harrylabsj/kiwi
A2A commerce negotiation runtime + DeepSeek Harness (dsh) plugin. 安装 Kiwi,让 AI 买家找到你的商品、向你询价;库存、底价和客户数据仍留在你的系统中。
Project Overview项目介绍
Kiwi is an open-source A2A commerce negotiation protocol and standalone runtime that ships the KNP/1.0 specification, a dual-stack A2A client/server, UCP interop, signed identity, and safe handoff primitives. It runs as an independent CLI surface (kiwi, kiwi chat, kiwi agent serve, kiwi tui, kiwi demo) and also publishes an official DeepSeek Harness plugin, kiwi-dsh-plugin, installable via dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin, which lets a dsh session search listings, issue RFQs, and produce non-binding agreements directly. The project lives at harrylabsj/kiwi with 20 stars, is tagged dsh-plugin and a2a/commerce/cordis/mcp, and is licensed under Apache-2.0.
In the canonical workflow, a buyer agent and a merchant agent discover each other through Agent Cards and UCP profiles, intersect capabilities, and exchange KNP/1.0 Envelopes containing Inquiry, RFQ, Offer, CounterOffer, ConditionalOffer, Clarification, AcceptNonbinding, Withdraw, and AcceptedNonbindingAgreement objects. Negotiation terminates at a non-binding commercial agreement: no order is created, no payment is captured, and no inventory is reserved, while a separate operator-gated handoff bridges the agreement into a downstream checkout. The README ships kiwi demo [a|b] which boots a real kiwi-catalog plus three local merchants for deterministic end-to-end exercise, plus a TUI cockpit with supervised, manual, and autopilot modes. Target users are agent-platform integrators and protocol researchers who need auditable, side-effect-free inter-agent commerce rails.
Dependencies center on Node.js plus npm, with npm install, npm run build, npm test, and npm run verify covering lint, strict typecheck, full offline tests, and a production-bundle smoke. The kiwi demo flow additionally requires a runnable kiwi-catalog checkout (default ../kiwi-catalog, overridable via KIWI_CATALOG_DIR) and its Python environment; all traffic stays on loopback with ephemeral SQLite. For public-network merchant exposure the node refuses to start unless an inbound HttpMessageSignatureVerifier (RFC 9421 with content-digest binding) or an explicitly auditable reverse-proxy auth contract is wired in, otherwise LoopbackOnlyAuthVerifier would silently trust loopback-looking requests. The KNP/1.0 spec and JSON Schema are hosted at harrylabsj/kiwi-spec under Apache-2.0, mirroring the runtime license.
Kiwi 是一个开源的 A2A 电商磋商协议与独立运行时项目,提供 KNP/1.0 磋商规范、双栈 A2A 客户端/服务端、UCP 互操作、签名身份与安全交接能力。它同时支持作为独立 CLI 运行(kiwi、kiwi chat、kiwi agent serve、kiwi tui、kiwi demo),也提供面向 DeepSeek Harness 的官方插件 kiwi-dsh-plugin,可通过 dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin 挂载,使 dsh 会话直接搜索商品并发起非绑定磋商。
典型使用流程是:买家与商家作为独立 A2A Agent,通过 Agent Card 与 UCP Profile 完成发现,再以 KNP/1.0 Envelope 进行 capability 协商与多轮磋商,最终在非约束性商业协议处终止。kiwi demo 可一键启动 kiwi-catalog 与三个本地商家做确定性演示;TUI 还提供 supervised/manual/autopilot 三档操作者驾驶舱。它面向需要安全可审计的 agent 间商业磋商、又不愿承担订单与库存副作用的协议研究者和集成方。
依赖上,核心仓库以 Node.js 与 npm 为基础,npm install && npm run build && npm test 即可完成离线验证,演示需要外加一个可运行的 kiwi-catalog checkout。公网部署必须配置 HttpMessageSignatureVerifier 或明确的可审计代理认证,否则节点会因为认证前置条件缺失而启动失败;所有磋商均不创建订单、不支付、不锁库存,协议规范与 schema 公开以 Apache-2.0 托管于 harrylabsj/kiwi-spec。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:kiwi(harrylabsj/kiwi)
仓库:https://github.com/harrylabsj/kiwi
本站详情页:https://www.yhbd.top/plugins/harrylabsj-kiwi/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 20 · 最近提交 2026-10-01 · 主语言 TypeScript · 未检测到 DSH 插件清单
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 20 stars - an early-stage project星标 20,属于早期项目
- No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @harrylabsj/kiwi-dsh-plugin
把 harrylabsj/kiwi 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
Kiwi
A2A 电商磋商协议 + 独立运行时(KNP/1.0)。Buyer 与 Merchant 作为独立 A2A Agent,通过 A2A 与 UCP 完成发现 → capability 协商 → 磋商 → 非绑定协议。磋商以非约束性商业协议终止:不创建订单、不支付、不锁库存。
Kiwi 当前代码版本以 package.json 为准(当前 0.11.0):当前发布线包含 A2A 双栈、KNP/1.0 磋商、签名身份
与安全交接能力。A2A 1.0 线协议互操作以组合 conformance transcript 为准,不用历史审计
文档替代运行证据。
商家注册、一次连接确认和默认 20 个可配置商品名额的现行流程见 商家接入与商品名额设计 v0.6。
十种产品形态的版本来源、制品、平台审批状态和统一 release bundle 见Portfolio 发布管理与 portfolio-products.json。
协议:KNP/1.0
- 公开稳定 namespace:
com.harrylabsj.kiwi.shopping.negotiation - spec:https://kiwi.harrylabsj.com/a2a/extensions/negotiation/1.0
- schema:https://kiwi.harrylabsj.com/schemas/negotiation/1.0/schema.json
- 完整规范:
docs/protocol/kiwi-negotiation-protocol-1.0-rev1.4.md - 架构基线:
docs/kiwi-a2a-architecture-baseline-rev1.3.md
KNP/1.0 九类核心对象(Inquiry / RFQ / Offer / CounterOffer / ConditionalOffer / Clarification /
AcceptNonbinding / Withdraw/Decline/Cancel / AcceptedNonbindingAgreement)已冻结为 JSON Schema,
与领域实现交叉一致性对齐(contracts/negotiation/1.0/schema.json)。
架构
Buyer Agent ──A2A wire──▶ Merchant Agent
│ │
├─ Agent Card / UCP Profile │
├─ capability intersection │
├─ Negotiation Envelope │ (KNP/1.0 对象,JCS 规范化 digest)
├─ Ledger(append-only) │
├─ Idempotency / Recovery │
├─ ConditionalOffer 求值 │
└─ 非绑定协议 └─ 交易 handoff(agreement→checkout,operator 授权)
- 谈判领域:Envelope + 九类对象、条件确定性求值、Ledger(hash 链)、幂等、跨进程恢复、remote/local 对账。
- 原生 A2A:Agent Card、A2A client/server、Channel 抽象(direct / hosted)、Task 生命周期、消息签名。
- UCP 互操作:profile 模型/resolver、capability intersection、well-known 服务。
- 开放网络:trust records、fan-out 隐私 + 多商家 RFQ、服务端限流。
- 交易 handoff:agreement→checkout 桥、operator 门控授权、只读 order records。
边界与安全
- 磋商只形成非约束性共识(§41 #25/#26/#27):不创建订单、不支付、不锁库存。
- Principal Memory 不进入远程上下文;Remote Content 不会直接成为 Principal Memory。
- Remote Agent 不能获得任意本地工具能力;所有写入经策略门 + 审批。
- 磋商期间不持久化模型 thinking;凭据按 scope 隔离,模型只见工具、永不见 token。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
nocobase/nocobase
TencentCloudBase/CloudBase-AI-Toolkit
WYH66666666/DSH-Transparent-UI-Plugin
Nagi-ovo/dsh-visualize
SepineTam/mcp-for-stata
omdsh-dev/dsh-data-agent
morluto/jacobian
youdotcom-oss/agent-skills