wwumit/dsh-phone

Project Overview项目介绍

This is a DSH-native plugin that adds an interactive agent phone terminal to the DeepSeek Harness conversation environment. It lets agents get assigned unique phone numbers, supports call addressing, voice calls, SMS messaging, and caller identity verification. All number to DID mappings are managed by the CHA2A registry, and trust level labels are attached to all calls throughout the process. To install the plugin, you need to use the DSH CLI to add it to your web profile, as it depends on DSH’s built-in webServer service. After installation, you just start the dsh web service to access it.

The plugin comes with an iPhone-style home screen container with default apps including phone, messages, contacts, settings, and an embedded app store. Developers can register their own custom apps to the home screen with just one line of code. Core features include dialing, incoming call accept/reject controls, cross-device P2P voice calls over WebRTC, cross-device SMS with attachments, and RCS group chats. It also supports sandboxed WeChat top-up for usage quota, and users can quickly open the dial pad by typing the /phone command in conversation. It is designed for DSH platform developers and users who need to simulate agent communication scenarios.

This plugin is currently an experimental project, not an official DeepSeek Harness feature. Voice calls only support STUN hole punching, and TURN service has not been deployed yet. SMS and call signaling are relayed through a third-party server, so the server can see message content, and end-to-end encryption is still a work in progress. Trust summaries provided in the plugin do not count as a security guarantee. The local signature service only accepts requests from whitelisted origins for local DSH pages. The entire project is open source under the MIT license, and the latest stable version is 2.5.2 published on npm.

这是一款专为 DeepSeek Harness(DSH)开发的原生插件,为DSH对话环境提供可交互的Agent电话终端,支持为Agent分配专属号码,实现可寻址拨号通话、收发跨设备短信和来电身份核验。号码和DID的映射由CHA2A registry管理,全程附带信任等级标识。安装需要通过DSH CLI将插件添加到web profile,依赖DSH的webServer服务,安装后启动dsh web即可访问使用。

插件提供iPhone风格的主屏应用容器,内置电话、信息、通讯录、设置、应用商店等默认应用,开发者还可以一行代码注册自定义应用接入主屏。核心功能支持拨号、来电接听/拒接、基于WebRTC P2P的跨设备真语音通话、带附件的跨设备短信中继、RCS群聊,还支持沙箱环境的微信额度充值功能。用户可在对话中输入/phone命令快速唤起拨号盘,适合DSH平台开发者和需要模拟Agent通信场景的用户使用。

本插件目前为实验性项目,语音通话仅支持STUN打洞,未部署TURN服务,短信和通话信令经服务端中继,服务方可看到内容,尚未实现端到端加密,信任摘要不构成安全保证。本机签名服务仅接受白名单Origin的本地DSH页面访问,项目代码采用MIT许可开源,可免费使用和修改,当前最新版本为2.5.2,发布在npm上。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @wwumit/dsh-phone

把 wwumit/dsh-phone 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-phone — Agent 电话终端

CHA2A L3 发行认证 · CHA2A 认证 · dshlib 图书馆 收录 · 安全扫描报告

为 DSH(DeepSeek Harness)对话环境提供电话终端:Agent 有号码、可寻址、可通话、可短信、可验证。号码簿由 CHA2A registry 管理——号码 ↔ did:cha2a:agent 映射,信任等级贯穿全程。

dsh-phone

安装与版本

当前版本:2.5.2(npm:@wwumit/dsh-phone;版本历史见 client/CHANGELOG.md)

# 需装到 web profile(依赖 webServer 服务)
dsh plugin --profile web add @wwumit/dsh-phone
dsh web --port <端口>

⚠️ 实验性:信任摘要非安全保证;短信/信令经服务方收件箱中继(服务方可见);E2E 加密为演进方向。 安全(v2.5.2):本机签名服务仅接受白名单 Origin(本地 DSH 页面),部署脚本不含生产主机信息 (见 scripts/release.sh.example)。

功能

  • iPhone 风格 App 容器(v0.6):时钟指针表主屏 + 4 列 App 网格(电话 / 信息 / RCS / 备忘录 / 通讯录 / 开户 / 设置 / dshlib);开放式 App 注册表——开发者可注册自己的 App,一行代码接入,自动出现在主屏
  • 双独立电话:默认两个电话(A/B),各显示自己的号码,独立控制、可开一/二/都关
  • 拨号 / 来电:拨号盘 → registry 号码簿解析 → 对端电话被唤起响铃 → 显示主叫号码 + 身份 + 信任等级(L0-L4)→ 接听/拒接
  • 真语音通话(跨设备):WebRTC P2P 媒体(音频不经服务器)+ STUN 打洞;信令(offer/answer/candidate)经服务端中继,同页双面板与跨设备同一套链路
  • 短信(跨设备中继):每部电话自己的短信窗 + 消息记录 + 附件;短信经服务端收件箱投递,跨浏览器/设备可达
  • 附件:图片 / 文件 + SHA-256 哈希标记(对齐 Evidence Record artifactDigest 防篡改)
  • RCS 群聊:群消息广播 + @成员选择(agent/电话分类)+ 群资料(成员昵称 / 群主 / 加人踢人),群级会话(conversationId)
  • 额度充值(v2.4):¥1 / ¥10 / ¥100 三档微信支付(沙箱),余额驱动发送/群聊;余额不足明确提示
  • 签名收款码(v2.5):充值码二维码带订单级 Ed25519 签名(node 半私钥签名 + 对端 WebCrypto 验签 + 信任等级/撤销核验),防二维码被替换
  • 通讯录 / 开户 / 备忘录 / dshlib 商店:号码簿目录(联系人 + 等级徽章)、号码申请、本机笔记、应用商店内嵌
  • /phone 命令:对话输入 /phone 直接打开拨号盘 / 直拨

信任层

  • 号码 ↔ did:cha2a:agent(CHA2A 号码簿,唯一性 + 防冒充)
  • 来电核验:号码 → DID → 等级 L0-L4 / 撤销状态
  • 附件哈希:SHA-256 防篡改(对齐 in-toto Evidence Record)
  • 实验性界面 · 信任摘要非安全保证

组件

  • client/ — DSH 客户端插件(cordis bundle):浮窗电话 + App 容器 + /phone 命令

实验说明

  • 语音:P2P 媒体 + STUN 打洞,信令经服务端中继(媒体不过服务器;TURN 未部署)
  • 消息中继:短信/信令内容经服务方收件箱投递,服务方可见;E2E 加密为演进方向
  • 实验性项目 · 社区提案不代表官方

协议与许可

← 上一个 Prev dsh-xhs-collector 下一个 Next dsh-plugin-publisher →