sulfide2085/dsh-skill-manager 预览 preview

sulfide2085/dsh-skill-manager

Manage AI skills for DSH / Codex / Claude uniformly on the DeepSeek Harness settings page: hot toggle to enable or disable, one-click discovery and installation from the GitHub skill marketplace, and local ZIP import (dsh-plugin skill hub).

Project Overview项目介绍

This is a native skill management plugin built exclusively for DeepSeek Harness (DSH). It adds a dedicated skill management section to DSH’s settings page, unifying the management of AI skills from multiple different sources, including DSH’s local skill directory, Codex, Claude, and public skills hosted on GitHub. To install the plugin from source, you can run the dsh plugin --profile web add . command inside the plugin directory, and you will need to restart DSH Web after installation for changes to take effect. On Windows, a junction to DSH’s existing node_modules directory is required to access shared dependencies.

The plugin lets users view all skills grouped by source, with clear display of each skill’s name, description, calling policy, and current enabled status. It supports bulk toggling all skills from an entire source directory, as well as individual toggling for each skill. It enables keyword search across added GitHub repositories to find new skills, and lets users install selected skills with one click. A local search filter is also available to sort through already installed skills, and clicking a skill card expands to show the full text of the skill.

The plugin is released under the open-source MIT license, and includes 100 unit tests that cover all core modules including ZIP parsing, GitHub repository handling, and client-side registration that can be run with Node.js’s built-in test runner without any extra external dependencies. It currently has several limitations: bundled or runtime-sourced skills have no local disk file, so they cannot be edited and their toggle buttons are disabled. It does not yet support ZIP64, download proxies, or symlink materialization. Project-level skills only show up when there is an active session with a working directory set.

这是一款专为 DeepSeek Harness (DSH) 开发的原生技能管理插件。它在 DSH 的设置页面中添加了专门的「技能管理」分区,统一管理来自 DSH 本地、Codex、Claude 以及 GitHub 等多个来源的 AI 技能。插件支持技能热开关启停、GitHub 技能市场一键发现安装、本地 ZIP 压缩包即装即用,安装后的技能可立刻被 /skill 命令和模型识别调用。

用户可以在统一面板按来源分组查看所有技能的名称、描述、来源、调用策略和启用状态,支持批量启停整个来源目录的技能,也可以针对单个技能切换启停状态。用户可通过关键词搜索 GitHub 仓库中的技能,选中目标技能后一键安装,也可以筛选已安装的本地技能,点击技能卡片即可展开查看技能完整内容。

插件采用 MIT 许可开源,可通过 DSH 插件命令行从源码安装,安装后需要重启 DSH Web 端才能生效。Windows 环境下需要通过目录软链接依赖 DSH 自带的 zod 和 dsh 协议包,自带 100 个单元测试用 Node 内置测试工具即可运行。目前暂不支持 ZIP64、下载代理、symlink 物化等功能,捆绑运行时来源的技能无法编辑。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 11 stars - an early-stage project星标 11,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:sulfide2085/dsh-skill-manager

把 sulfide2085/dsh-skill-manager 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-skill-manager · DSH 技能管理插件

English · 中文

在 DSH 设置页里统一管理 DSH / Codex / Claude 的全部 AI 技能——热开关启停、GitHub 技能市场一键发现安装、本地 ZIP 即装即用,装完立刻被 /技能 与模型看见。

DSH 技能管理预览

这是什么

DSH(DeepSeek Harness)的技能管理插件。技能文件散落在各处:DSH 自己的技能目录、Codex 的 ~/.codex/skills、Claude 的 ~/.claude/skills、GitHub 上的技能仓库。本插件在设置页加了一个"技能管理"分区,把这些来源的技能收进一个面板统一查看和管理。

本插件收录于 GitHub dsh-plugin 话题。

功能

  • 技能列表:合并注册表(启用)与磁盘(停用)条目,按来源分组(DeepSeek Harness / Agents / 项目 / Codex / Claude),显示名称、描述、来源、调用策略与启用状态;从 GitHub 安装的技能带来源标签。
  • 启停:DSH / Agents 目录的启停通过重命名 SKILL.md ↔ SKILL.md.disabled 实现,filesystem watcher 约 200ms 生效,DSH、Codex、Claude 都遵循这个约定;codex / claude 目录的技能默认停用,显式启用后才进入官方 /技能 注册表。
  • 目录级启停:组头的开关一次操作整个来源目录。
  • ZIP 安装:选择本地 .zip(≤64 MiB),解压后自动查找包内的技能(SKILL.md 目录束或平铺 .md),查重后装入 ~/.dsh/skills 并启用;包内没有技能时报错。
  • GitHub 技能搜索:添加仓库(owner / name / 分支,分支可留空,默认 main→master 回退),输入关键词跨所有已添加仓库搜索技能,命中可逐个安装;本地列表另有独立搜索框,过滤已安装技能。
  • 安装即刷新:ZIP / 仓库安装成功后列表自动刷新,标题旁另有手动刷新按钮;点击卡片可展开查看技能全文。

技能管理界面

文件结构

文件 作用
lib/index.js host 半:skillManager 远程服务(list / content / setEnabled / installZip / 仓库接口)
lib/skill-files.js 磁盘约定:扫描根、frontmatter 解析、.disabled 启停
lib/skill-zip.js ZIP 解析/解压(store+deflate)、CRC32 校验、条目名安全检查、包内技能发现与安装
lib/skill-repo.js GitHub 归档下载(大小上限 / 超时 / 重试 / 缓存 / 镜像)、仓库技能扫描、按目录安装
lib/client.js 浏览器半:手写 bundle,注册 settings.section 分区(id: skill-manager,order: 17)

安装

dsh plugin --profile web add .   # 在插件目录内执行

代码更新后需要重启 DSH Web 生效(host 的 manifest 在网关启动时注册,不重启新接口会 404)。

Windows 下插件依赖 zod 与 @deepseek-ai/dsh-typert-protocol,它们随 DSH 安装树分发,插件目录下的 node_modules 是指向 <dsh 安装目录>/node_modules 的 junction。删除后重建:

New-Item -ItemType Junction -Path "node_modules" -Target "C:\Users\<你>\AppData\Roaming\npm\node_modules\@deepseek-ai\dsh\node_modules"

测试

使用 Node 内置 node:test,无需额外依赖,共 100 个用例:

npm test

覆盖:skill-zip(解析/解压/安全过滤/发现/冲突/坏包)、skill-repo(坐标校验/分支回退/缓存/重试/安装)、index(host 远程方法 + 状态文件持久化)、client(bundle 加载/描述符/face 往返)。

限制

  • bundled / runtime 来源的技能没有磁盘文件,不可编辑,开关置灰。
  • 停用只是重命名文件,不删除内容,随时可恢复。
  • 未开会话时只显示用户级与全局技能(项目级技能依赖会话的 cwd)。
  • 尚未实现:zip-bomb 预算、symlink 物化、ZIP64、下载代理支持。
← 上一个 Prev dsh-tui-pi 下一个 Next dsh-telegram-channel →