ma-pony/deepspider 预览 preview

ma-pony/deepspider

AI 原生智能爬虫与 JavaScript 逆向工程平台,基于 DSH、Patchright/CDP 与独立语义运行时,从浏览器证据恢复参数生成逻辑并交付可验证 Solver。 | AI-native web scraping and JavaScript reverse-engineering platform powered by DSH, Patchright/CDP, and an independent semantic runtime—from browser evidence to recovered parameter-generation logic and verifiable Solvers.

Project Overview项目介绍

DeepSpider is an AI-native native plugin for DeepSeek Harness that provides smart crawling and JavaScript reverse engineering capabilities. To install it, you can either run npm install -g deepspider --legacy-peer-deps to get the full package, or add it directly to an existing DSH environment with dsh plugin --profile web add deepspider. It combines DSH Web, Patchright Chromium, Chrome DevTools Protocol, and an independent Node semantic runtime to build a complete reverse engineering workbench. All results are regenerated in a non-browser runtime and verified via real requests, rather than stopping at one-off crawl results.

It is built to help developers reverse engineer anti-bot protections on target websites, locate parameter generation logic from browser evidence, and build re-runnable solvers that can be verified against real requests. It can handle dynamic code execution, packed assets like Webpack bundles, Web Workers, WebAssembly, finite state machines, and heavily obfuscated source code. Instead of modifying captured source code directly, it uses hooks, debuggers, and attribute collection to gather accurate facts from the browser environment. It is intended for developers that need reliable, verifiable crawlers for websites with strict anti-crawling access controls.

DeepSpider requires Node.js 24.15.0 or newer, and a global installation will automatically download the required Patchright Chromium binary for browser-based evidence collection. As of the current release, only cookie generation is supported for end-to-end automatic semantic recovery. Headers, query parameters, request bodies, and navigation can still be collected as browser evidence but do not support automatic generation of fully reproducible output. It is released under the open source MIT license, and users are required to only analyze targets they have permission to access and comply with all applicable local laws.

DeepSpider 是一款为 DSH 打造的 AI 原生智能爬虫与 JavaScript 逆向工程平台。它整合了 DSH Web、Patchright Chromium、Chrome DevTools Protocol(CDP)与独立 Node 语义运行时,组成一套完整的逆向工作台。浏览器负责采集请求、脚本与运行时事实,最终结果会在非浏览器运行时重新生成,并通过真实请求验证。它可通过 npm 全局安装,也可直接作为 DSH 原生插件添加到 DSH web 配置文件中。

DeepSpider 核心能力是沿真实请求的发起方、调用栈和脚本源码定位参数写入边界,可分析动态执行、Webpack、Worker、WebAssembly、状态机和高度混淆的代码。它通过钩子、调试器和属性采集补充浏览器事实,不会直接修改捕获的源码。它面向需要爬取带有反爬机制网站的开发者,尤其适合需要生成可验证、可重复运行求解器的场景。

DeepSpider 需要 Node.js 版本不低于 24.15.0,全局安装时会自动下载 Patchright Chromium。当前版本仅支持 Cookie 的自动语义恢复,请求头、查询参数、请求体等内容仍可作为证据收集,但不支持自动生成可复现结果。它以 MIT 许可证开源,用户需要确保对目标网站的爬取获得授权,并遵守相关法律法规。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • 20 stars - an early-stage project星标 20,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add deepspider

把 ma-pony/deepspider 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DeepSpider

npm version License: MIT

AI 原生的智能爬虫与 JavaScript 逆向工程平台——基于 DSH、Patchright/CDP 与独立语义运行时,从浏览器证据恢复参数生成逻辑,并交付经过真实请求验证的可运行 Solver。

DeepSpider 将 DSH Web、Patchright Chromium、Chrome DevTools Protocol(CDP)和独立 Node 语义运行时组合成一套逆向工作台。浏览器负责采集请求、脚本与运行时事实;最终结果必须由非浏览器运行时重新生成,并通过真实请求验证,而不是停留在页面自动化或一次抓取结果。

English

快速开始

需要 Node.js >=24.15.0。全局安装会下载 Patchright Chromium。

npm install -g deepspider --legacy-peer-deps
deepspider agent

DSH 当前预发布包的 peer 依赖范围会让 npm 默认求解器进行大量无效回溯,因此全局安装与 deepspider update 统一使用 --legacy-peer-deps。这只影响依赖树求解,不会跳过安装脚本或运行时校验。

deepspider 同时发布为原生 DSH Bundle。主启动命令会通过 DSH Profile 管理器将它挂载到 web Profile;已有 DSH 环境也可以直接安装:

dsh plugin --profile web add deepspider
dsh web

这是主启动命令。DSH Web 会加载 Spider Preset;新建一个 Session,说明目标 URL、触发路径和目标输出。首版自动语义恢复只支持 Cookie。Header、Query、Body、返回值和导航仍可作为浏览器证据、Output Contract 和手工分析目标,但当前不会由高层工具自动生成 reproduced 结果或 Solver。多个 Session 可以同时运行,各自持有独立浏览器、SessionArtifactStore、Worker 和产物目录。

Ctrl+C 会关闭 DSH Web,并等待所有 Session 的 Patchright Chromium、sdenv Worker 和运行资源退出。

DeepSpider 解决什么问题

  • 沿真实请求的 Initiator、调用栈和脚本源码定位参数写入边界。
  • 分析动态执行、Webpack、Worker、WebAssembly、状态机和高度混淆代码。
  • 用 Hook、Debugger 和属性采集补足浏览器事实,而不是直接修改捕获源码。
  • 将 Cookie 生成所需的浏览器依赖描述成可审计的 Runtime Recipe,再由独立 Worker 执行。
  • 用真实请求验证自动生成的 Cookie,并导出可以脱离浏览器 Session 重跑的 Solver;其他输出继续使用通用浏览器、Hook、Debugger 和 Code Mode 定位与实现。

唯一完成定义

对于当前自动支持的 Cookie 恢复,只有以下链路全部成立才算完成:Browser Oracle 已保存目标证据;Output Contract 与 Runtime Recipe 已绑定当前 Session;独立 sdenv Worker 用全新状态生成 Cookie;CycleTLS 仅使用这些生成值完成真实请求;验证等级为 reproduced;导出的 Solver 能在浏览器关闭后再次得到同一验收结果。

浏览器结果、页面自动化脚本、捕获 Cookie、单次 Hook 日志或仅能回放的请求都不是完成证据。

输出驱动的语义恢复

Browser Oracle → Session Artifact Graph → Output Contract → Runtime Recipe
               → sdenv Worker → Real-request Validation → Solver
阶段 作用 边界
Browser Oracle 用 Patchright Chromium + CDP 观察真实页面、请求、脚本和运行时事实 浏览器最终值只形成 observed 证据
Session Artifact Graph 关联 Document、Script、动态源码、请求、响应及后续恢复产物 原始内容不可覆盖,所有节点属于当前 Session
Output Contract 定义要生成的输出和请求成功条件 只恢复影响目标输出的语义
Runtime Recipe 声明固定值、属性隐藏、window proxy、UA、TLS 与超时 站点规则留在 Session Recipe,不进入通用底层分支
sdenv Worker 在独立 Node 子进程和全新 Cookie Jar 中执行页面语义 不读取 Patchright 最终输出或 browser-data/
Request Validation 仅用 Worker 生成值发起真实请求 状态与内容条件同时通过才是 reproduced
Solver 导出 Contract、Recipe 与独立入口 浏览器关闭后仍能重新生成并验证

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-llm-fallbacks 下一个 Next dsh-tavern →