zp-home/dsh-dev-sandbox
DSH插件开发者沙箱:生成隔离的DeepSeek Harness Web镜像实例(拥有各自的DSH_HOME/端口/配置文件),这些实例挂载正在开发的插件,并可选地继承宿主API/模型。提供GUI面板及sandbox_*代理工具。
Project Overview项目介绍
This repository is a native plugin built exclusively for DeepSeek Harness (DSH), designed to provide a safe isolated environment for DSH plugin developers. It lets you spin up a separate DSH web instance with one click, complete with its own DS_HOME directory, port assignment, and user profile. The plugin you are developing is automatically mounted into the sandbox, so any issues from testing like crashes or bad configurations will not affect your main development instance. To install, you can use the DSH CLI command dsh plugin --profile web add github:zp-home/dsh-dev-sandbox for a one-step setup, or manually configure local source hot loading if you prefer.
After installation, you can access the sandbox panel from the DSH sidebar. To start a test, simply enter the path to your plugin directory (or leave it blank for a clean base environment), select your desired configuration options like inheriting host API settings, then click create and launch. You can manage all existing sandbox instances directly from the panel, checking status, viewing logs, stopping, restarting, or destroying instances as needed. This tool is built for DSH plugin developers who want to test their work without risking their main development environment.
dsh-dev-sandbox is released under the open-source Apache-2.0 license, and welcomes community contributions via pull requests or issues. Sandboxes are real running processes, so they will consume CPU and port resources on your host machine. When you destroy a sandbox, the entire isolated directory is deleted, so always double check before confirming a destroy action. The plugin supports a range of optional configuration settings, including custom sandbox root directory, starting port, build on start, and API inheritance settings.
dsh-dev-sandbox 是专为 DeepSeek Harness 打造的原生插件开发沙盒,可一键生成完全隔离的 DSH 网页实例,拥有独立的 DS_HOME 目录、端口号和配置文件,自动挂载正在开发的测试插件。测试过程中的重启、崩溃、错误挂载都只会影响沙盒实例,不会损坏主开发环境,方便开发者安全地进行插件兼容性测试和问题复现排查。
本插件支持多种功能,包括自动发现本地插件、可选复制本机 Web 配置、支持手动输入本地插件路径、自动复用当前 DSH 环境。沙盒可注入宿主的 DeepSeek API 密钥和模型配置,也可通过侧边栏 GUI 面板和 sandbox_* agent 工具进行操作,支持状态持久化,宿主重启后自动恢复沙盒状态。
安装可通过 DSH CLI 直接从 GitHub 拉取,也支持本地源码热挂载,无需额外的 npm 安装步骤。本插件采用 Apache-2.0 开源许可,沙盒是真实进程,会占用端口和 CPU 资源,销毁时会删除整个隔离目录,操作前请务必确认内容。它还提供了详细配置项,可自定义沙盒根目录、起始端口等参数。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-dev-sandbox(zp-home/dsh-dev-sandbox)
仓库:https://github.com/zp-home/dsh-dev-sandbox
本站详情页:https://www.yhbd.top/plugins/zp-home-dsh-dev-sandbox/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 2 · 最近提交 2026-08-21 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:zp-home/dsh-dev-sandbox
把 zp-home/dsh-dev-sandbox 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
@zp-home/dsh-dev-sandbox · DSH 插件开发沙盒
English: A developer sandbox for DeepSeek Harness (dsh) plugins. One click spawns a fully isolated dsh web instance — its own
DSH_HOME, its own port, its own profile — that auto-mounts the plugin you are developing, so plugin work (restarts, crashes, bad mounts) never touches — or breaks — the development instance. Mirrors can optionally inherit the host'sDEEPSEEK_API_KEY/DEEPSEEK_BASE_URLand model settings, so you can chat with the mirror directly. Ship with a GUI panel (sidebar "沙盒") and agent tools (sandbox_*).
痛点与方案
痛点:直接在开发本体上测试插件很危险——反复重启、挂载坏掉的插件、改坏配置,都可能把开发实例搞坏,而修它又得靠别的 AI 来折腾。
方案:一键启动一个独立的 DSH web 业务镜像(自己的 DSH_HOME、自己的端口、自己的 profile),
自动把正在开发的插件挂载进去做兼容性测试。测试、重启、搞坏,都在沙盒里发生,开发本体毫发无伤。
能力
- 完全隔离:每个沙盒 = 独立
DSH_HOME(默认~/.dsh-sandboxes/<name>,含独立的 sessions / storages / settings / profiles)+ 独立端口(默认从 4000 起自动分配)+ 标准 web profile (dsh-base+dsh-web-app+ 待测插件)。销毁 = 删除整个隔离目录,零残留。 - 插件路径选填:不填插件路径 = 纯净镜像(仅标准 web 环境),适合验证插件对原生 harness 的 兼容性,或纯粹复现/排查问题。
- 本机插件选择器:面板自动发现本机 Web profile 中声明
dsh.bundle.patch的插件,按当前 profile 是否启用排序;选择后自动填写待测插件路径,也可继续手动输入其他本地 checkout。 - 本机 Web Profile 镜像(可选):创建时可复制本机
profiles/web的 bundle 清单、package.json、 Cordis 配置和已安装包链接,在新的DSH_HOME中重放本机插件组合;不复制 session、storage、缓存或凭据。 待测插件会覆盖镜像中同名包,适合复现“沙盒可用、装入本机后崩溃”的组合兼容性问题。 - 挂载待测插件:junction 把插件源码目录挂进沙盒 profile 的
node_modules,插件本体无需 pnpm 安装;沙盒自动复用当前 DSH。源码检出走tsx/esm apps/cli/src/bin.ts,全局 npm 安装走@deepseek-ai/dsh声明的编译 CLI 入口,因此两种安装方式都可用。 - 集成主机接口(默认开启):
- 注入宿主的
DEEPSEEK_API_KEY/DEEPSEEK_BASE_URL(先取宿主进程环境,再回退读宿主 home 的.env与.credentials.yaml),沙盒内直接就能与 DeepSeek 对话; - 首次启动把宿主
settings.yaml复制进沙盒 home(模型/主题默认值与宿主一致)。 - 面板勾选框「集成主机 API/模型配置」或按沙盒/全局配置可关闭。
- 注入宿主的
- 双面操作:
- GUI:侧边栏「沙盒」入口 + 面板(创建/启动/停止/重启/销毁/日志/打开测试界面/插件扫描与构建)。
- Agent 工具:
sandbox_list/sandbox_status/sandbox_start/sandbox_stop/sandbox_destroy/sandbox_logs/sandbox_build/sandbox_verify—— 让开发本体里的 AI 直接驱动沙盒。
- 生命周期可靠:状态持久化(
sandbox-state.json),宿主重启后自动校正运行状态;进程退出自动 标记;SIGTERM 优雅停止,超时强杀;沙盒可反复重启,状态保持。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
kenryu42/cc-safety-net
hyhmrright/brooks-lint
zhu1090093659/dsh-trading
lire1131/dsh-undo-savepoint
jigjoy-ai/baro
c3ll256/dsh-toy
huaweicloud/huaweicloud-devkit