hinayoung23/dsh-cordis-plugin-kit
Offline Cordis/DSH plugin standards, scaffolding, static checks, runtime debugging, and performance gates.
Project Overview项目介绍
This repository is a native DSH plugin that delivers offline development specifications, project scaffolding, and quality gate tooling for DeepSeek Harness and Cordis plugin development. It runs entirely offline without requiring any network access to check your code. It codifies common development conventions and Cordis-specific rules for lifecycle management, dependency injection, services, events, configuration, and hot module replacement into executable, offline checks. This eliminates the need for developers to repeatedly look up online documentation every time they start a new plugin project. The current supported compatible versions are DeepSeek Harness 0.1.2-rc.1 and @deepseek-ai/cordis 4.0.2.
The tool includes 35 pre-built offline development standards for Cordis, DSH, Node.js, and automation workflows. It supports GitHub, GitLab, Gitee, and any generic Node.js CI pipeline out of the box. It can scaffold a new DSH plugin project with an installable bundle, lifecycle tests, performance budgets, Git hooks, and CI configuration files for multiple platforms. It supports static analysis that does not execute any target plugin code, along with performance testing that measures p50/p95 load latency and heap growth. Quality gates are automatically triggered at every key development milestone, from file save through to package publishing.
You can install this tool as a development dependency via npm, pnpm, or Yarn, or install it directly as a DSH bundle into your DeepSeek Harness instance via the DSH CLI. The tool has zero production dependencies, and its continuous integration test suite covers Node.js 22 and 24 on both Windows and Linux platforms. To use the provided Git hooks on Windows, you must first install Git for Windows on your system. This project is released under the permissive MIT open source license, so it can be used freely for both personal and commercial development projects.
这是一款面向 DeepSeek Harness/Cordis 插件开发的原生 DSH 工具,提供离线规范、项目脚手架与质量检查门禁工具。它将常用开发约定,以及 Cordis 特有的生命周期、依赖注入、服务、事件、配置和热更新规则固化为可执行检查,避免开发者每次开发都重新查阅在线文档。当前兼容基线为 DeepSeek Harness 0.1.2-rc.1、@deepseek-ai/cordis 4.0.2。
它内置35条离线 Cordis/DSH/Node.js 开发规范,可生成可安装的 DSH bundle、生命周期测试、质量预算、Git 钩子和 CI 适配文件,提供不执行代码的静态检查,支持性能测试和加载延迟测量,在开发、提交、推送、打包等全流程提供质量管控。它支持 GitHub、GitLab、Gitee 等多种平台的 CI 适配,也可适配任意支持 Node.js 的自定义流水线。
它可作为开发依赖安装到项目,也可作为 DSH bundle 直接安装到 DSH 中。工具零生产依赖,CI 覆盖 Windows/Linux 平台的 Node.js 22/24 版本,Windows 环境下使用 Git 钩子需要提前安装 Git for Windows。本项目使用 MIT 许可证开源,可免费供个人和商业项目使用。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-cordis-plugin-kit(hinayoung23/dsh-cordis-plugin-kit)
仓库:https://github.com/hinayoung23/dsh-cordis-plugin-kit
本站详情页:https://www.yhbd.top/plugins/hinayoung23-dsh-cordis-plugin-kit/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-05 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-cordis-plugin-kit
把 hinayoung23/dsh-cordis-plugin-kit 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH Cordis Plugin Kit
中文
面向 DeepSeek Harness/Cordis 插件开发的离线规范、脚手架与质量门工具。它把常用开发约定和 Cordis 特有的生命周期、依赖注入、服务、事件、配置及 HMR 规则固化为可执行检查,避免每次开发都重新查阅在线教程。
质量门可以发现已知模式和回归,但任何静态或动态工具都不能数学上保证代码绝无功能、性能或安全问题。高风险插件仍需要人工审查、真实依赖集成测试和针对业务的威胁建模。
当前兼容基线:DeepSeek Harness 0.1.2-rc.1、@deepseek-ai/cordis 4.0.2。
0.2.1 修复 Windows 下 npm/pnpm/yarn 的 .cmd 启动问题及超时后的子进程清理;生成项目支持含空格和中文的路径,Git hooks 由 Git 执行并保留 LF 换行。CI 覆盖 Windows/Linux、Node.js 22/24;本包没有新增生产依赖。Windows 使用 Git hooks 需要安装 Git for Windows。运行时检查仍需要目标项目安装 @deepseek-ai/cordis 开发依赖。
功能
- 内置 35 条离线 Cordis/DSH/Node.js/自动化规范,可按分类或 JSON 输出
- 生成可安装 DSH bundle、生命周期测试、质量预算、Git hooks、代理指令和 CI 适配文件
- 不执行代码的静态检查:manifest、bundle patch、inject、effect、Config、事件、工具契约、秘密和危险 API
- 使用项目原有包管理器执行测试,并提供超时与输出上限
- 在隔离子进程中使用目标项目的真实 Cordis 版本执行
apply/dispose - 重复加载与卸载,测量 p50/p95 延迟及堆增长,按项目预算阻断交付
- 保存时执行防抖快速检查,提交/推送/打包时自动升级质量门;开发监听器只随
pnpm dev运行,不安装系统常驻进程 - 统一
ci核心兼容 GitHub、GitLab、Gitee 及任意可运行 Node.js 的流水线 - 安装到 DSH 后提供
ctx.cordisPluginKit规范、静态检查和显式质量门服务 - 零生产依赖
安装
作为开发工具安装:
pnpm add -D dsh-cordis-plugin-kit
作为 DSH bundle 安装:
dsh plugin --profile web add dsh-cordis-plugin-kit
快速开始
npx dsh-cordis-plugin-kit init ./my-cordis-plugin --name my-cordis-plugin --ci auto
cd my-cordis-plugin
pnpm install
pnpm check
pnpm dev
init 默认使用 balanced 自动化模式:创建本地 Git 仓库,配置版本库级 core.hooksPath=.githooks,生成 AGENTS.md,并根据 Git remote、现有流水线或 package.json.repository 选择 CI。不会修改全局 Git 配置。目标已设置其他 hooksPath 或已有 CI 文件时会保留原内容并给出合并提示。
自动工作流
| 关键节点 | 触发方式 | 检查内容 |
|---|---|---|
| 保存 | pnpm dev 文件监听,或 DSH/Codex 按 AGENTS.md 调用 |
静态、Cordis 规则、安全模式 |
| 提交 | Git pre-commit hook |
严格静态检查、单元测试 |
| 推送 | Git pre-push hook |
严格检查、测试、真实 Cordis apply/dispose |
| 打包 | npm/pnpm prepack |
完整运行时与性能门;避免递归打包 |
| push / PR / MR | 托管平台流水线 | 测试、运行时、性能、安全和包内容复核 |
检查结果统一写入 .cordis-kit/reports/:result.json、junit.xml、security.sarif 和 summary.md。失败时所有平台使用同一个非零退出码语义。
监听器不是后台服务。它只在显式运行 pnpm dev / dsh-cordis-kit watch . 时存在,退出终端即停止。即使未启动监听器,Git hooks 和远端 CI 仍是不可绕过的后续质量门。
已有项目可以直接检查:
npx dsh-cordis-plugin-kit standards
npx dsh-cordis-plugin-kit check . --strict
npx dsh-cordis-plugin-kit test . --timeout 60000
npx dsh-cordis-plugin-kit debug . --provide tools,systemPrompt
npx dsh-cordis-plugin-kit perf . --iterations 50 --max-apply-ms 80
npx dsh-cordis-plugin-kit checkpoint pre-push .
npx dsh-cordis-plugin-kit ci .
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
esengine/DeepSeek-Reasonix
strukto-ai/mirage
chuspeeism/dashi-taskboard
Aisland-SJL/dsh-worktable
ccch1mneyyy/working-activity
zhoushoujianwork/easyeda-agent
pulseaiclub/phi
Ikalus1988/MisakaNet