kedoupi/xiaotaozi-dsh
Xiaotaozi DSH: the xtz CLI as the user product, plus a shared DeepSeek Harness plugin layer.
catalog descriptioncatalog 简介 / catalog description:xiaotaozi-dsh:小桃子 DeepSeek Harness 插件与 Mac 客户端
Project Overview项目介绍
xiaotaozi-dsh is a product bundle built on top of DeepSeek Harness, where the xtz command shipped from apps/cli/ is the actual user-facing artifact, and the plugins/ tree is the capability layer it seeds on first launch. Installation is one of three equivalent routes: npm install -g xiaotaozi-dsh-cli, the curl | sh bootstrap, or bun add -g xiaotaozi-dsh-cli; xtz itself still runs on Node regardless of the package manager used to fetch it. The CLI pins @deepseek-ai/dsh@0.1.2-rc.1 and explicitly treats other Harness versions as out of scope.
On the first xtz start, the tool prepares the official web profile at ~/.dsh on port 3080 and seeds six first-party plugins in order: dsh-providers for vendor sign-in plus API keys, dsh-im for nine chat channels and an experimental AI Office connector, dsh-wecom-office driving calendar/docs/meetings through wecom-cli, dsh-xtz-ui for brand chrome and toggles, dsh-sidebar for the right-hand files-editor-Git-terminal panel, and dsh-market which hosts the Plugin Center UI plus the MARKET_PLUGINS catalog. The Plugin Center opens from the left rail under **New Session**, with Installed as the default tab and Discover pulling third-party rows such as Agent Teams, Session Context, and OpenContext directly from their upstream Git/npm sources — this repo never vendors those external packages.
The target audience is operators who want a guided, opinionated Harness deployment with chat-channel and WeCom/Feishu/Slack connectors and a built-in curated marketplace rather than a hand-rolled plugin set. Dependencies are Node ^22.19.0 || >=24.0.0 on PATH; license is MIT. First-run caveats: a welcome confirm opens Plugin Center → Installed → Models, runtime controls sit under Settings → Advanced, and a Loader inventory exists but is not a user settings page — run xtz doctor for diagnostics. By design, init, plugin, run/ask, config dump/defaults, and update are disabled, and xtz will not claim port 3080 or manage processes it did not start.
**xiaotaozi-dsh** 是基于 DeepSeek Harness 的产品化打包项目,核心交付物是 apps/cli/ 下的 xtz 命令行工具,用户通过 npm install -g xiaotaozi-dsh-cli 安装后执行 xtz start 启动。首次运行会自动写入官方 Web 配置(~/.dsh,端口 3080)并从 plugins/ 目录注入六款官方插件:Models、IM bots、WeCom office、Xiaotaozi 外观、Side workbench、Plugin Center。
项目配套的 dsh-market 插件承载 Plugin Center 的已安装与发现功能,"Discover plugins" 会从上游 Git/npm 拉取第三方插件,当前目录收录 Agent Teams、Session Context、OpenContext 三项,但本仓库仅保留 MARKET_PLUGINS 目录而不 vendoring 任何外部代码。
依赖与限制方面:要求 Node.js ^22.19.0 || >=24.0.0;CLI 固定 @deepseek-ai/dsh@0.1.2-rc.1,其它 DSH 版本不被视为兼容;License 为 MIT。xtz 仅管理自己启动的进程,永不抢占 3080 端口,init/plugin/run/ask/config/update 等命令被刻意禁用;插件开发须走 <repo>/.dsh-home 的 3081 沙箱。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:xiaotaozi-dsh(kedoupi/xiaotaozi-dsh)
仓库:https://github.com/kedoupi/xiaotaozi-dsh
本站详情页:https://www.yhbd.top/plugins/kedoupi-xiaotaozi-dsh/
本站登记:类型 client · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-11 · 主语言 TypeScript · 未检测到 DSH 插件清单
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
- No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
- Desktop client: installation downloads an executable - verify the publisher and checksums桌面客户端:安装会下载可执行文件,请核对发布者与校验和
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:kedoupi/xiaotaozi-dsh
把 kedoupi/xiaotaozi-dsh 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
xiaotaozi-dsh
Xiaotaozi DSH: the xtz CLI as the user product, plus a shared DeepSeek Harness plugin layer.
English · 中文 · Conventions · Workflow · DeepSeek Harness
Xiaotaozi DSH is a product bundle on DeepSeek Harness: the xtz command in apps/cli/ is what users install, and plugins/ is the capability layer it seeds. Something broken, or a plugin missing? Open an issue.
Quick start
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →






reactive-resume/reactive-resume
anywhere-labs/dsh-desktop
dataelement/dsh-desktop
ccch1mneyyy/dsh-TUI
DSH-EAC/DSH-Desktop-EAC
shaobeichen/dsh-pocket
xyTom/coding-tools-mcp