omdsh-dev/dsh-tool-encoding

DSH编码/哈希工具插件:base64/base64url/url/hex编解码、md5/sha1/sha256/sha512哈希、UUID生成,零依赖

Project Overview项目介绍

This is a native encoding and hashing plugin built exclusively for DeepSeek Harness (DSH). It provides a full set of encoding and decoding tools for UTF-8 text, covering base64, base64url, URL, and hex formats, along with cryptographic hashing and UUID v4 generation. Unlike relying on external shell commands to handle common encoding tasks, this plugin is implemented as pure functions with zero dependencies, eliminating pain points like quote escaping errors, cross-platform command inconsistencies, and unnecessary process overhead. It also runs safely without using eval or new Function calls, adhering to strict security best practices.

DSH agent developers and end users can call this plugin for frequent daily encoding tasks. Common use cases include decoding JWT payloads from API responses, constructing URL query parameters, generating file integrity hashes, and creating random UUIDs for session or resource identifiers. The plugin enforces strict input validation: it checks for valid UTF-8 encoding, rejects non-canonical base64 that can cause mapping collisions, and throws consistent, clearly prefixed error messages for invalid inputs. This makes debugging much easier than troubleshooting opaque, inconsistent errors from shell commands.

The plugin is compatible with DSH version 0.1.5-rc.1, and can be installed in one step using the DSH plugin management CLI, directly pulling from the public GitHub repository. It supports both interactive web profiles and headless profiles for automated batch tasks, and can also be installed from a locally built npm tarball for development testing. It is released under the open source MIT license, has 41 comprehensive test cases covering standard compliance and edge input scenarios, and has documented known limitations around binary encoding, HMAC support, and full URL form encoding.

这是一款专为 DeepSeek Harness (DSH) 开发的原生编码哈希工具插件,支持UTF-8文本的base64、base64url、URL、hex编解码,同时提供哈希计算与UUID生成功能。它采用零依赖、零进程、纯函数实现,没有eval或不安全构造函数调用,解决了使用shell命令处理编码时常见的转义错误、跨平台不一致等问题。

DSH开发者或Agent用户在日常处理API响应JWT负载解析、拼接URL查询参数、校验文件完整性、生成随机UUID时,都可以直接调用这个工具完成操作。相比调用外部shell命令,它速度更快,不会出现转义错误,且严格遵循相关标准规范,对非法输入有明确的错误提示,降低了调试成本。

本插件采用MIT许可协议,兼容DSH 0.1.5-rc.1版本,可通过DSH插件管理命令直接从GitHub安装,同时支持web和headless两种运行配置。项目包含41个测试用例覆盖标准合规性与边界场景,当前已知限制包括暂不支持任意二进制非可打印字节编解码,哈希不支持HMAC,仅提供component级URL编码。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:omdsh-dev/dsh-tool-encoding

把 omdsh-dev/dsh-tool-encoding 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-tool-encoding

English

DSH 编码/哈希工具插件 —— UTF-8 文本的 base64/base64url/url/hex 编解码 + 哈希 + UUID。零依赖、零进程、纯函数。

包名:@deepseek-ai/dsh-tool-encoding(独立 bundle,非 monorepo 集成形态);lib/ 产物由仓库内 npm run build(tsc)生成并随仓库提交。

License

动机

Agent 处理编码/哈希是日常高频操作:查看 API 响应里的 base64 字段(JWT payload)、构造 query 参数、校验文件完整性(sha256)、生成 UUID。当前做法 bash -c "echo ... | base64" 的问题:进程开销、引号转义地狱(base64 串嵌进 bash 命令再嵌进 JSON 参数,双层转义错误率极高)、跨平台工具命名不一致(md5 vs md5sum vs shasum -a 256)。

安全模型

无 eval、无 new Function。所有操作是 Buffer/node:crypto/TextDecoder/encodeURIComponent 的纯函数组合:

  • UTF-8 完整性:解码用 fatal 模式(TextDecoder('utf-8', { fatal: true })),非法字节抛 encoding: invalid UTF-8 output;合法 U+FFFD/控制字符不误伤(00 NUL、0a 换行、efbfbd U+FFFD 均合法,ff 非法)
  • base64 严格校验:无空白、= 仅末尾且 ≤2、长度必须为 4 的倍数、RFC 4648 canonical unused bits(Zh== 等非 canonical 编码拒绝,防多串映射同文本)
  • 孤立 surrogate 统一拒绝:所有文本输入过 String.prototype.isWellFormed(),避免静默替换与 URIError 行为不一致
  • 字节上限:输入 1 MB / 输出 4 MB(各 1,000,000 / 4,000,000 字节,Buffer.byteLength;输出上限为分配前预估 + 最终检查的保险丝)
  • 哈希算法白名单:Object.hasOwn 查表(md5/sha1/sha256/sha512)
  • 错误统一 encoding: 前缀,不透传底层 URIError/TypeError

架构

DSH Agent
    │ ctx.tools.register()
    ▼
src/index.ts(Cordis 插件入口 + action 分发 + 独立校验)
    │
    ▼
src/encoding.ts
    ├── b64Encode/b64Decode — 标准 base64(严格校验)
    ├── b64UrlEncode/b64UrlDecode — base64url(canonical 无 padding,解码兼容)
    ├── urlEncode/urlDecode — component 语义(URIError 包装)
    ├── hexEncode/hexDecode — UTF-8 字节 hex(fatal 解码)
    ├── digest — 白名单哈希
    ├── newUuid — crypto.randomUUID()
    └── validateUnicode/assertInputBytes/decodeUtf8Strict — 校验器

工具声明

ctx.tools.register(defineTool({
  name: 'encoding',
  parameters: {
    action: {
      type: 'string', required: true,
      enum: ['base64_encode','base64_decode','base64url_encode','base64url_decode',
             'url_encode','url_decode','hex_encode','hex_decode','hash','uuid'],
    },
    input:     { type: 'string', description: 'Input string for encode/decode/hash' },
    algorithm: { type: 'string', enum: ['md5','sha1','sha256','sha512'], description: 'For hash' },
  },
  output: { schema: { type: 'json' }, render: (_a, v) => [{ type: 'text', text: JSON.stringify(v) }] },
  execute: (args) => Promise.resolve(executeAction(args.action, args) as JsonValue),
  timeoutMs: 1000,
}))

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev wps-dsh-plugin 下一个 Next dsh-tool-time →