harrylabsj/kiwi

Plugin插件 ⭐ 20 Apache-2.0 Data & Analysis数据与分析

A2A commerce negotiation runtime + DeepSeek Harness (dsh) plugin. 安装 Kiwi,让 AI 买家找到你的商品、向你询价;库存、底价和客户数据仍留在你的系统中。

Project Overview项目介绍

Kiwi is an open-source A2A commerce negotiation protocol and standalone runtime that ships the KNP/1.0 specification, a dual-stack A2A client/server, UCP interop, signed identity, and safe handoff primitives. It runs as an independent CLI surface (kiwi, kiwi chat, kiwi agent serve, kiwi tui, kiwi demo) and also publishes an official DeepSeek Harness plugin, kiwi-dsh-plugin, installable via dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin, which lets a dsh session search listings, issue RFQs, and produce non-binding agreements directly. The project lives at harrylabsj/kiwi with 20 stars, is tagged dsh-plugin and a2a/commerce/cordis/mcp, and is licensed under Apache-2.0.

In the canonical workflow, a buyer agent and a merchant agent discover each other through Agent Cards and UCP profiles, intersect capabilities, and exchange KNP/1.0 Envelopes containing Inquiry, RFQ, Offer, CounterOffer, ConditionalOffer, Clarification, AcceptNonbinding, Withdraw, and AcceptedNonbindingAgreement objects. Negotiation terminates at a non-binding commercial agreement: no order is created, no payment is captured, and no inventory is reserved, while a separate operator-gated handoff bridges the agreement into a downstream checkout. The README ships kiwi demo [a|b] which boots a real kiwi-catalog plus three local merchants for deterministic end-to-end exercise, plus a TUI cockpit with supervised, manual, and autopilot modes. Target users are agent-platform integrators and protocol researchers who need auditable, side-effect-free inter-agent commerce rails.

Dependencies center on Node.js plus npm, with npm install, npm run build, npm test, and npm run verify covering lint, strict typecheck, full offline tests, and a production-bundle smoke. The kiwi demo flow additionally requires a runnable kiwi-catalog checkout (default ../kiwi-catalog, overridable via KIWI_CATALOG_DIR) and its Python environment; all traffic stays on loopback with ephemeral SQLite. For public-network merchant exposure the node refuses to start unless an inbound HttpMessageSignatureVerifier (RFC 9421 with content-digest binding) or an explicitly auditable reverse-proxy auth contract is wired in, otherwise LoopbackOnlyAuthVerifier would silently trust loopback-looking requests. The KNP/1.0 spec and JSON Schema are hosted at harrylabsj/kiwi-spec under Apache-2.0, mirroring the runtime license.

Kiwi 是一个开源的 A2A 电商磋商协议与独立运行时项目,提供 KNP/1.0 磋商规范、双栈 A2A 客户端/服务端、UCP 互操作、签名身份与安全交接能力。它同时支持作为独立 CLI 运行(kiwi、kiwi chat、kiwi agent serve、kiwi tui、kiwi demo),也提供面向 DeepSeek Harness 的官方插件 kiwi-dsh-plugin,可通过 dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin 挂载,使 dsh 会话直接搜索商品并发起非绑定磋商。

典型使用流程是:买家与商家作为独立 A2A Agent,通过 Agent Card 与 UCP Profile 完成发现,再以 KNP/1.0 Envelope 进行 capability 协商与多轮磋商,最终在非约束性商业协议处终止。kiwi demo 可一键启动 kiwi-catalog 与三个本地商家做确定性演示;TUI 还提供 supervised/manual/autopilot 三档操作者驾驶舱。它面向需要安全可审计的 agent 间商业磋商、又不愿承担订单与库存副作用的协议研究者和集成方。

依赖上,核心仓库以 Node.js 与 npm 为基础,npm install && npm run build && npm test 即可完成离线验证,演示需要外加一个可运行的 kiwi-catalog checkout。公网部署必须配置 HttpMessageSignatureVerifier 或明确的可审计代理认证,否则节点会因为认证前置条件缺失而启动失败;所有磋商均不创建订单、不支付、不锁库存,协议规范与 schema 公开以 Apache-2.0 托管于 harrylabsj/kiwi-spec。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • 20 stars - an early-stage project星标 20,属于早期项目
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin

把 harrylabsj/kiwi 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

Kiwi

A2A 电商磋商协议 + 独立运行时(KNP/1.0)。Buyer 与 Merchant 作为独立 A2A Agent,通过 A2A 与 UCP 完成发现 → capability 协商 → 磋商 → 非绑定协议。磋商以非约束性商业协议终止:不创建订单、不支付、不锁库存。

Kiwi 当前代码版本以 package.json 为准(当前 0.11.0):当前发布线包含 A2A 双栈、KNP/1.0 磋商、签名身份 与安全交接能力。A2A 1.0 线协议互操作以组合 conformance transcript 为准,不用历史审计 文档替代运行证据。

商家注册、一次连接确认和默认 20 个可配置商品名额的现行流程见 商家接入与商品名额设计 v0.6。 十种产品形态的版本来源、制品、平台审批状态和统一 release bundle 见Portfolio 发布管理与 portfolio-products.json。

协议:KNP/1.0

KNP/1.0 九类核心对象(Inquiry / RFQ / Offer / CounterOffer / ConditionalOffer / Clarification / AcceptNonbinding / Withdraw/Decline/Cancel / AcceptedNonbindingAgreement)已冻结为 JSON Schema, 与领域实现交叉一致性对齐(contracts/negotiation/1.0/schema.json)。

架构

Buyer Agent ──A2A wire──▶ Merchant Agent
   │                          │
   ├─ Agent Card / UCP Profile │
   ├─ capability intersection  │
   ├─ Negotiation Envelope     │   (KNP/1.0 对象,JCS 规范化 digest)
   ├─ Ledger(append-only)    │
   ├─ Idempotency / Recovery   │
   ├─ ConditionalOffer 求值    │
   └─ 非绑定协议                └─ 交易 handoff(agreement→checkout,operator 授权)
  • 谈判领域:Envelope + 九类对象、条件确定性求值、Ledger(hash 链)、幂等、跨进程恢复、remote/local 对账。
  • 原生 A2A:Agent Card、A2A client/server、Channel 抽象(direct / hosted)、Task 生命周期、消息签名。
  • UCP 互操作:profile 模型/resolver、capability intersection、well-known 服务。
  • 开放网络:trust records、fan-out 隐私 + 多商家 RFQ、服务端限流。
  • 交易 handoff:agreement→checkout 桥、operator 门控授权、只读 order records。

边界与安全

  • 磋商只形成非约束性共识(§41 #25/#26/#27):不创建订单、不支付、不锁库存。
  • Principal Memory 不进入远程上下文;Remote Content 不会直接成为 Principal Memory。
  • Remote Agent 不能获得任意本地工具能力;所有写入经策略门 + 审批。
  • 磋商期间不持久化模型 thinking;凭据按 scope 隔离,模型只见工具、永不见 token。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-ears 下一个 Next dsh-llm-fallbacks →