yuyi2439/dsh-1bot
Project Overview项目介绍
This is a DSH-native plugin that bridges OneBot 11 protocol, the standard for QQ chat clients like NapCat, LLOneBot and Lagrange, to DeepSeek Harness. It adds a new OneBot UI profile to DSH that runs parallel to the existing web and TUI interfaces, built on top of the official @deepseek-ai/dsh-base base layer. To install it, you can run the simple DSH CLI command dsh plugin --profile onebot add dsh-1bot which initializes the profile and installs the package from npm automatically. After installation, you will need to edit the generated configuration file to add your OneBot connection details.
This plugin is designed for developers and users who want to expose DSH agent capabilities through the QQ chat channel. Each incoming QQ message from a private or group chat triggers a new agent turn for a dedicated DSH agent and session that corresponds to that specific chat. Unlike default setups, automatic sending of replies at the end of a turn is disabled, so the model must explicitly call the onebot_send tool to send a reply, which prevents duplicate responses. Each session gets its own dedicated working directory, and all session data is persisted as JSONL so you can resume it later if the process restarts.
This plugin is released under the open-source Apache 2.0 license, with core logic ported from the Rust-based nota project. It requires a running OneBot 11 forward WebSocket service to work, and only supports the ws connection mode. To prevent corrupted session logs from concurrent writes, only one instance of the plugin can run at a time, and it uses a lock file to enforce this. It also includes quality of life features like whitelist filtering, spam protection, and connection failure diagnostics. On first run, it will automatically generate a commented configuration template and exit, prompting you to edit it before starting the bridge.
这是一个专为DeepSeek Harness(DSH)开发的原生插件,可将OneBot 11协议(用于NapCat、LLOneBot、Lagrange等QQ客户端实现)转换为DSH的一个UI交互层面,与DSH现有的web、TUI界面平级。它基于@deepseek-ai/dsh-base开发,每个QQ私聊或群聊对应一个独立的DSH agent与会话,可通过DSH的命令行工具直接安装配置。
该插件适合需要将DSH的agent能力通过QQ渠道对外开放的开发者或用户使用。典型工作流为:用户在QQ发送消息触发DSH的agent回合,模型需要主动发送回复时必须显式调用插件提供的onebot_send工具,避免了回合结束自动投递导致的重复回复问题。每个QQ会话会单独分配工作目录,持久化保存会话数据,支持断点恢复。
该插件采用Apache 2.0开源协议,核心逻辑移植自Rust编写的nota项目。它依赖已经运行的OneBot 11正向WebSocket服务,仅支持ws模式连接,限制单实例运行避免会话日志损坏,还支持白名单过滤、刷屏防护、连接失败诊断等功能。首次启动会自动生成配置模板提示用户编辑,配置错误会给出清晰的诊断信息。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-1bot(yuyi2439/dsh-1bot)
仓库:https://github.com/yuyi2439/dsh-1bot
本站详情页:https://www.yhbd.top/plugins/yuyi2439-dsh-1bot/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 2 · 最近提交 2026-09-17 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile onebot add dsh-1bot
把 yuyi2439/dsh-1bot 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-1bot
把 OneBot 11(QQ,NapCat / LLOneBot / Lagrange)变成 dsh 的一个 UI 表面 —— 与 web / tui
平级的 profile bundle,骑在 @deepseek-ai/dsh-base 之上。每个 QQ 聊天(私聊/群)对应一个
dsh agent + session:消息进来驱动回合;自动发送已移除——模型要说话必须显式
调用 onebot_send(每次调用立即发送),因为回合末自动投递会与模型主动发送
重复(双重回答)。
逻辑移植自 nota 项目(Rust)的 OneBot 桥接实现,Apache-2.0。
快速开始
dsh plugin --profile onebot add dsh-1bot # 初始化 profile 并从 npm 安装
编辑 $DSH_HOME/profiles/onebot/cordis.patch.yml(id 定向 patch 整段替换 config,需重述所有字段):
- id: onebot
config:
enabled: true
mode: ws
ws_url: 'ws://127.0.0.1:3001' # NapCat 正向 WS 地址
access_token: ''
prefix: ''
friend_ids: [123456789] # 白名单:你的 QQ
group_ids: [] # 白名单:群
reply_chunk_size: 4000
max_pending_turns: 8
console_log: true
启动(NapCat 需开着正向 WS):
dsh --profile onebot
配置
| 字段 | 默认 | 说明 |
|---|---|---|
enabled |
false |
启动桥接 |
mode |
ws |
仅支持 ws(正向 WebSocket) |
ws_url |
ws://127.0.0.1:3001 |
OneBot 实现地址 |
access_token |
"" |
可选令牌,以 ?access_token= 查询参数附加到 ws_url(OneBot 11 正向 WS 约定) |
prefix |
"" |
只回复以它开头的消息,并剥掉前缀。群聊生产环境强烈建议设置:留空时白名单内的每条消息都会触发一次完整 agent 回合(成本),刷屏时还会把队列堆到上限 |
friend_ids |
[] |
私聊白名单;空 = 无人可入 |
group_ids |
[] |
群白名单;空 = 无群可入 |
workspace_root |
$DSH_HOME/workspaces/onebot |
聊天工作区根;每聊天一个 <root>/chats/<sessionId> 子目录(自动创建)。稳定路径,勿用随启动目录变化的路径,否则会话 cwd 冲突 |
connect_retries |
5 |
启动连接失败后的重试次数(每次间隔 connect_retry_delay_secs) |
connect_retry_delay_secs |
1 |
启动连接重试间隔(秒) |
reply_chunk_size |
4000 |
出站消息分块上限 |
reply_chunk_delay_ms |
300 |
同一条回复的分块发送间隔(毫秒),避免多块连发触发 QQ 风控 |
max_pending_turns |
8 |
每聊天排队回合上限(含正在运行的一个);超出上限的新消息被丢弃并告警(刷屏防护) |
console_log |
true |
把 onebot 日志打到控制台 |
工具
onebot_send(唯一发送途径,即时发送,可多段:先回复、查资料、再回复)、onebot_get_msg_history(群/私聊历史)、onebot_get_content、onebot_status(含连接状态)、
onebot_voice_text。统一 onebot_ 前缀(send_message 是子 agent 控制的保留名)。
自动发送已移除:所有出站消息都由模型显式调用 onebot_send 发送;prompt/persona 注入不在本插件内(纯 adapter,由独立的 persona 层插件负责)。
非白名单目标的 onebot_send 直接报错——QQ 内审批流已移除,白名单外一律直接拒绝。
行为要点
- 入站非文本段按类型渲染(默认
[<type> msg id:N k=v …],带上全部 data 和消息 id),模型用onebot_get_content/onebot_voice_text取内容。 - 每聊天一个 agent/session(
onebot-private-<QQ>/onebot-group-<群号>,用-分隔避免磁盘转义),JSONL 持久化、可 resume;每聊天一个独立工作区<workspace_root>/chats/<sessionId>。 - 白名单为空 = 所有消息被忽略(启动时控制台会警告)。
- 日志形如
[onebot info] 2026-…;掉线会看到reconnecting重试日志——连接断开后按connect_retries有界重试,耗尽后停止(重新可用需重启进程)。 - 首次启动若配置里没有 onebot 配置:自动在
$DSH_HOME/profiles/onebot/cordis.patch.yml追加带注释的配置模板并提示你编辑,然后退出;编辑好再启动。 - 启动连不上 OneBot 是致命的:重试
connect_retries次(默认 5 次 × 1 秒)后报错退出,并打印一条自足诊断:失败原因、实际尝试的ws_url、access_token是否设置、解析后的配置文件路径、重试预算,以及实测 TCP 可达性给出的下一步(端口没人监听 → 启动实现端;端口通却被拒 → 核对令牌/路径)。此路径不写配置文件(唯一写配置的是首次运行的模板门);改完运行dsh --profile onebot。 - 单实例:第二个 dsh-1bot 进程会因锁(
<workspace_root>/.onebot.lock)拒绝启动 —— 两个实例同时写同一会话会损坏日志。 - 会话与 web 隔离:onebot 会话持久化在
$DSH_HOME/sessions-hidden(非sessions/)。web UI 打开它可见的会话会 resume 成第二个写入者导致日志损坏,隔离后 web 看不到也碰不到;监视请用 onebot 进程控制台日志。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
whiteguo233/dsh-openbiliclaw
hanshanyike/dsh-yolo
AX1202/ax-feishu-bridge
amlyczz/dsh-lark-link
MichengAI/dsh-im-connect
caoyiwei850/dsh-ssh-ops
jiezeng2004-design/dsh-chatgpt-bridge