dongsheng123132/dsh-xiapan-media
用于DeepSeek Harness的Xiapan Cloud原生视觉、gpt-image-2和Seedance插件
Project Overview项目介绍
This is a native plugin built exclusively for DeepSeek Harness (DSH), adding three native multimodal media capabilities to DSH: image recognition/OCR, image generation/editing, and video generation. It relies on Xiapan Cloud's remote model services for inference, rather than running models locally. To install the plugin, users can run the DSH CLI command either with a local development link or by specifying the GitHub repository along with a valid commit SHA that has passed CI checks. After installation, all three capabilities are added at once, but each can be disabled individually from the DSH profile.
This plugin is designed for DSH users who want to handle multimodal content directly within their DSH conversations, without switching to external tools. After installation, users select the xiapan-vision route for automatic image-to-text conversion when pasting images into DeepSeek-powered conversations, or use the three dedicated file tools for targeted vision tasks like OCR and object location. For image generation, users can specify up to four outputs, adjust size and quality, and add a reference image, while video generation supports text-to-video and image-to-video with adjustable durations from 5 to 15 seconds and resolutions up to 1080p. All generated media is saved to specified folders in the local DSH workspace for immediate reference in the current conversation.
The client-side plugin is released under the open-source MIT license, but all model inference, quota management, billing, and security checks are handled by the closed-source Xiapan Cloud service. Users need to log into U-King and add credits to use the service, and credentials are pulled dynamically in order of priority from DSH credential storage, environment variables, and local device files. By default, all paid generation calls require manual user approval before execution, to prevent accidental silent charges, and this approval requirement can only be disabled by admins for headless environments. The plugin also enforces security boundaries, limiting input files to the workspace root, capping input image size at 10 MiB and output size at 200 MiB.
这是一款专为 DeepSeek Harness (DSH) 开发的原生插件,为 DSH 新增识图 OCR、图像生成/改图、视频生成三项多模态媒体能力,还提供了三个独立文件工具用于针对性识图任务。插件调用虾盘云的模型服务完成推理,识图使用 qwen3.7-flash 将图片转文本后交回原文本模型处理,作图改图调用 gpt-image-2,视频生成调用 Seedance,产物分别保存到工作区指定目录。
目标用户是需要在 DSH 会话中直接处理多模态媒体内容的用户,典型工作流为:用户安装插件后,选择对应路由或工具,粘贴图片或输入文本描述指令,插件自动调用虾盘云服务生成结果,保存到本地工作区后供 DSH 会话直接引用。识图支持自动粘贴处理,作图改图可设置输出数量、尺寸、参考图,视频生成支持文生、图生不同时长与分辨率。
插件采用 MIT 许可证开源,模型服务由虾盘云提供,用户需要登录 U-King 并充值获得使用额度,凭据按优先级从 DSH 凭据服务、环境变量、本地设备文件获取。插件自带付费审批闸门,默认需要用户手动确认才会调用付费服务,防止静默扣费,对输入输出也做了明确的安全边界限制,例如限制输入文件必须位于工作区内。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-xiapan-media(dongsheng123132/dsh-xiapan-media)
仓库:https://github.com/dongsheng123132/dsh-xiapan-media
本站详情页:https://www.yhbd.top/plugins/dongsheng123132-dsh-xiapan-media/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-07 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add "github:dongsheng123132/dsh-xiapan-media#COMMIT_SHA"
把 dongsheng123132/dsh-xiapan-media 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-xiapan-media
给 DeepSeek Harness 增加三项原生媒体能力:
- 识图/OCR:
xiapan-vision路由让仍由 DeepSeek 负责思考的会话可以直接粘贴图片;图片先由虾盘云qwen3.7-flash转译为文本,再交回原文本模型。另提供xiapan_vision_analyze、xiapan_vision_ocr、xiapan_vision_locate三个文件工具。 - 作图/改图:
xiapan_image_generate调用gpt-image-2,支持 1–4 张、尺寸/质量与参考图,产物保存到工作区.dsh-media/images/。 - 视频生成:
xiapan_video_generate调用 Seedance,支持文生视频、图生视频、5–15 秒、480p/720p/1080p,产物保存到.dsh-media/videos/。
这不是把 API Key 写死在开源代码中的“共享密钥插件”。客户端插件使用 MIT 开源;模型推理、额度、风控和充值由虾盘云服务端提供。用户安装 U-King、登录并充值后,插件复用设备级凭据 UKING_DSH_API_KEY。也可自行在 DSH 凭据仓库或环境变量中设置该引用。
安装
本地开发安装:
dsh plugin --profile web add "link:D:/uking编程/dsh-xiapan-media"
GitHub 固定提交安装:
dsh plugin --profile web add "github:dongsheng123132/dsh-xiapan-media#COMMIT_SHA"
发布后请把 COMMIT_SHA 换成 README/Release 中经过 CI 的完整提交。插件包通过 cordis.patch.yml 一次安装三个独立插件行,任何一项都可以单独从 profile 中删除。
自动粘贴识图依赖文本路由 uking-managed。安装完成后在 DSH 模型选择器里选择 U-King DeepSeek + 虾盘云识图(路由 ID xiapan-vision)。如果用户只安装了原生 DeepSeek 路由,可把视觉插件的 innerProvider 改成实际文本 provider ID。
凭据顺序
每次调用时动态解析,不缓存、不打印:
- DSH credentials 服务中的
UKING_DSH_API_KEY; - 同名环境变量;
XIAPAN_API_KEY;~/.uking/device.json中的设备凭据。
未找到凭据时会提示登录/充值,不会尝试匿名调用。Authorization 只允许发送到 api.u-claw.org.cn(兼容旧域名 api.u-claw.org 并自动改为 .org.cn)。
付费保护
作图和视频工具默认注册 DSH tools/pre-execute 审批闸门。交互式 DSH 会先显示模型、数量/时长和粗略价格;无审批服务的 headless 环境会拒绝,不会静默扣费。只有管理员明确把 requireApproval 设为 false 时才允许无人值守付费调用。
Seedance 当前粗略基价(以虾盘云实时计费为准):
- mini:约 ¥2.9 / 5 秒 / 480p
- fast(
doubao-seedance-2-0-fast-260128):约 ¥4.9 / 5 秒 / 480p - full(
doubao-seedance-2-0-260128):约 ¥6.9 / 5 秒 / 480p - 720p 通常约 1.5 倍,1080p 约 2.5 倍;最终价格应由服务端账单页展示,插件文案不是报价承诺。
安全边界
- 输入文件必须位于配置的工作区根目录内;拒绝
..越界和指向工作区外的符号链接。 - 单张输入图最大 10 MiB,下载产物最大 200 MiB。
- 产物使用临时文件 + 原子改名写入,不覆盖已有文件。
- 只接受 HTTPS 虾盘云 API 和 HTTPS 产物 URL;错误信息会遮蔽常见密钥格式。
- DSH v1 attachment 服务目前只原生保存图片,因此视频作为真实
.mp4/.webm文件路径返回。
开发验证
npm install
npm test
npm run check
测试只使用模拟 HTTP,不消耗虾盘云额度。真实作图/视频会产生费用,不应放进公共 CI。
商业与开源边界
推荐保持这个薄客户端 MIT 开源,同时保留虾盘云服务端闭源:
- 开源部分负责 DSH 适配、工作区安全、审批与可审计行为;
- 商业部分负责统一模型供应、U-King 充值、余额、限流、退款与风控;
- 后续可增加 BYOK/baseURL 高级配置,但不能在客户端内置平台总密钥。
SkillHub/ClawHub 更像发现与分发渠道,不应假设它们替插件作者完成分账。常见可持续模式正是“免费 skill/plugin + 用户 API Key 或托管 credits”。
nexu-io/open-design
Devin-AXIS/iPolloWork
liustack/modlens
Alisa0808/vox-director
EthanYoQ/AI-Novel-Writer
Anionex/agent-vision-toolkit
ysr666/dsh-vision-router
tong-io/tongflow