zmh2000829/dsh-x-connect

Project Overview项目介绍

dsh-x-connect is an X (formerly Twitter) API v2 connector plugin built specifically for DeepSeek Harness, binding a single X account to a local DSH instance through OAuth 2.0 Authorization Code with PKCE for a public/native client. Installation is performed with the shell command dsh plugin --profile web add dsh-x-connect, after which dsh web is restarted and the X Connect card under Settings → Plugins accepts the OAuth 2.0 Client ID minted in the X Developer Console, with the loopback callback registered as http://127.0.0.1:56130/callback. No client secret is ever transmitted, because public-client PKCE only needs the Client ID, and the loopback listener only runs while an authorization is pending rather than as a permanent service.

Eight agent tools are exposed to the active DSH model so it can search, read, and publish on X without an extra paid LLM summarizer: x_status reports local scopes and usage, x_connect and x_disconnect manage the credential, x_me reads the bound profile, x_search queries recent posts, x_user_tweets reads a timeline starting at five posts, x_tweet fetches one post by URL or ID, x_post publishes after one-time DSH approval, and x_activity_log inspects or clears the local audit trail with that same approval gate.

The plugin depends only on Node and the metered X Developer API, so users must configure scopes tweet.read, users.read, and offline.access and add tweet.write for posting; current public rates shown in the README are $0.005 per Post read, $0.010 per User read, $0.015 per plain-text create, $0.200 per URL-bearing create, and $0.001 for eligible owned reads. Credentials are stored at ~/.dsh/x-connect/credentials.json with file mode 0600 and never returned to the browser card or model, publishing and log deletion fail closed without an interactive approver, development uses npm ci && npm run check && npm pack --dry-run, and the project is released under the MIT license.

dsh-x-connect 是一款为 DeepSeek Harness(DSH) 量身打造的 X(原 Twitter)API v2 连接插件,通过 OAuth 2.0 授权码加 PKCE 公共客户端流程,把单个 X 账号绑定到本地 DSH 实例。安装方式为 dsh plugin --profile web add dsh-x-connect,随后重启 dsh web 并在「设置 → 插件 → X Connect」中输入 X 开发者后台创建的 Client ID,本地仅在授权期间启动 127.0.0.1 的回环监听。

插件向当前 DSH 模型暴露八组工具,涵盖 x_status、x_connect/x_disconnect、x_me、x_search、x_user_tweets、x_tweet、x_post 与 x_activity_log,可读取、检索账号时间线并按用户一次性确认后发文或回帖,避免重复接入收费 LLM 做摘要。

依赖仅 Node 与官方 X API 计费,凭据以 0600 权限写入 ~/.dsh/x-connect/credentials.json,不向浏览器或模型回传。X 按次收费,插件显示保守估价但以开发者控制台账单为准;许可证 MIT,日常推送建议 maxResults: 5 起,并优先使用已知 URL 的 x_tweet。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-x-connect

把 zmh2000829/dsh-x-connect 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-x-connect

简体中文

An X API v2 connector for DeepSeek Harness. It binds one X account through OAuth 2.0 Authorization Code with PKCE and gives the agent tools to search, read, summarize, and publish posts.

Features

  • Configure and bind an account in Settings → Plugins → X Connect.
  • Test the saved account connection from the settings card.
  • Search recent posts, read a post or a user's timeline, and return structured content for the active DSH model to summarize.
  • Publish posts and replies only after DSH asks the user for one-time approval by default.
  • Refresh OAuth tokens locally and keep an action/cost audit log.
  • Never sends an OAuth client secret: X public-client PKCE needs only a Client ID.

Install

dsh plugin --profile web add dsh-x-connect

Restart dsh web, then open Settings → Plugins → X Connect. For local development, pass the repository's absolute path instead of the package name.

X application setup

  1. Create a project and app in the X Developer Console.
  2. Enable OAuth 2.0 and configure a public/native client with Authorization Code + PKCE.
  3. Register http://127.0.0.1:56130/callback as a callback URI, or enter another loopback HTTP URI with an explicit port in both X and the plugin.
  4. In DSH settings, enter the OAuth 2.0 Client ID and save.
  5. Keep tweet.read, users.read, and offline.access; enable tweet.write for publishing.
  6. Select Generate authorization link, authorize in X, return to DSH, and select Test connection.

The callback listener starts only while an authorization is pending. It is not a permanent web service and is not exposed beyond the local loopback interface.

Agent tools

Tool Capability
x_status Account, scopes, callback and estimated usage status
x_connect / x_disconnect Bind or remove the local OAuth credential
x_me Read the bound account profile
x_search Search recent X posts
x_user_tweets Read recent posts from an account
x_tweet Read one post by ID or URL
x_post Publish a post or reply after user approval
x_activity_log Inspect or, after approval, clear local activity

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-ppt-composer 下一个 Next dsh-stash →