Starfie1d1272/dsh-builtin-toggles
基于证据的内置能力检查器,针对DeepSeek Harness Web具备故障关闭控制。
Project Overview项目介绍
This is an unofficial community-built native plugin designed exclusively for DeepSeek Harness (DSH), specifically targeting the DSH Web profile. Its core function is to provide an evidence-backed built-in capability inspector for DSH Web, with 9 reviewed UI controls that add narrow, fail-closed additional capabilities. To install the plugin, you can use the dsh CLI with the command dsh plugin --profile web add dsh-builtin-toggles followed by dsh web, or use npx if you do not have the dsh CLI installed globally. After installation, you need to restart the DSH web gateway to load the plugin bundle correctly.
The plugin is intended for DSH Web developers and users who need to debug DSH capability configurations. Once installed, it can be accessed directly from the Settings → Plugins → Built-in Plugins menu in the DSH web interface. It displays server-calculated inspection results for all loaded capabilities, including review status, profile overrides, persistence, compatibility, and mutation eligibility, grouped by composition scope to avoid misidentifying duplicate IDs across different scopes. You can filter results by multiple attributes and copy a fully redacted diagnostic report for sharing outside your local environment without leaking sensitive configuration data.
The only officially tested and supported baseline for this plugin is DSH version 0.1.0-rc.6, and later public DSH releases have not been reviewed or confirmed compatible by the plugin maintainer. The plugin is released under the open source MIT license, and it does not make any unauthorized changes to your original DSH profile content. When uninstalling, you need to first restore any entries that were overridden by the plugin, then remove the plugin via the dsh CLI or npx, then restart DSH to complete the process. All changes made by the plugin are strictly limited to its own allowlist of manageable capabilities.
这是一个专为 DeepSeek Harness (DSH) 开发的非官方社区原生插件,核心功能是为 DSH Web 提供经过验证的内置能力检查器。插件安装后会出现在 DSH 的「设置→插件→内置插件」菜单中,能够展示由服务端计算的能力审阅结果、配置覆盖状态、持久化性和兼容性等信息,还会按组合范围区分检查结果,避免不同范围的同ID条目误判重复。
开发和测试 DSH Web 功能的开发者、调试 DSH 能力配置的用户都可以使用本插件,它支持按ID、类别、运行状态、组合范围等条件筛选检查结果,还能生成不含本地敏感信息的脱敏诊断报告供复制分享。安装插件后需要重启 DSH Web 网关才能加载 bundle,启动后即可在插件菜单打开检查器查看当前所有能力的运行状态和诊断信息。
本插件仅支持已初始化的 DSH Web profile,目前仅经过 DSH 0.1.0-rc.6 版本的测试,后续更高版本未经过明确审阅,不承诺兼容稳定。插件采用 MIT 许可开源,安装可通过 dsh CLI 或 npx 完成,卸载前需恢复被插件修改的条目,插件不会擅自修改用户原有的 profile 内容。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-builtin-toggles(Starfie1d1272/dsh-builtin-toggles)
仓库:https://github.com/Starfie1d1272/dsh-builtin-toggles
本站详情页:https://www.yhbd.top/plugins/starfie1d1272-dsh-builtin-toggles/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 7 · 最近提交 2026-09-29 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 7 stars - very few users, little community feedback星标只有 7,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-builtin-toggles
把 Starfie1d1272/dsh-builtin-toggles 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-builtin-toggles — Evidence-backed Built-in Capability Inspector
简体中文 | English
DeepSeek Harness Web 的 evidence-backed 内置 capability Inspector;9 个经过审阅的 UI controls 只是极窄、fail-closed 的附加能力。
非官方社区插件(unofficial community plugin)。与 DeepSeek Harness 官方无关,不受官方支持。
本插件位于 设置 → 插件 → 内置插件。它显示由 Host 生成的 capability inspection:审阅事实、profile override、可持久化性、兼容性和 mutation eligibility 均由服务端计算。检查结果按 composition scope 区分:Host/profile 组合与按会话挂载的 Agent 预设组合即使使用相同 id(如 tool-bash)也不会互相误判为重复。

截图环境:published @deepseek-ai/dsh@0.1.0-rc.6、内置 standard Agent 预设、本插件当前版本;数据未伪造。Host 不公开稳定 runtime release identity,因此 Compatibility 如实显示 unverified / 运行时身份不可用。(另两张真实截图保存在 docs/assets/:builtin-toggles-anomalies.png 展示干净 rc.6 + 内置 standard Agent 预设下仅异常项为 0,builtin-toggles-agent-preset-scope.png 展示 26 个按会话挂载的 Agent 预设组合条目。)
安装
前置:已初始化的 DSH web profile。后续公开 DSH 版本可能仍可安装或运行,但除非经过明确 review,不自动成为 supported/reviewed baseline。
已安装 dsh CLI:
dsh plugin --profile web add dsh-builtin-toggles
dsh web
使用 npx(无需全局安装 dsh):
npx @deepseek-ai/dsh plugin --profile web add dsh-builtin-toggles
npx @deepseek-ai/dsh web
安装后重启 DSH web/gateway,使启动时读取 bundle 层。
功能
- Capability Inspector / Doctor:检查当前 Web Loader 的所有 capability,包括 external、未审阅和异常条目;逐项展示运行状态、profile override 三态、Agent 预设 ownership、composition scope(Host 组合 / Agent 预设组合)、审阅溯源、依赖证据、兼容性与服务端计算的 mutation eligibility。
- 筛选与诊断:按 ID/包名、类别、管理平面、组合范围、策略、验证、运行状态及异常筛选;可复制不含本地路径和配置内容的脱敏诊断报告。复制成功/失败反馈显示在按钮旁。
- Composition-scope 建模:duplicate 检查使用 Loader 的公开
Entry.id(含 tree-owner 链)。Host 与内置standardAgent 预设中合法的同 ID 各自归属不同 composition scope,不产生duplicate_runtime_id或new_official_entry;同一 scope 内的真正碰撞仍然drifted并 fail-closed。Agent 预设条目由服务端 DTO 直接锁定:policy=locked(reasonagent-preset)、mutationEligibility=ineligible,绝不借用同 bare-id Host 行的可管理性,也不会变成 Web-profile 可管理项。v1 的profileOverride.state/profilePersistence.status值域保持不变(preset 行保守投影为unavailable/unwritable),真实语义由新增 additive 字段configuration.profileApplicability(applicable/not-applicable)表达,且不把这种「不适用」当异常。 - Agent 预设平面:
tool-*/plan-mode等按会话由 Agent 预设组装,单独标注,绝不误认为 profile override。 - 9 个 reviewed UI controls:仅
ui-deliverables、ui-jobs、ui-goal、ui-message-feedback、ui-model-selection、ui-agent-preset、ui-skill、ui-subagent、ui-trajectory。它们是纯界面 leaf,作用于webprofile、影响全部 Web 会话、不编辑 Agent 预设;强制开关更新 Host 并持久化,恢复继承交由 DSH profile/HMR 重组下层值。 - Fail-closed:核心服务、Agent 能力、第三方与未知条目一律锁定;没有 generic plugin manager、marketplace 或安装/更新生命周期。
- Inspection API v1:
GET /api/builtin-toggles/v1/inspection是稳定、无本地化文案的机器接口,提供 inventory、审阅基线、配置三态、compatibility 和 eligibility。详见 Inspection API v1。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Bin-hy/dsh
anweat/dsh-restart
peiyucn/dsh-sparrow