memories-coder/DSH-plugin-android-apk
使用DSH帮助你构建APK
Project Overview项目介绍
dsh-plugin-android-apk is a JavaScript-based DSH-native plugin published as a tarball and installed into a chosen profile via dsh plugin --profile <profile> add "<path>/dsh-plugin-android-apk-0.2.4.tgz, which requires pnpm on PATH and a DSH restart before the new tool appears. It registers itself as a Cordis bundle (cordis.patch.yml adds the android-apk-builder row, package.json declares dsh.bundle.patch) and relies on three peer dependencies — @deepseek-ai/cordis, @deepseek-ai/dsh-tools, and @deepseek-ai/schemastery — that the DSH host resolves itself; manually adding them with pnpm add inside ~/.dsh/profiles/<profile> will shadow the host's own dsh-tools row and break profile activation, a documented regression from versions ≤0.2.0.
The intended workflow is to ask the running agent to "build the xxx folder into an APK" or to call build_android_apk(project="myapp", variant="debug", clean=false) directly; the tool detects AGP and Gradle versions from the project, chooses a JDK major (17 for AGP 8 / Gradle 8, otherwise 11), downloads Temurin JDK, Android SDK components, and Gradle if absent, runs assemble<Variant>, then copies produced APKs into apkOutputDir and returns apks[], logTail, and durationMs. It targets Android developers who want APK builds inside a DSH session — for quick local debugs, release packaging, or unconventional hosts such as Termux on aarch64 Android 15, which the maintainers verified end-to-end producing real APKs with classes.dex and AndroidManifest.xml.
The first build pulls roughly 460 MB into <plugin-dir>/toolchain (JDK ~180 MB, cmdline-tools ~150 MB, Gradle ~130 MB); Gradle's GRADLE_USER_HOME cache lives there too, so every session and project share one toolchain instead of leaving hundreds of megabytes in each workspace. Default download sources are api.adoptium.net, services.gradle.org, and dl.google.com, with automatic fallback mirrors mirrors.tuna.tsinghua.edu.cn/Adoptium, mirrors.cloud.tencent.com/gradle and mirrors.aliyun.com, mirrors.cloud.tencent.com/AndroidSDK; when upstream checksums are reachable they are verified via SHA-256 (Adoptium, Gradle) or SHA-1/SHA-256 (Google XML), otherwise the download proceeds without blocking. Projects whose paths contain non-ASCII characters are staged into %TEMP%\dsh-android-build to work around AAPT2 failures on Windows, the staged SDK is cached, signing and resource preparation remain the user's responsibility, and the package is MIT-licensed using only Node built-in modules.
dsh-plugin-android-apk 是一个 DSH 原生插件,使用 JavaScript 编写,通过 dsh plugin --profile <profile> add 命令以 tarball 形式装入指定 profile,重启 DSH 后即可调用 build_android_apk 工具。它以 Cordis 插件形式接入 DSH 宿主环境,依赖由宿主提供的 @deepseek-ai/cordis、@deepseek-ai/dsh-tools、@deepseek-ai/schemastery 三个 peer 依赖,并声明了 dsh.bundle.patch 以便 profile 层识别。
插件面向希望在 DSH 会话里直接让 Agent 把现有安卓工程编译成 APK 的开发者,使用时只需对 Agent 说"把 xxx 文件夹构建成 APK",或显式调用 build_android_apk(project, variant, clean)。它会自动探测 AGP/Gradle 版本以决定 JDK 大版本,下载 Temurin JDK、Android SDK(cmdline-tools + platform-tools + build-tools + platform)、Gradle 发行版,运行 assemble<Variant>,并把产物 APK 复制到 apkOutputDir。典型场景包括调试本地工程、跨平台 CI、出包归档,以及在 Termux 等非桌面宿主上构建。
首次运行会下载约 460MB 的 JDK + SDK + Gradle,全部缓存在 <插件目录>/toolchain,可由 downloadDir 或 cordis.patch.yml 的 downloadRoot 覆盖以跨版本存活。包含非 ASCII 路径时自动 staging 到 %TEMP%\dsh-android-build 构建,签名/资源需用户自备。JDK/Gradle/SDK 默认源分别为 Adoptium、services.gradle.org、dl.google.com,并在国内网络下回退到清华、腾讯、阿里镜像。依赖以 peer 声明,禁止在 profile 里手动 pnpm add @deepseek-ai/*。插件以 MIT 协议发布,仅依赖 Node 内置模块。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:DSH-plugin-android-apk(memories-coder/DSH-plugin-android-apk)
仓库:https://github.com/memories-coder/DSH-plugin-android-apk
本站详情页:https://www.yhbd.top/plugins/memories-coder-dsh-plugin-android-apk/
本站登记:类型 client · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-10-01 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:memories-coder/DSH-plugin-android-apk
把 memories-coder/DSH-plugin-android-apk 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugin-android-apk
DeepSeek Harness (DSH) 插件:把一个安卓项目文件夹直接构建成 APK。 缺少的工具链(JDK / Android SDK / Gradle)会自动下载到工作文件夹内,不污染用户目录。
更新记录见 CHANGELOG.md。
功能
- 识别 Gradle 安卓工程(
settings.gradle/settings.gradle.kts/build.gradle),可选支持 Gradle Wrapper。 - 自动准备工具链:
- JDK:系统
JAVA_HOME/PATH里有满足要求的 Java(AGP 8 / Gradle 8 需要 ≥17,否则 ≥11,插件会先探测工程里的 AGP 版本)就直接用;否则按当前系统与架构下载对应的 Temurin JDK(Windows/Linux/macOS × x64/aarch64…,Windows 取.zip、其它取.tar.gz)到下载文件夹,并复用上次下载的 JDK,不重复下载。若请求的版本在该平台没有官方构建(例如 Temurin 没有 windows/aarch64 的 JDK 17),会自动沿 LTS 阶梯回退到有构建的版本(17 → 21 → 25)并在日志里说明原因。 - Android SDK:依次检查
local.properties的sdk.dir、ANDROID_HOME、ANDROID_SDK_ROOT、%LOCALAPPDATA%\Android\Sdk;都没有则下载 commandline-tools + platform-tools + build-tools + platform 到下载文件夹,并自动写入local.properties和接受许可。local.properties里失效的sdk.dir(指向已删除的 SDK)会被自动修正。 - Gradle:工程带可用 Wrapper 就用 Wrapper(若 Wrapper 的 Gradle 版本无法在当前 JDK 上运行,例如 Gradle 7.0 配 Java 17,则自动改为下载发行版);否则按
gradle-wrapper.properties里的版本(或配置的gradleVersion)下载发行版。
- JDK:系统
- 运行
assemble<Variant>(默认debug,可用release),把产物 APK 复制到输出文件夹。 - 非 ASCII 路径自动处理:当工程或 SDK 目录路径含有非 ASCII 字符(例如中文路径,AAPT2 在 Windows 上会因此无法读取
android.jar)时,自动把工程和 SDK 复制到一个可用的 ASCII 临时目录(%TEMP%\dsh-android-build)里构建,再把 APK 复制回你的输出文件夹。staged SDK 会缓存复用,不重复下载。 - 所有下载、Gradle 发行版、依赖缓存(
GRADLE_USER_HOME)都放在插件自己的toolchain/目录(<插件安装目录>/toolchain,可用downloadDir覆盖)。放在插件根目录意味着所有会话、所有工程共用同一套工具链——不会每个工作区各留一份几百 MB 的缓存,也不污染用户目录。
安装
在 DSH 宿主机器上(需要 pnpm 在 PATH 上)。把 <插件路径> 换成这个 tarball 在你机器上的实际位置,
<profile> 换成你要装的 profile 名:
dsh plugin --profile <profile> add "<插件路径>/dsh-plugin-android-apk-0.2.4.tgz"
<profile>填什么? 桌面端常见的是desktop,Web 端常见的是web,但名字由你自己决定, 取决于当前跑的是哪个 profile——填错不会报错,只是"装到另一个 profile 去了",当前会话看不到这个工具。 查看本机有哪些 profile:ls ~/.dsh/profiles(Windows:dir %USERPROFILE%\.dsh\profiles)。 想知道当前会话用的是哪个,可在任务管理器里看 DSH 主进程的命令行,末尾那个路径就是...\.dsh\profiles\<名字>。插件与 profile 无关:
cordis.patch.yml按包名插入一行插件,代码里没有写死任何 profile 名, 所以desktop/web/ 自定义 profile 都同样可用。唯一的差别是每个 profile 要各装一次—— 它属于 profile 级依赖;如果你同时用桌面端和 Web 端(通常就是两个 profile),两边都装才会都出现。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
reactive-resume/reactive-resume
anywhere-labs/dsh-desktop
dataelement/dsh-desktop
ccch1mneyyy/dsh-TUI
DSH-EAC/DSH-Desktop-EAC
shaobeichen/dsh-pocket
xyTom/coding-tools-mcp