MeowTnT3r/catalog-capabilities-zh
一个面向 Codex 的公开 skill:编排当前 Agent 已有的可信安装器,并为 skills、插件和市场能力维护一份有来源依据的中文说明目录
Project Overview项目介绍
This tool is a Chinese-language capability catalog that supports both Codex and DeepSeek Harness (DSH). For Codex, you can install it by running npx skills@latest add https://github.com/MeowTnT3r/catalog-capabilities-zh --skill catalog-capabilities-zh directly in your terminal. For DSH, you can install it via the command dsh plugin --profile web add github:MeowTnT3r/catalog-capabilities-zh and restart dsh web after the installation completes. It does not handle downloading or installation logic itself; instead it calls existing trusted installers in your current environment to manage capabilities, only updating descriptions for already installed skills.
By default, the tool runs in curated mode, which means it will not automatically index every capability found in your working environment. On first run, it prompts you to choose whether you want to scan your existing environment as a discovery aid, or manually add the specific skill packages you want to learn more about. Only entries explicitly confirmed by you will be added to the generated documentation catalog. You can also use natural language to describe your needs, and the tool will filter matching capabilities and return key details like install status, appropriate use cases, and known limitations.
The project is released under the open-source MIT license, and only depends on Python 3.8 or newer, requiring no additional external packages beyond the Python standard library. For Python versions 3.8 through 3.10, the tool automatically uses the built-in TOML parser, so you do not need to upgrade to Python 3.11 to run it. Configuration files are stored in the appropriate system configuration directory by default, but you can override this path with the CAPABILITY_CATALOG_CONFIG environment variable. The tool follows strict security boundaries, only reading metadata and never executing untrusted external code.
这是一个同时面向Codex和DeepSeek Harness的中文能力目录工具,可为技能、插件和市场能力维护带来源依据的中文说明目录,同时支持在Codex以公开技能形式调用,在DSH作为bundle插件注册同名运行时技能,并切换CLI到DSH适配模式。它本身不提供下载安装逻辑,仅调用环境中已有的可信安装器完成操作,仅更新已有能力的说明。
默认启用精选模式,不会自动全量收录当前环境能力。首次运行时会询问用户,是选择扫描现有环境作为发现辅助,还是手动添加需要了解的技能包,仅收录用户确认的条目。支持用户使用自然语言描述需求,从已收录能力中筛选匹配项,返回其安装状态、适用场景和主要限制。
项目采用MIT开源许可协议,仅依赖Python 3.8+标准库,Python 3.8到3.10会自动使用内置TOML解析器,无需额外安装依赖。配置文件默认保存在系统对应配置目录,可通过环境变量自定义路径,不存储账号或令牌信息,严格遵循安全边界,仅读取元数据不执行外部未知代码。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:catalog-capabilities-zh(MeowTnT3r/catalog-capabilities-zh)
仓库:https://github.com/MeowTnT3r/catalog-capabilities-zh
本站详情页:https://www.yhbd.top/plugins/meowtnt3r-catalog-capabilities-zh/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-09-04 · 主语言 Python
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:MeowTnT3r/catalog-capabilities-zh
把 MeowTnT3r/catalog-capabilities-zh 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
catalog-capabilities-zh
一个面向 Codex 与 DeepSeek Harness 的公开能力目录:编排当前 Agent 已有的可信安装器,并为 skills、插件和市场能力维护一份有来源依据的中文说明目录。
- Codex:以
skills/catalog-capabilities-zh的公开 skill 形式使用。 - DeepSeek Harness:仓库根目录同时是一个 DSH bundle 插件,安装后注册同名 runtime skill,并把 CLI 切换为
--agent dsh适配器。
它不会自己重写下载或安装逻辑。明确要求安装时,它会调用当前环境已有的可信安装器(Codex 的 skill-installer / 插件管理能力,或 DSH 的 dsh plugin);目标已经安装时,只更新说明;只有链接而没有安装意图时,只做检查和介绍。
默认采用精选模式:不自动全量收录当前环境。技能会先问用户:是扫描现有环境作为“发现辅助”,还是手动喂入想了解的技能/技能包(本地目录、GitHub、npm 或直接粘贴内容);只有用户确认的条目才会进入文档。
安装
Codex
npx skills@latest add https://github.com/MeowTnT3r/catalog-capabilities-zh --skill catalog-capabilities-zh
也可以把 skills/catalog-capabilities-zh 复制到当前 Agent 的 skills 根目录。首次调用:
$catalog-capabilities-zh
DeepSeek Harness
要求 pnpm 在 PATH 上(dsh plugin 会转发给 pnpm):
dsh plugin --profile web add github:MeowTnT3r/catalog-capabilities-zh
安装后重启 dsh web。插件会注册名为 catalog-capabilities-zh 的 runtime skill;在会话里输入 $catalog-capabilities-zh,或直接用自然语言要求扫描、筛选或维护中文能力目录即可。插件内嵌的 Python CLI 仅需 Python 3.8+,且只使用标准库(Python 3.8–3.10 会自动使用内置 TOML 回退解析器,不要求安装 Python 3.11)。
Windows 本地路径包含空格时
DSH 0.1.0-rc.6 在 Windows 上转发本地文件参数时,包含空格的路径可能被拆成多个 pnpm 参数。项目位于这类路径时,不要使用 dsh plugin --profile web add .。先运行 npm pack,把生成的 .tgz 移到一个无空格路径,再安装该 tarball:
npm pack
# 将生成的 catalog-capabilities-zh-<version>.tgz 移到无空格路径后:
dsh plugin --profile web add C:\dsh-pack\catalog-capabilities-zh-1.0.0.tgz
GitHub、npm 包名以及本身不含空格的本地路径不受这个 rc.6 启动器问题影响。正式安装优先使用上面的 GitHub 命令。
扫描只作为发现辅助:技能会列出检测到的 skills、插件和市场路径,以及“技能包 → 子技能”的关系,用户挑选后再写入文档;render --all 或 --catalog-mode full 才是显式的全量收录。
生成的手册默认按“技能包”组织:每个技能包作为一条主条目并归入功能分类,包内子技能在包详情中列出;没有包概念的独立技能直接进入功能分类。每个条目都可以跳转到完整说明,技能较多时可以直接搜索中文名、原始名、标签、别名、使用范围或触发词。
筛选与查找技能
除了维护中文说明目录,这个 skill 也可以帮助用户从已经收录的能力中筛选合适的 skill、插件或市场能力。可以直接使用自然语言描述需求,例如:
$catalog-capabilities-zh 帮我筛选前端技能
$catalog-capabilities-zh 帮我找适合前端重构和 UI 设计的技能
$catalog-capabilities-zh 有哪些能力可以生成图片或处理 PDF?
$catalog-capabilities-zh 从现有技能里推荐几个适合调试复杂 Bug 的,并说明区别
筛选时会综合中文名称、原始标识、功能分类、标签、别名、使用范围、能力效果和典型触发词,并返回匹配项的安装状态、适用场景和主要限制。默认搜索“已选中的精选条目”;如果需要搜索全部扫描结果,使用 search <关键词> --all。筛选和推荐本身是只读操作;只有用户同时明确要求安装某个结果时,才会进入安装编排流程。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
freestylefly/awesome-gpt-image-2
leenkcool/Blue-Whale-Harness
Viy1204/recruiting-copilot
cheshireez/dsh-skill-hub
wingsky-1/dsh-plugin-hub