zcx369658780/governed-workflow-for-dsh
面向DeepSeek Harness代理的基于策略强制、以证据为先的受管工作流。
Project Overview项目介绍
dsh-governed-workflow is a community plugin for DeepSeek Harness that adds task authority, lifecycle, and independent review boundaries to coding agents. It collapses free-form vibe coding into GitHub Issue authority, allows protected mutations such as bash, write, and edit only while a task is RUNNING, then freezes changes in terminal states for separate review. Best suited to multi-file, long-running projects with real release or data risk. Note: this is a V0.9 Developer Technical Preview, the IH-1 installer is not yet on main, and it is not a full OS sandbox.
dsh-governed-workflow 是面向 DeepSeek Harness 的社区插件,为 Coding Agent 增加任务权限、生命周期和独立验收边界。它将 vibe coding 收敛为:先由 GitHub Issue 给出 authority,仅在 RUNNING 期间允许 bash/write/edit 等受保护修改,进入终态后冻结并交独立 Reviewer。适合多文件、长会话、有真实上线或数据风险的项目。注意:当前为 V0.9 Developer Technical Preview,IH-1 安装脚本尚未合并到 main,且尚未提供完整 OS 沙箱。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:governed-workflow-for-dsh(zcx369658780/governed-workflow-for-dsh)
仓库:https://github.com/zcx369658780/governed-workflow-for-dsh
本站详情页:https://www.yhbd.top/plugins/zcx369658780-governed-workflow-for-dsh/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-08-20 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:zcx369658780/governed-workflow-for-dsh
把 zcx369658780/governed-workflow-for-dsh 加入你的 DSH 配置(web profile)即可启用。
READMEREADME

中文
1. 插件简介
dsh-governed-workflow 是一个面向 DeepSeek Harness 的独立社区插件,用来给 Coding Agent 增加一层明确的任务权限、生命周期和独立验收边界。
它把一个常见的 vibe-coding 流程从“给 Agent 一句话,然后让它自由修改”收敛成:先由 GitHub Issue 给出任务 authority,只有进入 RUNNING 后才允许受保护的修改,完成或阻塞后冻结修改并交给独立 Reviewer / Owner。
当前版本为 V0.9 Developer Technical Preview;已验证基线为 @deepseek-ai/dsh@0.1.0-rc.6,包名为 dsh-governed-workflow。本项目不隶属于 DeepSeek,也不代表 DeepSeek 官方背书。
2. 具体功能
工作流
GitHub Issue Authority
↓
OBSERVE
↓
ADMIT
↓
RUN
↓
BLOCK / COMPLETE
↓
REVIEW
- GitHub Issue Authority:可以从公开 GitHub Issue 中读取机器可解析的 authority block;Builder 不应从旧聊天记录、分支存在或自己的计划中推断任务权限。
- Lifecycle 状态机:任务按
AUTHORITY_OBSERVED → TASK_ADMITTED → RUNNING → BLOCKED/COMPLETED → REVIEW_PENDING推进,非法迁移 fail closed。 - RUNNING-only Mutation Guard:当前受保护的 DSH mutation tools 为
bash、write、edit;没有 accepted authority 或状态不是RUNNING时拒绝执行。 - 模型侧治理工具:提供只读的
governance_status,以及受限动作集的governance_transition。 - 终态冻结:进入
BLOCKED、COMPLETED或REVIEW_PENDING后重新禁止受保护修改。 - 独立验收边界:Builder 不能自行 ACCEPT、merge、关闭已接受任务或创建/激活后续任务;最终决定留在 Builder Runtime 之外。
- 治理证据:authority 观察与 lifecycle transition 会记录为受限治理证据,方便审查和回放。
这种工作流的取舍
优势:任务边界更清楚,能减少长会话中的 scope drift 和误修改;什么时候可以改、什么时候必须停止比较明确;对需要真实验收、回滚和审查的项目更友好。
劣势:比自由式 vibe coding 多了 Issue、状态迁移和 Review 的流程成本,因此会牺牲一部分速度;当前实现也不是完整 OS sandbox——allowedPaths 文件系统硬隔离、Git 命令语义、GitHub merge/close API 等仍不是 Runtime 强制边界。
更适合:中等及以上规模、多文件、长会话、多阶段交付、需要运行命令/修改真实代码、上线或数据风险较高的 vibe-coding 项目,例如 App、后端服务、研究工具、自动化系统和长期维护仓库。
不太适合:一次性小脚本、几分钟的 throwaway prototype、完全可丢弃的实验;这类任务的治理成本可能高于收益。
3. 安装方式
IH-1 正在把安装方式收敛为一个可维护、可 clean-room 验证的安装脚本。当前候选脚本已经是:
scripts/install-dsh-governed-workflow.mjs
候选调用方式为:
node scripts/install-dsh-governed-workflow.mjs --profile governed --ref <40位 Git commit SHA>
该脚本要求显式提供 DSH Profile 和 immutable source ref,不会默认安装浮动的 main。当前候选实现会执行固定 GitHub source install,并在安装后自动运行:
dsh --profile governed --dump-config
用于确认 Governed Workflow 的五个默认组件已经加载,同时不会自动启用可选的 GitHub Issue network-authority bootstrap。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
tt-a1i/archify
loopx-project/loopx
ZSeven-W/openpencil
omdsh-dev/DSH-better-sidebar
NanmiCoder/dsh-agent-teams
LiPu-jpg/Openwrite