zz-zhi54/dsh-plugins
Project Overview项目介绍
dsh-plugins is an unofficial, community-maintained collection of DeepSeek Harness (DSH) plugins organized as a pnpm workspace monorepo, currently at version v0.2.0-rc.2.1 with explicit compatibility for DSH v0.1.7-rc.2, v0.2.0-rc.1, and v0.2.0-rc.2. The repository ships four independently installable packages: system-notification (side-channel listener for task and approval events that surfaces native macOS/Windows notifications), codex-login (one-shot ChatGPT/Codex OAuth entry, intended to be removed after first login), codex-usage (a footer widget that reuses DSH's own Codex credentials to render the 5-hour and weekly quota with a reset countdown), and session-cost (an inline USD provider/model cost line under the existing token statistics row). Installation happens straight from GitHub subpaths via dsh plugin --profile web add 'github:zz-zhi54/dsh-plugins#path:packages/<name>', with no clone required.
The plugins are aimed at DSH users who want narrow, non-intrusive add-ons around their daily workflow: developers who need background visibility into session progress, want to monitor Codex quota without re-authenticating, or want a per-session USD cost tally attached to the chat footer. A typical setup first installs codex-login to complete the initial OAuth, then layers in codex-usage — which reads the same llm-pi-ai/openai-codex credential store in read-only mode and never refreshes tokens — followed by session-cost and system-notification as desired, with each package removable by its dsh-<name>-plugin package name via dsh plugin --profile web remove. Every plugin mounts as an independent Profile layer and does not touch the Agent loop, approval pipeline, or any other core DSH flow.
On the dependency side, the repo centralizes resolution through pnpm at the workspace root with pnpm-lock.yaml, and sub-packages must not be installed with npm or yarn; runtime wiring is declared in each package's cordis.patch.yml, referenced from package.json via dsh.bundle.patch, with real logic kept inside packages/*/src. Caveats worth noting: codex-login is disposable after first login, side-channel failures must never affect DSH's main flow, and plugins are deprioritized or retired once official DSH features cover the same capability. The project is released under Apache-2.0 while third-party dependencies and DSH itself remain under their own terms; a recommended first-run sequence is pnpm install then pnpm check at the repository root, finishing with dsh --profile web --dump-config to confirm the installed profile entries.
dsh-plugins 是个人维护的 DeepSeek Harness(DSH)非官方插件集合,以 pnpm workspace monorepo 组织,当前版本 v0.2.0-rc.2.1,兼容 DSH v0.1.7-rc.2、v0.2.0-rc.1、v0.2.0-rc.2。仓库提供四个可独立安装的插件:system-notification(监听任务状态与审批事件,发送 macOS/Windows 原生系统通知)、codex-login(提供 ChatGPT/Codex OAuth 登录入口,登录后即可卸载)、codex-usage(在输入框下方显示 Codex 5 小时/每周额度与重置倒计时)以及 session-cost(在 Token 统计行下方显示会话费用与 USD 统计)。安装通过 dsh plugin --profile web add 'github:zz-zhi54/dsh-plugins#path:packages/<name>' 直接从 GitHub 子目录装载,不需 clone 仓库。
这些插件面向需要在 DSH 工作流中扩展旁路能力的用户:希望离线监控会话进度、复用 DSH 自带 Codex 凭据查看用量、按会话核算支出成本的开发者。典型流程是先单独安装 codex-login 完成首次 OAuth,再安装 codex-usage 读取同一份 llm-pi-ai/openai-codex 凭据展示额度(只读不写、不刷新 token),按需叠加 session-cost 与 system-notification,最后用 dsh plugin remove <package> 卸载临时插件。每个插件作为独立 Profile layer 接入,不接管 Agent 循环、审批流程或 DSH 主流程。
依赖方面,仓库根目录使用 pnpm 与 pnpm-lock.yaml 统一管理依赖,子项目不得使用 npm 或 yarn 单独安装;运行时通过 package.json 的 dsh.bundle.patch 指向 cordis.patch.yml 插入 Profile 条目,业务实现留在 packages/*/src。局限在于:codex-login 是临时插件登录后应卸载;notification 失败不应影响主流程;DSH 官方提供等价能力时插件会被标记废弃。许可证为 Apache-2.0,第三方依赖与 DSH 本身仍遵循各自条款;首次运行建议先执行 pnpm install 与 pnpm check,再用 dsh --profile web --dump-config 校验安装结果。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugins(zz-zhi54/dsh-plugins)
仓库:https://github.com/zz-zhi54/dsh-plugins
本站详情页:https://www.yhbd.top/plugins/zz-zhi54-dsh-plugins/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 2 · 最近提交 2026-09-30 · 主语言 JavaScript · 未检测到 DSH 插件清单
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
- No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add 'github:zz-zhi54/dsh-plugins#path:packages/system-notification'
把 zz-zhi54/dsh-plugins 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugins
个人维护的 DeepSeek Harness(DSH)插件集合,以 pnpm workspace monorepo 组织。可独立安装的插件位于 packages/*。
这是个人维护的非官方社区项目,不隶属于 DeepSeek AI 或 DeepSeek Harness 官方团队。
本 README 是用户入口,负责项目选择、安装方式和仓库结构;各项目 README 负责记录自身的具体行为和限制。安装章节会列出当前 workspace 中的插件及版本示例;实际版本、DSH 兼容关系及发布记录请以
CHANGELOG.md和各项目的package.json为准。
项目总览
当前 workspace 兼容目标为 DSH v0.2.0-rc.2,并保留对 v0.2.0-rc.1 和 v0.1.7-rc.2 的兼容。经核对,插件使用的 Host Service、Event、Session 投影、Web 扩展槽位及 Client ModuleLoader 注册契约未变;session-cost 继续使用 Session 投影 seam。
| 项目 | 类型 | 包名 | 用途 | 详细说明 |
|---|---|---|---|---|
packages/system-notification |
按需插件 | dsh-system-notification-plugin |
旁路监听任务状态和审批事件,发送 macOS / Windows 原生系统通知 | README |
packages/codex-login |
按需临时插件 | dsh-codex-login-plugin |
提供 ChatGPT / Codex OAuth 登录入口;首次登录完成后即可卸载 | README |
packages/codex-usage |
按需插件 | dsh-codex-usage-plugin |
在输入框下方显示 Codex 的 5 小时 / 每周额度与重置倒计时,复用 DSH 自己的 Codex 凭据 | README |
packages/session-cost |
按需插件 | dsh-session-cost-plugin |
在 Token 统计行下方显示当前会话的 provider/model 费用与 USD 统计 | README |
项目关系
- 每个插件都可以独立安装、更新和卸载,不再维护组合 pack。
- Codex 用量插件读取同一份
llm-pi-ai/openai-codex凭据;它只读凭据、不写凭据,也不自己刷新 token。 - Codex 登录插件仅用于首次登录;登录完成后即可卸载。
设计原则
- 最小依赖、最少代码:只引入完成目标所需的依赖,优先复用 DSH 已提供的服务和扩展点。
- 轻量、稳定:围绕实际使用场景提供小而明确的能力,不追求覆盖所有场景,优先控制维护成本。
- 最小侵入:插件以独立 Profile layer 接入,不修改 DSH 核心,不接管 Agent 循环、审批流程或其他主流程。
- 开放协作:欢迎社区通过 Issue 和 Pull Request 提交问题、建议、文档、测试或实现;贡献应尽量保持独立、低依赖和低侵入。
- 稳定优先:优先保持现有行为和公开契约;通知等旁路能力失败时,不应影响 DSH 主流程。
- 上游优先、可撤销:当 DSH 官方提供等价能力时,对应插件会停止维护、标记废弃并删除,而不是长期保留重复实现。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
extracurricular-ai/dsh-filesnap
SenmuuuuW/dsh-whale-report
SnowCrescenter-tech/dsh-milestone
PerryLink/dsh-checkpoint-rewind
XieZongChen/dsh-md-notes
TencentCloud/tencentcloud-agentobs-sdk-dsh