exoticknight/dsh-plugin-template
One sentence to an AI agent: create, release and list a DeepSeek Harness plugin. DSH 插件模板与 AI 操作手册
Project Overview项目介绍
This repository is a template project named dsh-plugin-template, maintained by exoticknight under the Apache-2.0 license, and it exists specifically to scaffold new plugins for DeepSeek Harness. The project already ships a full skeleton split into two entry points: a Host entry that runs inside DSH's Node process and is mounted as a Cordis plugin with a configuration schema, and a Client entry that is bundled into the format consumed by DSH's module loader. A --host-only flag strips out the client side for service-only plugins. The esbuild configuration treats every @deepseek-ai/* package as an external dependency supplied by DSH itself, injects the plugin name and version as build-time constants, and ships a bundle-manifest so the package can be picked up by the DSH runtime.
The intended workflow starts by clicking "Use this template" on GitHub or simply cloning the repo, then sending a single sentence in Chinese to a coding agent such as Claude Code, Codex, Cursor, or any other compatible programming assistant—for example, "用 dsh-plugin-template 建一个 DSH 插件 dsh-foo, 功能是……, 发布到 npm." From there the agent opens AGENTS.md and follows six numbered playbooks under playbooks/ that walk through 00-init (repo creation and parameter collection), 10-github (Actions permissions, tag protection, npm environment), 20-npm (Trusted Publisher, first publish), 30-release (tagging, recovery), 40-maintain (DSH and Node upgrades, Dependabot), and 50-listings (catalog submission plus README badge). The agent pauses only when human credentials are needed: npm login, the very first npm publish with its two-factor code, configuring the Trusted Publisher on npmjs.com, and approving the catalog submission.
Required tooling includes Node.js ^22.19.0 || >=24, pnpm, git, an authenticated GitHub CLI, and a DSH CLI for local testing; the manual path begins with node scripts/init.mjs --name dsh-foo --owner <user> --dsh-version <ver> --title "Foo" --description "Foo for DeepSeek Harness." followed by pnpm install, pnpm hooks:install, and pnpm verify. Development is kept isolated via pnpm dev, which links the current source into an in-repo .dsh-dev directory and verifies it never touches the user's regular DSH install, while pnpm smoke installs the already-published version into a throwaway directory and verifies it the same way end users would. CI runs on Ubuntu and Windows against Node 22.19 and 24, npm Trusted Publishing is preconfigured, GitHub Releases and notes are generated automatically, and prereleases flow through npm's next dist-tag. A first-run caveat is that AGENTS.md and playbooks/00-init.md must run before any plugin feature is written, otherwise template placeholders such as dsh-plugin-template, {{OWNER}}, and {{DSH_VERSION}} will survive into the published package.
这是一个面向 DeepSeek Harness 的插件脚手架仓库,名字叫 dsh-plugin-template,由 exoticknight 用 Apache-2.0 协议维护。它预置了一套完整的插件骨架:Host 入口以 Node 进程内的 Cordis 插件形式挂载到 DSH,含配置 schema;Client 入口打包为 DSH 模块加载器所需的格式,纯服务插件可通过 --host-only 一键剔除。esbuild 构建时把 @deepseek-ai/* 视作 DSH 外部依赖,并把插件名与版本号在编译阶段注入代码,并携带 bundle-manifest 形式的 DSH 包清单。
典型用法是把仓库设为模板后,给 Claude Code、Codex、Cursor 或任何编程 agent 一句中文需求(如"用 dsh-plugin-template 建一个 DSH 插件 dsh-foo,功能是……"),agent 会按照 playbooks/ 下 00-init、10-github、20-npm、30-release、40-maintain、50-listings 六本剧本自动完成建仓、实现、pnpm verify、GitHub 配置、npm Trusted Publishing、tag 发布、目录收录与 README badge 等步骤。用户只需亲自完成 npm login、首次 publish、npmjs.com 上配置 Trusted Publisher,以及向插件目录提交收录这三件事。
环境要求 Node.js ^22.19.0 || >=24、pnpm、git、已登录的 GitHub CLI,本地调试还需要 DSH CLI,并依靠 pnpm dev 把源码链接进隔离目录 .dsh-dev,pnpm smoke 在一次性目录中按用户方式验证已发布版本,两者都会校验隔离,避免污染日常的 DSH 环境。CI 覆盖 Ubuntu 与 Windows 上的 Node 22.19/24,预发布版本自动走 npm next 通道。手动模式可执行 node scripts/init.mjs --name dsh-foo --owner <user> --dsh-version <ver>,再用 pnpm hooks:install 与 pnpm verify 完成初始化;首次提交前请勿先写插件功能,必须先让 agent 读 AGENTS.md 并按 playbooks/00-init.md 完成初始化,否则会留下模板占位符。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugin-template(exoticknight/dsh-plugin-template)
仓库:https://github.com/exoticknight/dsh-plugin-template
本站详情页:https://www.yhbd.top/plugins/exoticknight-dsh-plugin-template/
本站登记:类型 resource · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 3 · 最近提交 2026-09-30 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:exoticknight/dsh-plugin-template
把 exoticknight/dsh-plugin-template 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH 插件模板
一句话交给 AI,从想法到上架一个 DeepSeek Harness 插件。
建仓、初始化、构建、测试、CI、npm 与 GitHub 发布、插件目录收录,全部准备好,并写成 AI 能照着执行的手册。
简体中文 | English
[!IMPORTANT] AI agent: 这是尚未初始化的模板。请先读
AGENTS.md,再按playbooks/00-init.md执行。初始化前不要编写插件功能。
30 秒上手
把下面这句话发给 Claude Code、Codex、Cursor 或任何编程 agent,把功能换成你想要的:
用 https://github.com/exoticknight/dsh-plugin-template 建一个 DSH 插件 dsh-foo,
功能是……,发布到 npm。
agent 会创建你的仓库、完成初始化、实现功能、配置 GitHub 和 npm、发布第一个版本,再帮你提交到插件目录。只有登录 npm、首次发布这类必须由你本人完成的步骤,它才会停下来问你。
从一句话到上架
flowchart LR
A["一句话需求"] --> B["建仓 + 初始化<br/>00-init"]
B --> C["实现功能<br/>pnpm verify"]
C --> D["GitHub 配置<br/>10-github"]
D --> E["npm 首发<br/>20-npm"]
E --> F["推 tag 发布<br/>30-release"]
F --> G["目录收录 + badge<br/>50-listings"]
每一步都有一份 playbook:写明目标、前置条件、可以直接执行的命令和完成标准。之后的升级、发版和维护也按同样的方式进行。
你会得到
🧩 开箱即用的插件骨架
- Host 入口运行在 DSH 的 Node 进程中,由 Cordis 挂载,带配置 schema
- Client 入口运行在 DSH 页面中,打包成 DSH 模块加载器使用的格式;纯服务插件可以一键去掉
- esbuild 构建:
@deepseek-ai/*由 DSH 提供,插件名和版本号在构建时注入
✅ 不会坏的质量关卡
- TypeScript strict,契约测试覆盖包元数据、Cordis 挂载与卸载、client 注册
- 检查 npm 包内容,确保入口文件齐全、源码和测试不会混入
- 发布前把关:tag 与版本一致、仓库地址正确、没有残留占位符
🚀 一个 tag 完成发布
- CI 覆盖 Ubuntu / Windows × Node 22.19 / 24
- npm Trusted Publishing,并自动创建 GitHub Release:按 PR 标签分类变更、标注贡献者,可附加版本重点与升级说明
- 预发布版本自动走 npm
next通道;每一步都能安全重跑 - 也可以只发布到 GitHub(
--no-npm)
🧪 不污染日常环境的本地调试
pnpm dev把当前源码链接进仓库内的隔离目录.dsh-dev并启动 DSH;pnpm smoke在一次性目录中按用户的方式安装已发布版本并验证。两者都会校验隔离是否生效,绝不改动你日常使用的 DSH
🤖 写给 AI 的操作手册
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
pingfanfan/hello-dsh
abab996/dsh-plugin-dev
walkinglabs/learn-harness-engineering
Electricitysheep/dsh-handbook
humblebanana/open-record-replay
feicaiclub/deepseek-harness-whitepaper