Ri0n72Y/dsh-workspace-scope
DeepSeek Harness 的分工作区技能与 MCP 启用功能
Project Overview项目介绍
This repository is a native plugin built exclusively for DeepSeek Harness (DSH), categorized as a preset-prompt plugin under the DSH ecosystem directory. It is distributed under the permissive MIT open source license, and can be installed directly via the official DSH CLI tool. To install it, users just need to run the command dsh plugin --profile web add dsh-workspace-scope in their terminal, after they have already installed the DSH CLI on their system. The core function of this plugin is to control the activation status of DSH skills and MCP servers per workspace, and it does not install or provide any new skills or MCP services on its own.
After installation, users can access the control panel by opening a new blank session and clicking the "Workspace Capabilities" entry on the right side of the input box. The panel automatically displays all model-invokable skills and global MCP servers from the current active Agent, and it will update the list whenever users switch to a different Agent preset. Users can toggle individual capabilities on or off, search through the full list, or use the bulk enable/disable options, and all changes are saved automatically to a .dsh-scope.json file in the root of the current workspace. This plugin is especially useful for developers who need to isolate Agent capability sets across different projects.
There are a few important limitations and caveats users should note before using this plugin. First, all configuration changes are locked once the first model request is sent in a session, so any changes made after the conversation starts will only apply to future new sessions. Second, the current 0.5.x version does not support MCP servers whose names include double underscores, though regular tool names are not affected by this limitation. Third, it only manages global MCP servers registered at the host level inherited by the Agent, so it does not handle tools or MCP registered within an individual Agent or preset. Users can also manually edit the configuration file if they prefer not to use the UI.
这是一款专为 DeepSeek Harness 开发的原生插件,分类属于预设提示类,项目名称为 dsh-workspace-scope,遵循 MIT 开源许可协议。该插件的核心能力是按工作区粒度控制 DeepSeek Harness 中当前 Agent 已拥有的技能和 Host 全局 MCP 服务器的启用禁用状态,不会主动安装、发现或提供新的技能与 MCP 服务。用户可通过 DSH CLI 执行安装命令完成部署。
通常在新建空白会话时,用户可点击输入框右侧的「工作区能力」入口打开控制面板,面板会同步当前 Agent 所有可被模型调用的技能和全局 MCP,切换 Agent 预设后列表会自动更新。用户可直接在面板中对单个能力开关、搜索,也可使用全部启用/全部禁用功能,所有修改会自动保存到工作区根目录的 .dsh-scope.json 配置文件,适合需要在不同项目隔离 Agent 能力的开发者使用。
本插件依赖已提前安装好 DSH CLI 环境,配置修改在首次发起模型请求后会锁定,因此对话开始后的修改仅对新会话生效。当前 0.5.x 版本暂不支持管理名称中包含 __ 的 MCP 服务,普通工具名称不受此限制。除了通过 UI 配置,用户也可手动编辑 .dsh-scope.json,支持白名单、黑名单、默认三种模式自定义能力范围。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-workspace-scope(Ri0n72Y/dsh-workspace-scope)
仓库:https://github.com/Ri0n72Y/dsh-workspace-scope
本站详情页:https://www.yhbd.top/plugins/ri0n72y-dsh-workspace-scope/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-09-30 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-workspace-scope
把 Ri0n72Y/dsh-workspace-scope 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-workspace-scope
为 DeepSeek Harness 按工作区启用或禁用当前 Agent 已拥有的 Skill 与 Host 全局 MCP。
本插件只做能力范围控制,不负责安装、发现或提供 Skill / MCP。不同工程可以通过各自的 .dsh-scope.json 暴露不同的能力集合。
English: README.en.md
[!IMPORTANT]
dsh-workspace-scope v0.5.3仅针对 DeepSeek Harness0.1.6-alpha.2完成适配与实测。这不是“0.1.6-alpha.2及以上均兼容”的声明;后续 DSH 版本可能继续调整 Client / Host contract,升级 DSH 前请单独验证本插件兼容性。
安装
需要已安装 dsh CLI:
dsh plugin --profile web add dsh-workspace-scope
卸载:
dsh plugin --profile web remove dsh-workspace-scope
使用
在新建会话的空白 Session 中,点击输入卡右侧的「工作区能力」。
界面会显示当前 Agent 可由模型调用的 Skill,以及 Host 全局 MCP 服务器。切换 Agent Preset 后,列表会随当前 Agent 更新。开关、搜索、全部启用和全部禁用都会立即保存到工作区根目录的 .dsh-scope.json。
配置在会话第一次真正发起模型请求时锁定。因此开始对话前的修改会应用到该会话;之后的修改只影响新的会话。
配置
通常直接使用 UI 即可。也可以手动编辑工作区根目录的 .dsh-scope.json:
{
"default": {
"mode": "whitelist",
"skills": ["<skill-name>"],
"mcps": ["<server-name>"]
}
}
default:全部启用。whitelist:仅启用列表中的能力。blacklist:禁用列表中的能力。skills:Skill 名称。mcps:Host 全局 MCP server 名称。
边界
- Skill 范围来自当前 Agent 已有的 model-invocable Skill;本插件不会安装或补充 Skill。
- 禁用 Skill 控制的是模型调用能力。是否仍可通过
/skill-name手动调用,由该 Skill 自身的 DSHuserInvocable策略决定。 - MCP 只管理 Host 全局注册并由 Agent 继承的 MCP;Agent / Preset 作用域内注册的 Tool / MCP 不在管理范围内。
- 当前 0.5.x 不支持名称中包含
__的 MCPserverName;普通 tool name 可以包含__。
实现细节、数据流与 C4 图见 docs/architecture.md。版本变化见 CHANGELOG.md。
贡献
发现 bug 或有想法可以直接开 issue。提交 PR 前请阅读 CONTRIBUTING.md。
License
MIT
titanwings/distilly
YuJunZhiXue/dsh-purge
Clearailhc/clearai-dsh
yejiming/MuseAI
superdesigndev/superdesign-skill
Miaotofu01/Study-Mate