)本站静态筛查没发现明显风险信号(星标、许可证、更新活跃度、清单完整度)
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

npx -y @deepseek-ai/dsh plugin --profile web add github:c3ll256/dsh-toy

把 c3ll256/dsh-toy 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-toy

CI

English | 简体中文

dsh-toy is a DeepSeek Harness plugin for connecting small toys to DSH.

At connection time, the agent first asks for the brand and model, then selects the connection method automatically. If the user genuinely does not know, the agent starts unknown-hardware discovery:

  • On macOS, unknown hardware first uses read-only raw CoreBluetooth advertisement discovery, without starting Intiface or connecting to devices.
  • Regular Bluetooth, serial, and USB models use Buttplug / Intiface. The plugin starts local Intiface Engine automatically when needed.
  • Known sharing-link models from Ankni (安可尼), MizzZee (谜姬), and Zuiqingfeng (醉清风) use MonsterParty. Known dual-output devices expose their channels separately.

Users do not need to understand or select an underlying connection method, or manually start Intiface.

Brand and model names are not an allowlist. The agent passes any user-reported name through unchanged; unfamiliar names still use local hardware discovery. The plugin also supplies a verified local compatibility mapping for RoomFun devices reporting model RF_CANNON_PT3, exposed as RoomFun Cannon with one vibration channel.

The implementation follows protocol observations from Chemtrails, together with the device model and message formats documented by Buttplug and the Buttplug Protocol Specification. This repository contains an independent TypeScript implementation; see NOTICE for attribution.

Guardrails

  • Sharing tokens stay in plugin configuration and never appear in model-visible tool arguments or results.
  • Raw BLE discovery is read-only: it scans connectable advertisements without connecting or writing characteristics.
  • Output stops automatically after 30 seconds by default.
  • Zero-duration holds are disabled unless allowHold: true is explicitly configured.
  • maxIntensityPercent and maxDurationSeconds are enforced before backend dispatch.
  • A newer command replaces the previous automatic-stop timer for the same device.
  • toy_stop without a device id performs a global stop.
  • Plugin unload, HMR, and toy_disconnect stop output and await WebSocket shutdown.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-plugins-store 下一个 Next dsh-remote →