grloper/dsh-deep-research
JavaScript evidence-processing tools for source-text anchoring, document similarity/lineage, claim assessment, and storage. The implementation is in lib/; the command-line entry point is bin/kestrel.mjs.
catalog descriptioncatalog 简介 / catalog description:Kestrel: normalized quotation admission, source anchoring and evidence-processing tools with verified offline workflows
Project Overview项目介绍
grloper/dsh-deep-research, codenamed Kestrel, is a native DeepSeek Harness (DSH) plugin for deep research and fact-checking. It also ships as a standalone zero-runtime-dependency Node.js library that can be used outside of DSH. It addresses four common failures of existing AI research tools that prompt engineering cannot fix: citations that do not actually support attached claims, fake corroboration from counting non-independent syndicated sources, confirmation-only search that ignores refuting evidence, and failure to separate low-quality AI-generated content from primary sources. To get started quickly, you can clone the repository, cd into the project folder, and run npm run demo to see the full verification pipeline work on a preconfigured test corpus.
Kestrel uses mechanical code-based checks instead of relying on LLMs to verify their own output, which is an inherently circular process that often misses hallucinations. First, it requires every claim paired with a citation to have a verbatim quote from the cited source, then runs a literal substring check against the full source text to confirm the quote actually exists. If the quote is not found with sufficient overlap, the citation is rejected and the claim is automatically marked as unverified. Next, it calculates source independence using MinHash and LSH to count independent origins instead of raw document counts, so 12 syndicated copies of one press release only count as one independent source.
The project is released under the permissive MIT license, requires Node.js version 20 or higher, and has no additional runtime dependencies beyond what is specified in the package.json. It explicitly documents its limitations to avoid overpromising: it only verifies that a quote exists in a source, it does not guarantee that the underlying claim is factually correct. It also notes that it cannot run at all without a search service for source discovery, and the overall quality of reasoning depends on the host LLM. You can run the full test suite with npm run test, or npm run test:serial if you are working in a restricted sandbox environment that does not allow parallel process spawning.
本仓库是 grloper/dsh-deep-research,代号Kestrel,是DeepSeek Harness(DSH)原生深度研究插件,同时也可作为独立无运行依赖的Node.js库使用。它的核心功能是对AI生成内容的引用和结论进行机械验证,解决现有AI研究工具常见的四类缺陷:引用不实、虚假佐证、仅搜索确认性内容以及劣质来源混杂。
Kestrel的工作流程分为两步:首先对每个结论的引用要求提供原文逐字引用,通过代码字面字符串匹配检查引用内容是否确实存在于来源文档中,不匹配的直接标记为未验证。接着通过MinHash和LSH算法计算来源独立性,统计独立信源数量而非总文档数量,避免把同一内容的多处转发当成多个独立佐证。
本项目使用MIT许可证,要求Node.js版本不低于20,无额外运行依赖,支持本地快速运行演示。它明确标注自身局限:只能验证引用是否存在,不能保证结论本身正确,没有搜索服务就无法运行,推理质量依赖宿主大模型。用户可克隆仓库后运行npm run demo快速体验核心流程。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-deep-research(grloper/dsh-deep-research)
仓库:https://github.com/grloper/dsh-deep-research
本站详情页:https://www.yhbd.top/plugins/grloper-dsh-deep-research/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-10-01 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:grloper/dsh-deep-research
把 grloper/dsh-deep-research 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
Kestrel / dsh-deep-research
JavaScript evidence-processing tools for source-text anchoring, document similarity/lineage, claim assessment, and storage. The implementation is in lib/; the command-line entry point is bin/kestrel.mjs.
Verified local behavior
On the audited branch, 265 Node tests pass. node demo/run.mjs executes the real library against the bundled fictional corpus: it checks source-text quotations, groups copied documents, surfaces the fixture contradiction, and recalls stored findings. These are offline fixture results; the corpus is not real-world business evidence.
The audit reproduced a citation defect: fuzzy matching admitted a long quotation whose amount was changed from 42 to 91. Quote matching now defaults to strict mode, and both citation-admission paths disable fuzzy matching. Regression tests exercise that exact counterexample. Explicit approximate search is still available, but it cannot enable fuzzy citation admission.
Run
Requires Node 20 or later. The local test/demo path has no required third-party packages or API keys.
node --test
node demo/run.mjs
node bin/kestrel.mjs --help
Standalone URL-fetching commands and DeepSeek Harness/model integration are implemented in the source but were not validated against live providers in this audit. Running URL commands makes network requests; installing into a Harness profile changes local configuration.
Limits
Finding a quote in a document does not prove the claim is true. Normalized matching ignores case and punctuation; inspect the returned source span. Similarity-based lineage is a heuristic, not proof of source independence. Model judgments, live search, fetch resilience and real-world research accuracy remain unverified here. No fabricated-quote-proof, accuracy, latency, or production-scale guarantee is claimed.
Han-1413141/dsh-cost-meter
wssfk12138/dsh-damage-pulse
songoao25/dsh-bottom-info-bar
Phant0Meow/dsh-meow-cachebilling
Rianico/dsh-better-edit
Ghost011118/dsh-balance-meter
ai-shushu/dsh-quota-meter
TwotwoPiggy/dsh-balance