omdsh-dev/dsh-tool-csv
DSH CSV 数据工具插件:解析/查询/统计/转换 CSV 文本(RFC 4180),零依赖状态机解析器,注册 csv 工具
Project Overview项目介绍
This repository is a native DSH plugin built specifically for DeepSeek Harness, focused on CSV data parsing, querying, filtering, statistics and conversion. To install the plugin for the interactive web profile, users can run the command dsh plugin --profile web add github:omdsh-dev/dsh-tool-csv, and for the default headless profile used by dsh run, the command is dsh plugin --profile headless add github:omdsh-dev/dsh-tool-csv. After installation, users can verify it by checking that tool-csv appears in the output of dsh --profile [your profile] --dump-config, and can run a quick functional test to confirm it works as expected.
This plugin is designed for DSH users who regularly handle CSV data in LLM agent conversations, such as exported spreadsheets, API response tables, or report fragments. When a user calls the csv tool with a target action and input CSV text, the plugin processes it in a single function call and returns structured JSON output, avoiding the overhead of spawning a new bash process and the errors from LLM-written parsers. Users can choose from four actions: parse (convert to JSON array), query (filter rows by exact column match), stats (get table metadata), and to_json, which is an alias for parse for better LLM compatibility.
This plugin is released under the open source MIT license, it has zero third-party dependencies and uses a hand-written single-pass state machine parser that complies with the RFC 4180 standard. It sets a 256,000 byte input size limit, 2000 millisecond timeout, and a default 100-line output limit to prevent output bloat. The plugin follows a pure function security model: it does not read or write files, does not access the network, and has no code injection surface, but users should be aware that tool parameters are logged in session logs, so sensitive data should never be passed to the tool.
omdsh-dev/dsh-tool-csv 是一款专为 DeepSeek Harness (DSH) 开发的原生 CSV 数据处理插件,提供解析、查询、过滤、统计和转换符合 RFC 4180 标准的 CSV 文本的能力。它采用零依赖纯函数实现,使用手写的单遍扫描状态机解析器,能够一次函数调用毫秒级返回结构化 JSON,解决了现有 LLM 会话中手写 CSV 解析易错、启动进程成本高的痛点。
该插件面向 DSH 用户,主要用于处理 Agent 会话中常见的各类表格形态 CSV 数据,比如导出文件、API 响应、报告片段、中转表格数据等。典型工作流程为:用户调用 csv 工具,传入 CSV 文本和指定动作(parse/query/stats/to_json),插件即可返回处理后的结构化 JSON 结果,支持按列精确过滤、获取表格统计信息、格式转换等操作。
本插件采用 MIT 许可开源,完全免费,零第三方依赖,对输入设置了 256KB 的大小上限,超时限制为 2000 毫秒,查询默认返回 100 行防止输出膨胀。安全方面采用纯函数设计,不读写文件、不联网,无代码注入风险,需要注意不要传入敏感数据,因为工具参数会被记入会话日志。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-tool-csv(omdsh-dev/dsh-tool-csv)
仓库:https://github.com/omdsh-dev/dsh-tool-csv
本站详情页:https://www.yhbd.top/plugins/omdsh-dev-dsh-tool-csv/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 4 · 最近提交 2026-09-10 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:omdsh-dev/dsh-tool-csv
把 omdsh-dev/dsh-tool-csv 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-tool-csv
DSH CSV 数据工具插件 —— 解析、查询、过滤、统计和转换 CSV 文本。零依赖、纯函数、RFC 4180 状态机解析器。
动机
Agent 会话里表格形态的数据(导出文件、API 响应、报告片段)出现频率很高。现有路径是起 bash 进程让模型现写解析脚本:
- 每次调用都起进程——Windows 上尤其昂贵
- 模型手写 CSV 解析器错误率高——引号内逗号、
""转义、BOM、跨行字段、CRLF 这些边界手写代码极易踩坑,且结果不可验证
本插件提供确定性、零依赖、纯函数的 CSV 处理:一次函数调用,毫秒级返回结构化 JSON。
与 dsh-tool-json 形成"结构化数据处理"对:JSON 管对象,CSV 管表格。
安全模型
- 零依赖:不引入 csv 解析库,手写状态机(单遍扫描,O(n))
- 纯函数:不读文件、不写文件、不联网、不 eval
- 无注入面:查询过滤只做字面精确匹配(
===),不支持表达式求值 - 预算:输入上限 256,000 字节(超限直接报错,不截断);
timeoutMs: 2000;limit默认 100 行防输出膨胀 - 工具参数会记入会话日志,不要传入敏感数据
工具声明
注册 csv 工具(@deepseek-ai/dsh-tool-csv,row id tool-csv),统一输出 JSON 文本字符串。
| 参数 | 类型 | 必填 | 说明 |
|---|---|---|---|
action |
string | ✅ | parse / query / stats / to_json |
csv |
string | ✅ | CSV 文本(RFC 4180;引号字段可含逗号/换行;"" 转义;忽略 BOM) |
column |
string | 查询列:列名(有表头时)或 1-based 索引如 "2" |
|
value |
string | 查询精确匹配值(严格相等,非子串) | |
delimiter |
string | 分隔符,默认 ",";单字符或 "tab" |
|
header |
boolean | 首行是否为表头,默认 true;false 时行解析为数组 |
|
limit |
integer | 返回行数上限(query/parse),默认 100 |
Actions
| action | 功能 | 输出示例 |
|---|---|---|
parse |
解析为 JSON 数组(有表头时每行一个对象) | [{"name":"Alice","city":"NYC"}] |
query |
按列名/索引精确过滤行(结果含表头,可回读) | [["name","city"],["Alice","NYC"]] |
stats |
行数 / 列数 / 列名 / 空行数 / 警告(含重复列名、字段数不一致) | {"rows":2,"columns":2,...} |
to_json |
parse 的别名(模型友好) |
同 parse |
示例
csv { action: "parse", csv: "name,city\nalice,nyc\nbob,la" }
→ [{"name":"alice","city":"nyc"},{"name":"bob","city":"la"}]
csv { action: "query", csv: "name,city\nalice,nyc\nbob,la", column: "city", value: "la" }
→ [["name","city"],["bob","la"]]
csv { action: "stats", csv: "name,city\nalice,nyc" }
→ {"rows":1,"columns":2,"columnNames":["name","city"],"emptyRows":0,"warnings":[]}
边界行为
| 情况 | 处理 |
|---|---|
| 引号内逗号/换行/CRLF | 视为字段内容(跨行字段) |
"" 转义 |
解码为单个 " |
| 未闭合引号 | 报错:csv: unterminated quoted field(严格模式,不静默容错) |
| 闭合引号后非法字符 | 报错:csv: invalid character "x" after closing quote(RFC 4180:闭合后只允许分隔符/换行/EOF) |
| 首行 BOM | 剥离后再解析 |
| 空行 | 跳过(stats 报告空行数) |
| 字段数不一致 | 不报错:缺失补 null、多余并入最后一个字段(stats 记录警告) |
| 重复列名 | 后出现的列覆盖先出现的(stats 记录警告) |
__proto__/constructor/prototype 表头 |
null-prototype 对象写入,无损序列化({"__proto__":"value"}) |
| delimiter | 仅单 UTF-16 code unit 或 "tab";拒绝 surrogate pair(如 😀)与控制字符(除 \t) |
| 无表头 | header: false,行解析为数组,column 用 1-based 索引 |
| 超 256KB 输入 | 直接报错(不截断) |
| 十万行级输入 | 单遍聚合计算列宽(无 spread),不触发 RangeError |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
nocobase/nocobase
TencentCloudBase/CloudBase-AI-Toolkit
WYH66666666/DSH-Transparent-UI-Plugin
Nagi-ovo/dsh-visualize
SepineTam/mcp-for-stata
omdsh-dev/dsh-data-agent
morluto/jacobian
youdotcom-oss/agent-skills