DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Plugin Kit — DeepSeek Harness 插件(DSH Plugin)
← Plugins

@perrylink/dsh-plugin-kit

Plugin Kit

PerryLink DSH 插件的共享零运行时依赖工具包:可插拔的 Provider 注册表接入点、故障关闭式审批和自适应会话事件门控、机械化验证脚本、共享的清理/定价/评判模块,以及新插件骨架。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add @perrylink/dsh-plugin-kit@0.1.9
README兼容性版本

兼容性与来源证明

Plugin Kit 以 @perrylink/dsh-plugin-kit 发布,当前版本为 0.1.9。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.1.9stable
2026/9/12
0.1.8stable
2026/9/10
0.1.7stable
2026/9/9
查看其余 7 个版本收起版本
0.1.6stable
2026/9/7
0.1.5stable
2026/9/4
0.1.4stable
2026/9/2
0.1.3stable
2026/9/1
0.1.2stable
2026/8/30
0.1.1stable
2026/8/30
0.1.0stable
2026/8/30

相关插件

正在加载相关插件…

最新版
0.1.9
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
247.3 kB
文件数
91
Surface
any
许可证
Apache-2.0
发布源
npm
GitHub
★ 0
周下载
67
最近提交
2026/9/19
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

README

@perrylink/dsh-plugin-kit

  • 1024 store channel: npm i -g dsh1024 once, then dsh1024 plugin --profile web add @perrylink/dsh-plugin-kit (counts toward the deepseek1024.com install ranking).

Shared zero-runtime-dependency toolkit for the PerryLink DSH plugin repositories. The per-project audit found 20+ of the 33 plugins hand-rolling the same Provider seam and duplicating the same sanitize/pricing/verdict shapes, so this package extracts all of it — the pluggable Provider seam, the fail-closed approval and adaptive session-event gates, the mechanical verify scripts, and the shared sanitize/pricing/judge pure modules — into one ESM + TypeScript package.

Compatibility

  • DSH harness: the kit imports nothing from @deepseek-ai/* at runtime. @deepseek-ai/cordis (^4.0.2), @deepseek-ai/schemastery (^3.18.2), and the @deepseek-ai/dsh-* packages are optional peer dependencies in the >=0.1.2-rc.1 <0.2.0 band the PerryLink plugin repos share; they exist only for type interop. Verified 2026-09-11 against the dsh-v0.1.5-rc.2 master checkout (full gate chain + profile install smoke).
  • Node: ^22.19.0 || >=24.0.0, ESM only.
  • Wire compatibility: names and shapes mirror dsh-mask (sanitize), dsh-budget (pricing), and dsh-auto-review (judge and the fallbackPolicy vocabulary), so migration is mechanical.

What you get

  • Zero runtime dependencies — the pure core (seam, gates, shared) is browser-safe.
  • ESM + strict TypeScript — JSDoc contracts on every module; strict, noUncheckedIndexedAccess, exactOptionalPropertyTypes.
  • Fail-closed and adaptive gates — approval never defaults to a grant; session-event appends degrade gracefully on hosts that reject unknown event types.
  • A new-plugin skeleton — template/ with cordis.yml, a three-role src/index.ts (Service Definition / Provider / Consumer), a test, and the shared Renovate preset.

Quick start

From npm:

pnpm add @perrylink/dsh-plugin-kit

From git (the prepare script builds lib/ using only production dependencies):

pnpm add github:PerryLink/dsh-plugin-kit

Replace a hand-rolled registry in one step:

import { ProviderRegistry } from '@perrylink/dsh-plugin-kit/seam'

const registry = new ProviderRegistry<Detector>({
  default: { name: 'regex', impl: new RegexDetector() },
})
ctx.effect(() => registry.register('ner', new NerDetector()))
const active = registry.use('ner') ?? registry.use()

Install & uninstall

Install is pnpm add (see Quick start). Remove with:

pnpm remove @perrylink/dsh-plugin-kit

Nothing registers global state: uninstall is exactly the reverse of install.

Configuration

No runtime configuration: the gates and helpers are pure functions. The only configuration surface is cordis.patch.yml, the bundle-patch layer shipped for harness profile composition; it mounts no plugin row (the kit is a library) and documents how consuming plugins add their own rows.

Tools & surfaces

SubpathPurpose
seamProviderRegistry<T> — reversible, fail-loud named provider registry.
gatesapplyFailClosed; makeEventGate / maybeAppendSessionEvent / probeIgnorableAppend.
sharedsanitize (Stripper, redactText, redactMapping, sanitizeText, sanitizeUrl), pricing (BUILTIN_PRICES, estimateUsageCost, tokenCarbon, latencyStats, formatMoney, formatTokens), judge (parseVerdict, VERDICT_SCHEMA, riskExceeds).
verifyMechanical CI gates (verify-license, verify-readme-languages, verify-seam) with a VerifyReport and a non-zero-exit CLI: node lib/verify/cli.js all .
template/New-plugin skeleton (cordis.yml, three-role plugin, test, README, renovate.json5).
root barrelRe-exports all of the above.

Permissions & data

The kit performs no I/O, no network access, and no subprocess spawns on its own. Stripper keeps placeholder→original mappings in memory only, and stats()/redactMapping() never emit plaintext; a consumer that persists a mapping owns that decision and its storage permissions.

Security boundaries

  • sanitize/redact* are display hygiene, not a security boundary: they reduce leakage into logs and results, they do not authenticate or authorize.
  • Approval gates are fail closed by default (rejected); the only grant path is an explicit allow-once opt-in.
  • Session-event appends the host refuses are skipped, never retried in a way that could break session resume.
  • Report vulnerabilities via GitHub Security Advisories — see SECURITY.md.

Known limitations

  • Hosts whose Session.append third argument is a SurfaceIntent (0.1.2-rc.1) throw validateNext on the ignorable-envelope probe; the gate degrades to skip-unknown, so audit events are dropped (fail closed) rather than logged on those hosts.
  • 0.1.2-rc.1 (adapted 2026-09-02): the session envelope keeps its ignorable field for stored-log read compatibility only - Session.append still cannot stamp it, so audit-gate behavior is unchanged.
  • The kit ships no browser UI half; it is a library consumed by the Host (and optionally Client) halves of other plugins.

Development

pnpm install
pnpm run typecheck        # tsc --noEmit
pnpm run typecheck:ci     # CI face: tsc -p tsconfig.ci.json --noEmit
pnpm test                 # vitest unit tests
pnpm run build            # emit lib/ + declarations (also run by prepare)
pnpm run verify:self-contained
pnpm run verify:artifacts

Topics

This repository is also the maintenance hub for the 33 plugin repos: scripts/sync-peer-range.mjs re-pins the shared peer band across all repos in one command, renovate/default.json5 is the shared Renovate preset every repo extends, .github/workflows/npm-publish.yml is a reusable tag-triggered publish workflow (needs only an NPM_TOKEN secret), and data/repos.json is the ecosystem registry consumed by the portal. See docs/ecosystem-tooling.md.

Keywords: dsh, dsh-plugin, deepseek-harness, deepseek, cordis, perrylink, provider, seam, approval, sanitize, pricing, judge.

Contributors

Maintained by PerryLink with contributions from the DSH plugin ecosystem.

License

Apache-2.0 — see LICENSE.

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序