omdsh-dev/dsh-tool-json

DSH JSON 查询工具插件:JMESPath 子集查询,零依赖递归下降解析器

Project Overview项目介绍

This repository is a native plugin built exclusively for DeepSeek Harness (DSH), providing a JSON query tool that uses a custom subset of JMESPath-inspired syntax. It includes a hand-written zero-dependency recursive descent parser that eliminates the process overhead of calling external tools like jq or Node.js for JSON queries. Unlike DSH’s built-in grep tool that only matches text strings, this plugin works directly with JSON structure to avoid incorrect matches of keys or values. It accepts input JSON in two formats: direct object passing or raw UTF-8 string input, both validated before querying.

The plugin follows a strict security model: it does not use eval or dynamic function execution, and includes built-in protection against prototype pollution. It enforces hard limits on query expression length, parse depth, input JSON size, and input nesting depth to prevent abuse or unexpected crashes. It supports common query operations including dot property access, array indexing, bracket access for special keys, and wildcard projection for array elements. This tool is designed for DSH agents that frequently handle JSON API responses, configuration files, and tool outputs.

This plugin is officially compatible with DSH version 0.1.5-rc.1, and can be installed directly from the public GitHub repository via the DSH CLI plugin command. It currently only supports read-only JSON queries, and does not include support for advanced JMESPath features like filters, pipes, or function calls. The plugin is released under the permissive MIT open source license, and includes 54 test cases covering core functionality, error handling, and edge cases. Installation requires a working DSH 0.1.5-rc.1 environment with npm configured.

omdsh-dev/dsh-tool-json 是面向 DeepSeek Harness(DSH)的原生 JSON 查询工具插件,采用受 JMESPath 启发的自定义子集语法,内置零依赖的手写递归下降解析器。它避免了调用外部 jq 或 node 进程处理 JSON 带来的进程开销和序列化成本,解决了 DSH 内置 grep 只能做字符串级匹配容易误匹配的问题,能够精准匹配指定JSON路径,不会混淆键和值。

本插件采用严格的安全模型,不使用 eval 或动态函数执行,内置原型污染防护,同时对查询表达式长度、解析深度、输入JSON大小和嵌套深度都设置了明确的安全上限。它支持点访问属性、数组索引、特殊键名方括号访问、数组通配符投影等常用查询语法,能够满足Agent日常处理JSON的大部分需求。

本插件已适配 DSH 0.1.5-rc.1 版本,支持通过 dsh plugin 命令从 GitHub 源码或打包后的 tarball 安装,区分 web 和 headless 两个不同配置文件需要分别安装。它目前仅支持只读查询,不支持过滤器、管道等高级JMESPath功能,开源协议为MIT,共包含54个测试用例覆盖核心功能和边界场景。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:omdsh-dev/dsh-tool-json

把 omdsh-dev/dsh-tool-json 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-tool-json

English

DSH JSON 查询工具插件 —— JMESPath-inspired 路径查询(自定义子集),零依赖递归下降解析器。

License

为什么需要

Agent 处理 JSON 是高频操作——API 返回值、配置文件、工具输出到处都是 JSON。当前做法是起 bash 进程跑 node -e 或 jq,每次都有进程开销和字符串序列化成本。

DSH 内置 grep 可以做正则匹配,但无法理解 JSON 结构。对于 {"items":[{"id":1}]}:

  • grep 只能做字符串级搜索,容易误匹配值、key、或嵌套子对象中的同名 key
  • json 走结构化路径,只匹配指定路径,不混淆 key 和 value

安全模型

手写递归下降解析器,无 eval/new Function;Object.hasOwn 防原型链污染(constructor/__proto__ 读取不触发原型链)。资源上限(对象与字符串两条输入路径统一执行):

  • 查询表达式长度 ≤ 200 字符、解析深度 ≤ 20 层、数组索引必须是安全整数
  • 字符串输入 ≤ 1,000,000 bytes(UTF-8);输入嵌套深度 ≤ 100
  • 单次 wildcard 投影 ≤ 100,000 元素
  • 只接受 JSON-compatible 值(null/boolean/有限 number/string/array/plain object;拒绝 undefined/BigInt/函数/Date/非有限数)

错误分类(JsonQueryError):MISSING_PROPERTY(投影内跳过)、TYPE_MISMATCH/INDEX_OUT_OF_BOUNDS/INVALID_QUERY(如实抛错),统一 json: 前缀。

成本模型(AUDIT-JSON-03):输入在每次查询前执行全量校验(类型/深度/字节/循环/枚举性)——这是有意的安全成本,查询小字段也会完整扫描输入;timeoutMs 无法中断同步校验。

架构

DSH Agent
    │ ctx.tools.register()
    ▼
src/index.ts(Cordis 插件入口 + action 分发)
    │
    ▼
src/query.ts
    ├── parseQuery() — 递归下降解析器(strict 语法 + 转义 + 上限)
    ├── executeQuery() — 执行器(错误分类 + 投影上限)
    └── normalizeInput() — 双形态输入 + assertJsonCompatible 校验

工具声明

ctx.tools.register(defineTool({
  name: 'json',
  parameters: {
    input: { type: 'json', required: true, description: 'JSON value or JSON string to query.' },
    query: { type: 'string', required: true, description: 'Path expression, e.g. "data.items[0].name".' },
  },
  output: { schema: { type: 'json' }, render: (_a, v) => [{ type: 'text', text: JSON.stringify(v) }] },
  execute: (args) => Promise.resolve(executeAction(args) as JsonValue),
  timeoutMs: 1000,
}))

input 双形态:对象直传(模型直接生成参数,零转义)或字符串(bash/read 原文透传),normalizeInput 统一归一化与校验。

查询语法(JMESPath-inspired 子集)

表达式 示例 说明
点号访问 foo.bar 嵌套对象属性(标识符字符集 [A-Za-z0-9_$ + BMP 非 ASCII])
方括号索引 items[0] 数组索引(安全整数)
方括号属性 items['key'] / items["key"] 含特殊字符的属性名
通配符投影 items[*].name 仅数组;提取元素属性
组合嵌套 a.b[0].c.d 以上全部自由组合

语义边界(有意不兼容标准 JMESPath,已锁定):

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-tool-markdown 下一个 Next dsh-chords →