LeemanCheung/dsh-skin-studio 预览 preview

LeemanCheung/dsh-skin-studio

本地安全令牌的DSH主题生成器、编辑器、审计器和导出器

Project Overview项目介绍

dsh-skin-studio is a local-first DSH Skin Studio for creating, auditing, previewing, persisting, importing, and exporting semantic --dsw-alias-* light/dark themes. It offers token editing, image palette sampling, WCAG AA checks, locks, undo/redo, and strict .dshskin JSON. Use it when customizing or sharing DSH themes. Caveat: imports are parsed as validated JSON only, and Host remotes trust clients in the same DSH Web composition rather than providing an authorization boundary.

dsh-skin-studio 是本地优先的 DSH 皮肤工作室,可在设置页编辑、审计、预览、保存并导入导出 --dsw-alias-* 明暗主题;支持图片取色、WCAG AA 检查、锁定令牌、撤销重做和 .dshskin JSON。需要定制或分享 DSH 主题时使用。注意:导入仅解析受校验 JSON,远程 CRUD 面向同一可信 DSH Web 组合,并非授权边界。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:LeemanCheung/dsh-skin-studio

把 LeemanCheung/dsh-skin-studio 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-skin-studio

English | 中文

A local-first DSH Skin Studio for creating, auditing, previewing, persisting, importing, and exporting semantic --dsw-alias-* light/dark themes.

Compatible with DeepSeek Harness 0.1.2-rc.1; its Client bundle uses the current Cordis context, UI renderer, Settings, Theme, and Remote contracts. The verified Windows interface results are recorded in Windows DSH 0.1.2 acceptance.

Screenshot

Skin Studio token editor and preview

Generated with GPT Image from the implemented Client layout and feature set; runtime appearance follows the active DSH theme and viewport.

Features

  • Settings → Skin Studio responsive library, semantic-token editor, and dual light/dark preview with six presets, locks, undo/redo, delete confirmation, and manual colour controls.
  • PNG/JPEG/WebP palette sampling bounded to 10 MB and 40 megapixels, with 128px downsampling and up to six selectable OKLab k-means swatches; automatic derivation always preserves locked tokens.
  • WCAG AA audit for body, secondary, and brand-button pairs, with correction of unlocked derived tokens, including white text that must move darker.
  • Durable Host CRUD and active-skin state through storageDomain and generated Typert Remotes; Save & Apply persists the current draft before replacing the reversible override.
  • Strict .dshskin JSON export/import, Stop Preview, generated Client entry source with a declared theme dependency, and a local PNG share card.

Data and security

dshskin/v1 accepts at most 100 KB, 128 semantic tokens, strict metadata, six-digit hex colours, unique locks that refer to existing tokens, and requires the current DSH core background, label, brand, and border tokens. Import parses plain JSON, refuses to overwrite an existing skin with the same id, and rejects unknown fields, prototype keys, deep or oversized values, invalid token names, scripts, CSS selectors, URLs, imports, expressions, and external fonts. Imported data is never executed.

Typert Remote methods are intended for clients mounted in the same trusted DSH Web composition. They are not an authorization layer for untrusted browser plugins.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-lived-pet 下一个 Next dsh-compact-provider →