MyPanda-Hash/CHENGXIAO
Remote control between DeepSeek Harness machines: pair with a one-time code, run tasks and transfer files on the other machine - LAN direct or cross-network via an end-to-end-encrypted relay (official zero-config default). Files stay on each machine.
Project Overview项目介绍
dsh-peer-mcp is a native plugin for DSH (DeepSeek Harness) that lets two machines call each other as MCP tools while keeping each side's files, local models, and toolchain strictly local. It is installed with a single command, dsh plugin --profile <profile> add github:MyPanda-Hash/CHENGXIAO, which drops the package into the profile's node_modules/ and auto-registers it under dsh.profile.bundles in the profile's package.json. The shipped cordis.patch.yml ships with listen: false, so the plugin never exposes anything until the operator explicitly opts in via the profile overlay. Once paired, the initiator gains tools named mcp__<peer>__ask, __fetch_file, __send_file, __submit_task, __cancel_task, and the responder executes everything against its own local DSH, model, and filesystem.
The typical workflow is: on machine B open Settings → Device Interconnect, click "Generate pairing code", and copy a dshr://<relay>/<deviceId>/XXXXX-XXXXX link into machine A. Pairing performs a one-shot X25519 key exchange; the relay only sees opaque encrypted envelopes, never the pairing code, credentials, task bodies, or plaintext files, and it has no database. The default relay is a long-running systemd service on an Alibaba Cloud Ubuntu host at http://8.134.255.221:7332, exposing a GET /health endpoint and an optional in-memory offline TTL (DSH_RELAY_OFFLINE_TTL_MS). Same-LAN deployments can flip listen: true to switch to direct TCP, or self-host the relay with docker compose -f docker-compose.relay.yml up -d and point relayUrl at it.
The package is MIT licensed, requires Node.js plus a working dsh CLI, and bundles 259 offline node --test tests against a real Cordis host. Caveats to know on first run: ask is a cold-start invocation with no cross-call memory, so long jobs should use submit_task (returns a taskId in roughly 60 ms) and the SDK profile for true long-lived sessions; whole-file tools cap at 5 MiB while the chunked channel allows up to 100 MiB with per-block integrity checks; direct listen mode will not traverse NAT without a relay; on Windows the dsh shim is .cmd, which Node cannot spawn directly, so the plugin resolves the real binary itself. The repository also ships a standalone worker.mjs and peer.cmd so a peer machine can join without launching DSH Desktop, reusing the same ~/.dsh trust store.
dsh-peer-mcp 是面向 DSH(DeepSeek Harness)的原生插件,让两台机器上的 agent 互相调用、互相传文件,同时各自的文件、工具和模型都保留在本地。通过 dsh plugin --profile <profile> add github:MyPanda-Hash/CHENGXIAO 安装后,会写入 profile 下的 node_modules/ 并自动登记到 dsh.profile.bundles,但默认 listen: false,必须由操作者显式开启。该插件以 MCP server 形态挂入 DSH,发起端会看到 mcp__<对端名>__ask、__fetch_file、__send_file、__submit_task、__cancel_task 等工具,对端可继续使用自己的本地 DSH、模型与文件,仅把结论回传。
典型用法是用户在 A 机通过「生成配对码」产生 dshr:// 链接,粘贴到 B 机完成 X25519 配对,之后 A 机即可把 B 机当作工具调用。官方提供一台阿里云 Ubuntu 上的常驻中继 http://8.134.255.221:7332,双方都主动出站即可,跨 NAT 也无须入站端口;同一局域网可改走直连加速,也可用 docker compose 自托管中继并把 relayUrl 指向自建实例。仓库还附带独立的 worker.mjs 与 peer.cmd,让一端不开 DSH 也能以 node 进程接入,配对凭据复用同一份 ~/.dsh 信任库。
依赖 Node.js 与 dsh --profile headless/sdk 命令行;配对响应与全部消息走 X25519 派生会话密钥的 AES-256-GCM,中继只见密文、不持密钥、不落盘(可选 DSH_RELAY_OFFLINE_TTL_MS 内存暂存,上限 24 小时,官方中继设为 5 分钟)。ask 每次为冷启动、无跨调用记忆,长任务用 submit_task(约 60 ms 立即返回),整文件默认 5 MiB、大文件走分片通道上限 100 MiB;直连跨 NAT 不通。MIT 许可,259 项离线测试通过。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:CHENGXIAO(MyPanda-Hash/CHENGXIAO)
仓库:https://github.com/MyPanda-Hash/CHENGXIAO
本站详情页:https://www.yhbd.top/plugins/mypanda-hash-chengxiao/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-09-24 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:MyPanda-Hash/CHENGXIAO
把 MyPanda-Hash/CHENGXIAO 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-peer-mcp
用得顺手就点个 Star —— 市场搜索按星排序,一颗星直接决定别人能不能搜到它。
让两台电脑上的 DSH 互相干活、互相传文件 —— 而各自的文件始终留在本机。
不再用截图 + 模拟键盘去驱动另一台机器。装好这个插件后,A 机的 agent 可以把 B 机当成 工具来调:B 机用自己本地的文件、工具和模型执行任务,只把结论和文件回传。
┌─ A 机 ─────────────────────┐ ┌─ B 机 ──────────────────────┐
│ DSH │ │ 文件/仓库都在本地,不搬家 │
│ └ MCP 客户端 ─────────────┼── HTTPS ─┼─▶ dsh-peer-mcp │
│ mcp__<对端名>__ask │ 凭据 │ ├ ask → 本地 DSH │
│ mcp__<对端名>__fetch_file│ │ ├ fetch_file → 读本地 │
│ mcp__<对端名>__send_file │ │ └ send_file → 收文件 │
└────────────────────────────┘ └─────────────────────────────┘
安装
dsh plugin --profile <你的 profile> add github:MyPanda-Hash/CHENGXIAO
这一条命令就够了:它会把插件装进 profile 的 node_modules/,并自动注册到
dsh.profile.bundles(你可以打开 profile 的 package.json 确认)。
装完后安装本身不会对外暴露任何东西 —— 插件自带的 cordis.patch.yml 里 listen 默认是
false,必须由操作者显式开启。
快速开始(推荐:官方中继,装完即用)
两台电脑任何网络(同一局域网、不同网络均可)走官方中继,不需要 Tailscale、 不需要入站端口、不需要碰防火墙和路由器:
两台机器都在 profile 覆盖层(
~/.dsh/profiles/<你的 profile>/cordis.patch.yml) 写入并重启 DSH:- id: dsh-peer-mcp config: relayEnabled: true就这三行——不填
relayUrl时自动使用官方公共中继。干活端
设置 → 设备互联,确认「共享工作区」(默认%USERPROFILE%\DSH Workspace) 与能力权限摘要。点「生成配对码」,链接形如
dshr://<中继>/<设备ID>/XXXXX-XXXXX,交给发起端粘贴。配对完成,发起端立即多出
mcp__<干活端名>__ask/__submit_task/__fetch_file等工具——同一局域网时可改走直连(见下节),其余场景全部经中继。
官方中继(http://8.134.255.221:7332):一台阿里云 Ubuntu 上的常驻 systemd 服务,
只转发端到端加密信封——不持有密钥、不落盘、GET /health 可随时探活。不信任它或需要
内网封闭时,换成自托管中继(改一行 relayUrl),协议与体验完全一致。
局域网直连(可选,延迟更低)
两台机器在同一个局域网时可以把 listen 配成 true 走直连(同时保留中继做兜底),
其余流程不变;细节见下文「配置」。
中继(自托管与运维)
中继模式:双方都主动出站连接同一台中继服务器,不需要任何入站端口、端口映射或 防火墙配置。中继只转发端到端加密的信封,看不到配对码、凭据、任务内容或文件明文, 也不落盘。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
hanshanyike/dsh-yolo
Smalldy/godot-bridge
Angel2518975237/deepseek-harness-hello-kitty-suite
Oscar-Williams/dsh-deepcanary
wssfk12138/dsh-wechat-notify
ltao0829/dsh-task-notify
yeruizhi/dsh-lark-meeting-notifier