omdsh-dev/dsh-inspect
发现问题(checkup) → 修复交付(fix) → 质量复查(review) 的对抗式闭环插件:基于官方 workflow 引擎的检查/修复/复查工具集
Project Overview项目介绍
dsh-inspect is a quality assurance plugin built exclusively for DeepSeek Harness (DSH) that ships with a native DSH cordis manifest and patch. It adds three connected tools to the DSH ecosystem: checkup for finding issues, fix for implementing resolutions, and review for validating completed fixes. It follows a cybernetic feedback framework that enforces adversarial checking, meaning only issues and fixes that withstand red-team verification are retained in the final output. To install the plugin, you run the official DSH plugin command, targeting any existing DSH profile you want to add it to.
Most users run the tools in a closed loop: first run checkup to generate a list of validated issues, then pass that list directly to the fix tool to resolve each issue, then run review to confirm all issues have been properly addressed. You can also use each tool independently if you only need one function, such as running a code health check without fixing anything, or reviewing pre-existing fixes. The plugin supports per-role model configuration, letting you assign different LLM models to different steps to leverage cross-model adversarial checking for more accurate results. It is designed for DSH users who want a standardized process for debugging and fixing codebase issues.
dsh-inspect is released under the permissive MIT open-source license. It requires the official DSH workflow engine to function, but if you install it to a profile that lacks this dependency, the plugin will load cleanly and throw a clear, informative error when you try to use any of its tools instead of hanging your entire profile. The project ships with a regression test suite that you can run with the built-in Node.js test runner, and no extra dependencies are needed to run the tests. The plugin requires no build step, as the source code runs directly in the DSH runtime with TypeScript type stripping handled natively by Node.
omdsh-dev/dsh-inspect 是一款专为 DeepSeek Harness(DSH)打造的原生闭环质量检查插件,提供 checkup 问题发现、fix 修复交付、review 质量复查三款工具,基于控制论反馈机制实现了「发现问题→修复交付→质量复查」的完整开发闭环,所有环节都要求对抗式验证,只有经得住反证的问题和修复才会被保留下来。
用户既可以按推荐流程串联使用三款工具,也可以单独使用某一款实现特定需求,比如单独做代码体检、单独完成指定修复任务或单独对已有修复做质量把关。插件支持角色级模型分层配置,可以给不同环节的子代理分配不同模型,利用异源对抗提升检查修复的质量,适合需要规范代码问题排查修复流程的 DSH 用户使用。
本插件采用 MIT 许可证开源,可通过 DSH 官方的插件管理命令安装到任意 DSH profile 中,依赖 DSH 官方工作流引擎,缺失依赖时调用工具会抛出清晰的指引错误,不会导致整个 profile 挂起。项目自带回归测试用例,源码无需构建即可运行,仅需要 TypeScript 做类型检查。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-inspect(omdsh-dev/dsh-inspect)
仓库:https://github.com/omdsh-dev/dsh-inspect
本站详情页:https://www.yhbd.top/plugins/omdsh-dev-dsh-inspect/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-08-17 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add git+https://github.com/dsh-external/dsh-inspect.git
把 omdsh-dev/dsh-inspect 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
@dsh-external/dsh-inspect
发现问题 → 修复交付 → 质量复查 的简单闭环插件。
三个朴素工具,共享同一套"对抗式检查"机制:
| 工具 | 干什么 | 核心机制 |
|---|---|---|
checkup |
找问题 | 对抗式检查员(各看一个角度)→ 红队攻击验证(尝试推翻问题声明,推不翻的才保留)→ 汇总分级(严重/一般/建议) |
fix |
修复交付 | 拆解 → 并行实现(每个实现员按找根因(沿数据流找偏离源头)→ 实施 → 重跑复现验证(反馈闭合))→ 对抗式检查 → 修复轮收敛 → 交付报告 |
review |
质量复查 | 对抗式审查员(各看一个角度)→ 汇总分级;可传 fixed_issues 逐条重跑复现确认问题真的消失 |
理论内核:控制论的反馈机制
- 发现是怀疑,验证是定罪:检查员/审查员一律对抗式(默认怀疑、找反例、只认可当场验证的证据); checkup 的红队环节就是负反馈——问题声明必须经受住攻击,推不翻才成立。
- 根据数据流定向判断状态:判断问题前先按数据流理清系统(输入 → 处理 → 存储 → 输出, 谁写谁读);问题 = 数据流某处状态偏离预期,而不是静态读代码猜。
- 互相校验:每个问题必须给出可互相校验的验证方式(重跑复现 / 日志对照 / 输入输出对照 / 双路径对照),并写明预期状态与实际观测——无法通过系统反馈验证的,不许报。
- 修复要证伪:先沿数据流找到状态偏离的源头(不许修表面);修复后重跑原复现, 观测输出与预期比较(反馈闭合)——问题没消失 = 根因没找对,重新分析。
- 根据数据判断直接定方案:根因找到后,方案由数据自然决定——实现员按"找根因 → 实施 → 验证" 三步直接做(根据数据判断选择最合理的方案,不空谈不犹豫,实施保持改动最小)。
- 闭环:checkup 的问题清单 → fix 修复任务 → review 把关(可逐条验证修复是否真消失); 复查不通过或人的反馈重新进入 fix。三个工具可单独用,也可串起来。
结构
dsh-inspect/
├── package.json # @dsh-external/dsh-inspect (MIT)(声明 dsh.bundle.patch)
├── cordis.patch.yml # bundle 补丁:按包名插入插件行
├── src/index.ts # cordis 插件:注册 checkup/fix/review 三个工具(官方 workflow 引擎;原生 TS,零构建)
├── tsconfig.json # typecheck 配置(project references 解析到 sibling deepseek-harness 源码)
├── test/
│ └── regression.test.mjs # 回归测试:前两轮 10 项修复固化为可重跑用例(node:test)
└── README.md
开发与检查
pnpm install # 仅 typescript/@types/node(typecheck 用)
pnpm run typecheck # tsc -b,类型从 sibling deepseek-harness checkout 解析
cd plugins/dsh-inspect && node --test # 回归测试
源码即运行时:包入口直接指向 src/index.ts,无构建步骤。profile 安装的副本位于
node_modules 下,由 dsh 源码启动器的 tsx hook 加载(Node 原生类型剥离拒绝
node_modules 内的文件);源码 checkout 在 node_modules 外直跑时也可用 Node ≥22.18
原生剥离。要求 erasable-only TS 语法(无 enum/命名空间等),测试的 vm 路径用
node:module 的 stripTypeScriptTypes 剥离类型,会挡住不可移植写法。
测试(回归)
cd plugins/dsh-inspect && node --test # 零依赖,纯 node + node:test
# 或:node --test test/(Node ≤20 支持目录参数;Node 22+ 把位置参数当 glob,请用
# node --test 或 node --test 'test/**',见 nodejs/node 测试运行器 glob 语义)
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
tt-a1i/archify
loopx-project/loopx
ZSeven-W/openpencil
omdsh-dev/DSH-better-sidebar
NanmiCoder/dsh-agent-teams
LiPu-jpg/Openwrite