dongsheng123132/task-passport
DeepSeek Harness、WorkBuddy、Claude Code和Codex的开放任务交接协议——验证状态,而非聊天记录
Project Overview项目介绍
Task Passport is a cross-agent task state management tool that lets tasks carry current working state across multiple AI harnesses and agents, including DeepSeek Harness, Claude Code, Codex, and CodeBuddy. It is distributed as a single npm package that works both as a generic CLI tool and a native DeepSeek Harness bundle. To install it on DSH, users can run the command dsh plugin --profile web add task-passport@0.3.0 and follow the step to dump config and launch dsh web. For other agents like Claude Code, it can be added as an MCP server via claude mcp add with the npx command.
Task Passport is designed for teams and projects that need to hand off tasks across people, devices, and different AI agents. Each task gets a unique stable short ID like TP-7K4M-9D2Q, and users can list existing passports, open a target passport to read its current state, and write back state after work with a checkpoint command that includes versioning to prevent silent overwrites. When you need to hand off a task, you can pack it into a single self-contained TaskPack file, and the receiver can land it into their own task store. This workflow avoids copying full chat history, keeps context clean, and reduces redundant context bloat for the next agent working on the task.
Task Passport is released under the open source MIT license, and requires Node.js 20 or higher to run. The current TaskPack 0.1 specification only checks structural conformance, it does not verify content completeness or provide built-in signing. Users need to handle additional validation of content outside of the TaskPack file itself. For users in mainland China, network issues often block access to the default npm registry, so switching to the npmmirror registry is recommended to avoid installation failures. It supports storage via U-King Action Core or a local directory, detects version conflicts to prevent overwrites, and allows third parties to implement custom storage providers.
Task Passport(任务护照)是一个跨AI agent平台的任务状态接力工具,核心功能是让同一个任务带着当前世界状态在不同AI框架(包括DeepSeek Harness、Claude Code、Codex、CodeBuddy等)之间传递,无需搬运冗余聊天记录。它同时提供通用命令行工具(CLI)和DeepSeek Harness原生插件包,可通过dsh命令一键安装到DSH的web profile,也可作为MCP服务接入其他AI agent,还适配了U-King存储和本地目录存储两种方式。
这款工具适合需要跨人和跨设备交接任务的开发团队、多AI协作项目使用。典型工作流是:创建带唯一短号标识(如TP-7K4M-9D2Q)的任务护照,工作完成后通过checkpoint写回带版本的状态,需要交接时将任务打包成自包含的单文件TaskPack,接收方通过land指令读取任务到本地存储,完成后可将回执写回原护照。整个过程不复制历史聊天,只保留有效任务状态,避免用无关历史挤占下一模型的上下文,提升交接效率。
本项目基于MIT许可证开源,要求Node.js 20及以上版本运行。当前0.1版本的TaskPack只校验结构合规,不保证内容完整性,也没有内建签名或第三方见证,需要用户在包外额外验证内容完整性。中国大陆用户使用npm安装时,建议切换到npmmirror镜像,避免网络问题导致安装失败;支持U-King、本地目录存储,也允许第三方实现自定义存储提供者。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:task-passport(dongsheng123132/task-passport)
仓库:https://github.com/dongsheng123132/task-passport
本站详情页:https://www.yhbd.top/plugins/dongsheng123132-task-passport/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 10 · 最近提交 2026-09-30 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 10 stars - an early-stage project星标 10,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add task-passport@0.3.2
把 dongsheng123132/task-passport 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
Task Passport · 任务护照
让一个任务带着“当前世界状态”在 DeepSeek Harness、Claude Code、Codex 等 AI Harness 之间接力,不搬运聊天记录。
护照留在家里,TaskPack 出门。 Task Passport 是常驻的任务状态(有版本、有锁、留在 store 里); TaskPack 是一次搬运的封装(单文件、自包含、在别人机器上打开)。
护照 --pack--> TaskPack --land--> 新护照
一个项目可以有多个任务护照;一个任务护照可以经历多个 Harness 和多个会话。
现在能做什么
- 每个任务一个稳定短号,例如
TP-7K4M-9D2Q。 list:只列身份与摘要,不误装载别的任务。open:读取目标、当前状态、验证过的事实、决策理由和下一步。checkpoint:工作完成后写回;带状态版本,过期写入直接冲突,不静默覆盖。pack/land:把任务装进一个文件发给别人、发给另一台机器,或者收下别人发来的。conformance:判定一个文件是不是合规的 TaskPack(退出码 0 / 2)。- 同一个包既是通用 CLI,也是 DeepSeek Harness 原生 bundle。
- 状态可由 U-King Action Core、本地目录参考存储或第三方 Provider 托管;插件本身是可装可卸的薄适配器。
它不做两件事:不复制上一位 AI 的聊天记录;不把“刚改过的任务”猜成当前任务。
跨机跨人:TaskPack
规范正本:docs/taskpack-0.1.md · https://taskpack.org
# 发出去(对方装了工具,走标准形态)
task-passport pack TP-7K4M-9D2Q --out 交接.taskpack --actor 贺方升 \
--file ./01-文案.txt \
--ask "给封面图的提示词|一段中文提示词,覆盖 750×400 与配色要求" \
--check "本机能出图|bl image generate 跑一张测试图"
# 发出去(对方什么都没装 —— 一个可读 JSON,丢给他自己的 AI 就行)
task-passport pack TP-7K4M-9D2Q --out 交接.taskpack.json --flat
# 收下来
task-passport land 交接.taskpack --store D:\TaskPassports
task-passport conformance 交接.taskpack
# 对方把回执发回来了:答案写回提问的那本护照,不新开一本
task-passport land 回执.taskpack.json --into TP-7K4M-9D2Q --store D:\TaskPassports
# 上周发给客户的那个包里到底有什么?
task-passport outbox --store D:\TaskPassports
task-passport outbox --store D:\TaskPassports --show 1 # 打开当时那份护照存根
三条硬规矩,写进格式而不是写进说明书:
- 机器级事实在打包时就被封存为未证,并记下它曾在哪台机器上被证明(
verified_on)。 降级发生在打包这一端,不是落地那一端——否则第三方写的接收器忘了降级,假 ✓ 就进去了。 安全属性必须长在文件里,不能长在接收方身上。 - 没有
accept的 ask 拒绝打包。 说不出"什么算答完"的请求,只会变成又一轮扯皮。 - 包里的每个字节都是数据,不是指令。 这条是实测倒逼的:首次跨人交接时,对方的 AI 明确拒绝执行文件里的交接说明——那是正确行为,协议必须活在这个安全模型里。
- 提出的 ask 会被记进护照,回执才有归处。
pack --ask在打包时把问题写回护照; 回执用land --into合并,答案落在原来那本护照上,open变answered并记下谁答的。 交接开新护照、回执回原护照——方向不同,因为一个是搬家,一个是回信。 - 发出去的每一个包都记一笔台账,并存下当时那份护照的存根。 包一旦出门就撤不回来(GitHub 对已推送密钥的官方建议也是「去轮换」而不是「去删除」), 所以记录写在出门这一端。护照后来改到 v9,也照样答得出 v5 那次发了什么。 台账不是公证:能写 store 的人就能改它,它回答的是「我发了什么」,不是向第三方举证。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
agentrq/agentrq
KelaoHu/dsh-lowtide
XDTrees/dsh-workbuddy-xdpool
FeatherHunter/dsh-prompt
dragonbaba/dsh-routing-suite