yoursc/dsh-siyuan
把思源笔记(SiYuan)接入 DeepSeek Harness:17 个 siyuan_* 工具(检索/读写/日记/删除)+ 独立设置页。SiYuan notes integration for dsh: 17 siyuan_* tools plus a Web settings page.
Project Overview项目介绍
dsh-siyuan is a native plugin built specifically for DeepSeek Harness (DSH) that wires SiYuan Notes into the host so models can search, read, and write against a local notebook vault. Installation uses the official DSH plugin command dsh plugin --profile web add @yoursc/dsh-siyuan, and because plugins are registered during profile composition, the dsh web process must be restarted afterwards — for container deployments this means docker restart <container>. After restart a dedicated settings page appears at Settings → SiYuan Notes with four cards (Connection, API token, Default notebook, Tool toggles), each saving independently, disabling its button when unchanged and showing an Undo affordance after edits; the Test Connection button probes SiYuan using the in-progress address and token without requiring a save first. API tokens are stored in the DSH credentials vault, the settings page never echoes the value, and tokens injected via the SIYUAN_TOKEN environment variable lock the input as read-only.
The plugin registers 17 model-facing tools named siyuan_*, grouped in the UI as read, write, daily, and danger; each row toggles individually, the whole row is clickable, and Space/Enter also flips the switch, while group headers can flip every tool in the group and show a half-state when only some are on. Default-on is read and daily; write and danger default off because they mutate or delete vault content, and users are expected to enable them progressively after observing read behaviour. A bottom Re-read control reloads from DSH and discards unsaved edits, and a global Deactivate-all button collapses every toggle instantly. Per-tool state is persisted to $DSH_HOME/storages/siyuan/config.json under a tools map; older per-group configs continue to load but migrate on the next toggle save.
On the integration side the plugin talks to SiYuan at whatever address the dsh process can reach (default http://127.0.0.1:6806), so cross-machine setups must use an address SiYuan answers on, and writes to closed notebooks are refused. Known limits include: one document/block per call, no extra size cap on read output (long docs consume context), the SQL tool accepts a single SELECT and rejects internal semicolons even inside string literals, and deletes have no second confirmation because SiYuan's own recycle bin already restores them. The settings nav icon is patched onto the shell DOM by the plugin and may silently revert to the default gear if upstream changes the panel structure. The project is MIT-licensed, unofficial, and unaffiliated with SiYuan; users on DSH 0.1.7-alpha.1 or newer must run 0.0.3+ because 0.0.2 fails with non-JSON responses due to an undici upgrade in the host.
dsh-siyuan 是一个面向 DeepSeek Harness(DSH)的原生插件,把思源笔记(SiYuan)接入宿主,让模型能检索、读取并写入本地笔记库。安装命令为 dsh plugin --profile web add @yoursc/dsh-siyuan,新增或删除插件条目后必须重启 dsh web 进程才会加载;容器部署下可执行 docker restart <container>。插件在 DSH 配置分区(设置 → 思源笔记)下注册一张独立设置页,含连接、API token、默认笔记本、工具开关四张卡,每张卡各自保存,按钮在无改动时禁用,改过会出现撤销;测试连接会直接用正在编辑的地址与 token。
模型侧暴露 17 个 siyuan_* 工具,按只读 / 写入 / 日记 / 危险四组排列,组标题上的开关控制整组开合,每行还能逐个工具切换,整行可点、选中后空格或回车也行。默认仅启用只读与日记两组,写入与危险组默认关闭,以避免模型直接改动笔记库;用户可按需在设置页逐个开启。所有工具调用从 DSH 视角访问思源,思源与 DSH 不在同一机器时需填写对方可访问到的地址,笔记本必须在思源里打开,否则写入会被直接拒绝。
依赖上需自备可访问的思源实例(默认 http://127.0.0.1:6806),API token 存储于 DSH 宿主凭据库、设置页永不回显值,若通过 SIYUAN_TOKEN 环境变量注入则页面输入框置灰。已知限制包括:一次工具调用只处理一个文档或块、读取输出无额外大小上限、SQL 工具只接受单条 SELECT、批量操作由模型多次调用完成。插件为 MIT 协议,非官方,与思源项目无隶属关系;0.0.2 在 DSH 0.1.7-alpha.1 及以后会因 undici 升级而全部工具不可用,请升到 0.0.3 及以上。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-siyuan(yoursc/dsh-siyuan)
仓库:https://github.com/yoursc/dsh-siyuan
本站详情页:https://www.yhbd.top/plugins/yoursc-dsh-siyuan/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-30 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @yoursc/dsh-siyuan
把 yoursc/dsh-siyuan 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-siyuan
把 思源笔记(SiYuan)接入 DeepSeek Harness:让模型能检索、读取、 写入你的笔记库,并提供一个独立设置页管理连接与权限。
- 模型侧:17 个
siyuan_*工具,逐个工具开关(设置页里按只读 / 写入 / 日记 / 危险四组 展示,组标题上的开关可以整组开合);默认只开只读与日记两组。 - 设置页:设置 → 思源笔记,四张卡——连接、API token、默认笔记本、工具开关。 每张卡各自保存(只提交本卡字段),改完地址不保存也能直接「测试连接」。
- API token 存在宿主的凭据库里,设置页永不回显它的值。
设置页长这样(整页截图:连接 / API token / 默认笔记本 / 工具开关;开关按只读、写入、 日记、危险四组排列,组标题上的大开关管整组,下面每个工具还有自己的小开关):

想改这个插件、或了解它是怎么实现的,请读
docs/DEV.md。 各版本改了什么见CHANGELOG.md。
安装
dsh plugin --profile web add @yoursc/dsh-siyuan
安装后必须重启 dsh web 才会加载插件——重启你启动 dsh web 的那个进程:
# 容器部署示例,容器名换成你自己的
docker restart <container>
插件是在 profile 组合树装载时注册的,新增/删除插件条目后重启是必需的。 从 0.0.x 升级到带逐工具开关的版本也要重启一次(宿主侧的配置形状变了), 之后改设置页里的任何内容都只用刷新页面。
DSH 0.1.7 用户请用 0.0.3 及以上:0.1.7-alpha.1 起宿主内置的 undici 升级后,经代理
dispatcher 的响应不再自动解压(content-encoding 还会被丢掉),0.0.2 会因此报
「返回了非 JSON 响应(HTTP 200)」、所有工具都不可用;0.0.3 起改成自适应解码,新旧宿主
都能正常工作。
配置
打开 设置 → 思源笔记,四张卡各管一件事,各自保存(按钮只提交本卡字段, 没有改动时是禁用的,改过会出现「撤销」):
- 连接 · 思源地址:默认
http://127.0.0.1:6806。注意这是以 dsh 进程所在机器的视角 去访问的——思源和 dsh 不在同一台机器时,要填对方能访问到的地址。改完点「保存地址」。 旁边的「测试连接」直接用你正在编辑的地址(不必先保存),逐项探测系统版本、笔记本列表、 SQL 查询,并显示实际探测的地址。 - API token:在思源 → 设置 → 关于 → API token 里复制,粘贴后点「保存 token」。
保存后写入宿主凭据库。卡片标题上的徽标说明它的状态,例如
token 已配置 · 存在 dsh 凭据库 · 可在页面修改、token 已配置 · 来自环境变量 · 页面不可改、token 未配置——徽标只报告状态,永不回显 token 的值。当 token 来自只读来源 (例如启动 dsh web 时设的环境变量SIYUAN_TOKEN),输入框和保存/清除按钮会置灰, 想改成在页面里管理就去掉那个环境变量并重启 dsh web。「测试连接」也会用你刚填进来、 还没保存的 token。 - 默认笔记本:打开这一页会自动拉一次笔记本列表(同样用正在编辑的地址),所以配置过
默认笔记本的话,再进来直接就能看到它的名字;拉不到时不会弹错误打扰你(列表还没回来时,
下拉里显示的是已保存的 id),可以点「刷新笔记本」重试。选好后点「保存笔记本」。
写入、日记、按路径列文档默认用它;工具调用里也可以显式传
notebook覆盖。 - 工具开关:每个工具一个椭圆开关,按只读 / 写入 / 日记 / 危险四组排列;整行都能点切换 (不必瞄准 34×20 的小圆钮,选中时按空格/回车也行;在行内拖选文字不会误切换)。组标题上的开关 可以整组开合(组内只开一部分时显示为"半开"),底部「全部停用」一键收回所有权限。 点「保存开关」即时生效(不需要重启 dsh)。
- 底部「重新读取」从宿主重新拉一遍配置——会丢弃还没保存的改动(页脚会提示)。
工具分组
工具可以逐个开关;下表的分组只决定设置页里的排列与「新建时的默认值」:
| 分组 | 新建时默认 | 工具 |
|---|---|---|
read 只读 |
开 | siyuan_list_notebooks、siyuan_search、siyuan_sql、siyuan_read_doc、siyuan_list_docs、siyuan_get_child_blocks、siyuan_get_block_attrs |
write 写入 |
关 | siyuan_create_doc、siyuan_append_block、siyuan_insert_block、siyuan_update_block、siyuan_set_block_attrs、siyuan_move_doc、siyuan_rename_doc |
daily 日记 |
开 | siyuan_daily_note(读写指定日期的日记,不存在时按笔记本的 dailyNoteSavePath 创建) |
danger 危险 |
关 | siyuan_delete_block(内容块)、siyuan_remove_doc(整篇文档)——都必须显式传 confirm=true |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
ruvnet/ruflo
Tencent/WeKnora
EverMind-AI/EverOS
MemTensor/MemOS
plastic-labs/honcho
agentscope-ai/ReMe
zilliztech/memsearch
vshulcz/deja-vu