HuanLinOTO/dsh-plugin-anti-ads
DSH Web 广告拦截器,四层独立防御拦截 dsh-ads 插件的所有广告位
Project Overview项目介绍
This is a DSH-native ad-blocking plugin built exclusively to block ads served by the dsh-ads plugin for the DSH Web UI. You can install it via DSH’s command line interface, either from the official npm registry using the command dsh plugin --profile web add @huanlin/dsh-plugin-anti-ads, or from a local cloned repository for development. After installation, the plugin automatically inserts the required configuration, so you don’t need to edit any config files manually. It only takes effect if you already have the dsh-ads plugin installed on your DSH instance.
It features four independent layers of defense that can each be toggled on or off individually, and each layer works even if other layers fail. Layers include writing ad settings to disable all ads via dsh-ads’ storage contract, cleaning up leftover ad DOM elements, blocking requests for ad registry data, and broadcasting a built-in close-all event that hides the entire ad module. After installation, a small badge showing the number of blocked ads appears in the lower right corner of the DSH UI, and you can click it to adjust plugin settings.
The plugin has no runtime dependencies, and pre-built artifacts are included in the repository, so you don’t need to run a build step after installation. There is a full test suite included with 54 test cases across three specs that check core functionality like shape matching, protocol compliance, and full layered behavior. A known limitation is that if you manually enable an ad slot from dsh-ads’ own settings page, the first layer of defense will not take effect until the next page refresh, though other layers will still work to block most ads.
这是一款专为DSH设计的原生插件,专门用于拦截dsh-ads插件展示的所有广告内容。它实现了四层独立可单独开关的防御机制,分别是设置写穿、兜底清理、屏蔽动态广告源和深层拦截,各层互不依赖,任意一层失效后其余层仍可正常工作。拦截状态默认开启,设置会跨页面刷新保持生效,关闭插件可一键恢复dsh-ads的默认设置。
你可以通过DSH的CLI命令从npm或本地开发分支安装本插件,安装完成后无需手动修改配置,工具会自动插入对应配置项。只有预先安装了dsh-ads插件,本插件才会生效,页面右下角会显示带有拦截计数的「广告已拦截」徽章,点击徽章可以查看或修改拦截设置,未安装dsh-ads时插件不会显示内容也没有任何效果。
本插件无运行时依赖,构建产物已经随仓库分发,无需额外执行构建步骤即可使用。已知限制为:如果用户在dsh-ads自身的设置页手动开启了某广告位,第一层拦截需要等到下次页面刷新才会重新生效,期间由其他层级兜底,只有对话内信息流广告可能短暂可见。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugin-anti-ads(HuanLinOTO/dsh-plugin-anti-ads)
仓库:https://github.com/HuanLinOTO/dsh-plugin-anti-ads
本站详情页:https://www.yhbd.top/plugins/huanlinoto-dsh-plugin-anti-ads/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 NOASSERTION · ⭐ 10 · 最近提交 2026-09-01 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 10 stars - an early-stage project星标 10,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @huanlin/dsh-plugin-anti-ads
把 HuanLinOTO/dsh-plugin-anti-ads 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-anti-ads
给 DSH Web UI 安装的广告拦截器——拦截对象只有 dsh-ads 一个。右下角一枚小徽章,广告没了,徽章记着拦掉了几个弹层。
它是怎么拦的
四层防御,独立工作、可单独开关:
| 层 | 机制 | 关什么 |
|---|---|---|
| L1 设置写穿 | 通过 dsh-ads 自身的存储契约(localStorage['dsh-ads:settings'] + dsh-ads:persist-changed 事件)把所有广告位开关写成关闭,并监听 dsh-ads 的广播持续压制 |
两侧广告栏、对话内信息流、右下角弹窗、跑分、安全告警、贪玩蓝鲸海报 |
| L2 兜底清理 | MutationObserver 监听页面变化,按形状(position:fixed + dsh-ads 的 z-index 区间,或全屏穿透遮罩层)识别并移除漏网弹层 |
dsh-ads 未来版本绕过设置新增的广告位、改版后的根浮层 |
| L3 屏蔽动态广告源 | 对 /dsh-ads/registry.json 的请求(含带 query 的变体)直接返回空列表 |
社区插件的自动横幅 |
| L4 深层拦截 | 广播 dsh-ads 自身的 dsh-ads:retired 事件——它的「关闭所有广告」是模块级一次性开关,广告层在渲染前就检查这个标志,广播后整层隐藏到刷新 |
无视自身设置开关、任何新加广告位的 dsh-ads 版本 |
四层都不依赖对方:L1 失效时 L2/L3/L4 还在;关掉 L4,L1/L2/L3 照常跑。
持久化:拦截状态默认开启,跨刷新持续生效。「启用拦截」开关在设置页和徽章面板里;关掉它等于「恢复广告」——会同时把 dsh-ads 的设置恢复为默认。注意:L4 广播的「本次关闭」是 dsh-ads 刻意做成不可撤销的,若已广播过,广告层要刷新页面才会回来。
一个已知边界:dsh-ads 的持久化层有内存镜像,用户若在 dsh-ads 自己的设置页手动打开过某个广告位,L1 要到下次刷新才重新生效;期间由 L2 兜底清理浮层,L4 的广播也能把整个层压下去,对话内信息流广告(无 DOM 特征,只能靠 L1)可能短暂可见。
安装
构建产物随仓库分发(lib/ 已提交),无 install、无 build、无运行时依赖:
# 从 npm 安装(推荐):
dsh plugin --profile web add @huanlin/dsh-plugin-anti-ads
# 从本地 clone 开发安装:
dsh plugin --profile web add link:/path/to/dsh-anti-ads
# 重启 dsh web,刷新页面
配置行由 bundle patch 自动插入,无需手动编辑 cordis.patch.yml。
先装 dsh-ads 才有东西可拦。装了之后:右下角出现「🛡 广告已拦截」徽章,点击可查看/修改拦截设置。dsh-ads 未安装时本插件无任何效果(徽章不出现)。
开发
pnpm install # devDeps 用 link: 指向本机 ~/.dsh/source/current
pnpm run typecheck # 类型门禁(tsconfig.json + tsconfig.client.json)
pnpm test # vitest 全量(3 个 spec,54 个用例)
pnpm run build # tsdown 双 bundle:lib/index.js(node stub)+ lib/client.js(浏览器半)
每次改动源码后跑 pnpm run check(typecheck + test + build 三件套)。
结构
src/
├── index.ts # node 半:stub,仅占 main 位置
└── client/
├── index.tsx # apply:注册 conversation.input.dock(order 100,晚于 dsh-ads 的 90)+ settings.section
├── AntiAdLayer.tsx # 四层防御组装 + 徽章/面板 UI;关闭主开关时恢复 dsh-ads 默认
├── AntiAdsSection.tsx# 设置页(设置对话框里)
├── settings.ts # 写穿协议:dsh-ads:settings key、persist-changed 事件、retired 事件、ADS_ALL_OFF、useAdsGuard
├── persist.ts # 本插件自己的持久化(dsh-anti-ads: 前缀,独立事件总线)
└── scrub.ts # L2:根 portal / 独立弹层 / 全屏遮罩的形状匹配 + 清理
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest
saya-ch/dsh-mobile