dongsheng123132/dsh-xiapan-media

Plugin插件 Native原生 ⭐ 2 MIT Vision & Media视觉与多媒体

用于DeepSeek Harness的Xiapan Cloud原生视觉、gpt-image-2和Seedance插件

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH), adding three native multimodal media capabilities to DSH: image recognition/OCR, image generation/editing, and video generation. It relies on Xiapan Cloud's remote model services for inference, rather than running models locally. To install the plugin, users can run the DSH CLI command either with a local development link or by specifying the GitHub repository along with a valid commit SHA that has passed CI checks. After installation, all three capabilities are added at once, but each can be disabled individually from the DSH profile.

This plugin is designed for DSH users who want to handle multimodal content directly within their DSH conversations, without switching to external tools. After installation, users select the xiapan-vision route for automatic image-to-text conversion when pasting images into DeepSeek-powered conversations, or use the three dedicated file tools for targeted vision tasks like OCR and object location. For image generation, users can specify up to four outputs, adjust size and quality, and add a reference image, while video generation supports text-to-video and image-to-video with adjustable durations from 5 to 15 seconds and resolutions up to 1080p. All generated media is saved to specified folders in the local DSH workspace for immediate reference in the current conversation.

The client-side plugin is released under the open-source MIT license, but all model inference, quota management, billing, and security checks are handled by the closed-source Xiapan Cloud service. Users need to log into U-King and add credits to use the service, and credentials are pulled dynamically in order of priority from DSH credential storage, environment variables, and local device files. By default, all paid generation calls require manual user approval before execution, to prevent accidental silent charges, and this approval requirement can only be disabled by admins for headless environments. The plugin also enforces security boundaries, limiting input files to the workspace root, capping input image size at 10 MiB and output size at 200 MiB.

这是一款专为 DeepSeek Harness (DSH) 开发的原生插件,为 DSH 新增识图 OCR、图像生成/改图、视频生成三项多模态媒体能力,还提供了三个独立文件工具用于针对性识图任务。插件调用虾盘云的模型服务完成推理,识图使用 qwen3.7-flash 将图片转文本后交回原文本模型处理,作图改图调用 gpt-image-2,视频生成调用 Seedance,产物分别保存到工作区指定目录。

目标用户是需要在 DSH 会话中直接处理多模态媒体内容的用户,典型工作流为:用户安装插件后,选择对应路由或工具,粘贴图片或输入文本描述指令,插件自动调用虾盘云服务生成结果,保存到本地工作区后供 DSH 会话直接引用。识图支持自动粘贴处理,作图改图可设置输出数量、尺寸、参考图,视频生成支持文生、图生不同时长与分辨率。

插件采用 MIT 许可证开源,模型服务由虾盘云提供,用户需要登录 U-King 并充值获得使用额度,凭据按优先级从 DSH 凭据服务、环境变量、本地设备文件获取。插件自带付费审批闸门,默认需要用户手动确认才会调用付费服务,防止静默扣费,对输入输出也做了明确的安全边界限制,例如限制输入文件必须位于工作区内。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add "github:dongsheng123132/dsh-xiapan-media#COMMIT_SHA"

把 dongsheng123132/dsh-xiapan-media 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-xiapan-media

CI License: MIT DeepSeek Harness

给 DeepSeek Harness 增加三项原生媒体能力:

  1. 识图/OCR:xiapan-vision 路由让仍由 DeepSeek 负责思考的会话可以直接粘贴图片;图片先由虾盘云 qwen3.7-flash 转译为文本,再交回原文本模型。另提供 xiapan_vision_analyze、xiapan_vision_ocr、xiapan_vision_locate 三个文件工具。
  2. 作图/改图:xiapan_image_generate 调用 gpt-image-2,支持 1–4 张、尺寸/质量与参考图,产物保存到工作区 .dsh-media/images/。
  3. 视频生成:xiapan_video_generate 调用 Seedance,支持文生视频、图生视频、5–15 秒、480p/720p/1080p,产物保存到 .dsh-media/videos/。

这不是把 API Key 写死在开源代码中的“共享密钥插件”。客户端插件使用 MIT 开源;模型推理、额度、风控和充值由虾盘云服务端提供。用户安装 U-King、登录并充值后,插件复用设备级凭据 UKING_DSH_API_KEY。也可自行在 DSH 凭据仓库或环境变量中设置该引用。

安装

本地开发安装:

dsh plugin --profile web add "link:D:/uking编程/dsh-xiapan-media"

GitHub 固定提交安装:

dsh plugin --profile web add "github:dongsheng123132/dsh-xiapan-media#COMMIT_SHA"

发布后请把 COMMIT_SHA 换成 README/Release 中经过 CI 的完整提交。插件包通过 cordis.patch.yml 一次安装三个独立插件行,任何一项都可以单独从 profile 中删除。

自动粘贴识图依赖文本路由 uking-managed。安装完成后在 DSH 模型选择器里选择 U-King DeepSeek + 虾盘云识图(路由 ID xiapan-vision)。如果用户只安装了原生 DeepSeek 路由,可把视觉插件的 innerProvider 改成实际文本 provider ID。

凭据顺序

每次调用时动态解析,不缓存、不打印:

  1. DSH credentials 服务中的 UKING_DSH_API_KEY;
  2. 同名环境变量;
  3. XIAPAN_API_KEY;
  4. ~/.uking/device.json 中的设备凭据。

未找到凭据时会提示登录/充值,不会尝试匿名调用。Authorization 只允许发送到 api.u-claw.org.cn(兼容旧域名 api.u-claw.org 并自动改为 .org.cn)。

付费保护

作图和视频工具默认注册 DSH tools/pre-execute 审批闸门。交互式 DSH 会先显示模型、数量/时长和粗略价格;无审批服务的 headless 环境会拒绝,不会静默扣费。只有管理员明确把 requireApproval 设为 false 时才允许无人值守付费调用。

Seedance 当前粗略基价(以虾盘云实时计费为准):

  • mini:约 ¥2.9 / 5 秒 / 480p
  • fast(doubao-seedance-2-0-fast-260128):约 ¥4.9 / 5 秒 / 480p
  • full(doubao-seedance-2-0-260128):约 ¥6.9 / 5 秒 / 480p
  • 720p 通常约 1.5 倍,1080p 约 2.5 倍;最终价格应由服务端账单页展示,插件文案不是报价承诺。

安全边界

  • 输入文件必须位于配置的工作区根目录内;拒绝 .. 越界和指向工作区外的符号链接。
  • 单张输入图最大 10 MiB,下载产物最大 200 MiB。
  • 产物使用临时文件 + 原子改名写入,不覆盖已有文件。
  • 只接受 HTTPS 虾盘云 API 和 HTTPS 产物 URL;错误信息会遮蔽常见密钥格式。
  • DSH v1 attachment 服务目前只原生保存图片,因此视频作为真实 .mp4/.webm 文件路径返回。

开发验证

npm install
npm test
npm run check

测试只使用模拟 HTTP,不消耗虾盘云额度。真实作图/视频会产生费用,不应放进公共 CI。

商业与开源边界

推荐保持这个薄客户端 MIT 开源,同时保留虾盘云服务端闭源:

  • 开源部分负责 DSH 适配、工作区安全、审批与可审计行为;
  • 商业部分负责统一模型供应、U-King 充值、余额、限流、退款与风控;
  • 后续可增加 BYOK/baseURL 高级配置,但不能在客户端内置平台总密钥。

SkillHub/ClawHub 更像发现与分发渠道,不应假设它们替插件作者完成分账。常见可持续模式正是“免费 skill/plugin + 用户 API Key 或托管 credits”。

← 上一个 Prev DSH-minesweeper 下一个 Next dsh-discord →