dsh-plugin-safety
by Seryta
1. 预检 + 自动禁用 : scripts/check-profile-plugins.py 在 dsh-web 启动前预检 profile 中每个未禁用的插件入口;import 失败的坏插件自动写入 disabled: true (bundle 则移除 bundle),并落盘告警。 2. 持久告警 + 自动修复会话…
1. Pre-check + auto-disable: scripts/check-profile-plugins.py pre-checks every enabled plugin entry in the profile before dsh-web starts; broken plugins that fail to import automatically get disabled: true written (bundles are removed) with a warning persisted to disk. 2. Persistent alerts + auto-repair
安装
dsh plugin --profile web add github:Seryta/dsh-plugin-safetyGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
DSH 插件故障防控的最后两环:
- 预检 + 自动禁用:
scripts/check-profile-plugins.py在 dsh-web 启动前预检 profile 中每个未禁用的插件入口;import 失败的坏插件自动写入disabled: true(bundle 则移除 bundle),并落盘告警。 - 持久告警 + 自动修复会话:浏览器半部渲染红色告警卡片,× 掉前 刷新/重开页面都会重现;host 半部在返回告警前保证每个告警 action 都有 对应的 headless 修复会话。
核心不变式
只要出现“不可用插件已被禁用/需人工处理”的告警,就自动创建修复会话。 不区分告警来源:预检脚本检出、直接写
notice.json的测试/手工场景, 都遵守同一规则。
具体机制:
- host 半部
GET /plugins/dsh-plugin-safety/notice返回告警前先检查fixActionIds是否覆盖全部 action;未覆盖就调用check-profile-plugins.py --ensure-fix补启动。 - 同一批 action 只启动一次;同一份告警新增坏插件时,只为新增 action 补启动一次。
Popen成功才写fixStartedAt/fixActionIds;启动失败时前端如实 显示“修复会话自动创建失败”,不再假装已创建。- 文件锁防多个 GET/预检并发重复启动。
组件
| 文件 | 职责 |
|---|---|
index.js |
host 半部:告警读写端点 + 返回前 ensure-fix |
client.js |
浏览器半部:持久弹窗、× 关闭(POST 清除) |
scripts/check-profile-plugins.py |
预检、自动禁用、告警落盘、修复会话启动 |
cordis.patch.yml |
bundle patch:把插件挂进 profile |
dsh.plugin.json |
DSH 插件元数据 |
零第三方依赖:host/脚本仅用 Node/Python 标准库;client 为原生 DOM。
告警文件
$DSH_HOME/storages/plugin-safety/notice.json(未设置 DSH_HOME 时为
~/.dsh/storages/plugin-safety/notice.json):
{
"at": 1786799000000,
"actions": [
{
"id": "some-plugin",
"name": "some-plugin",
"kind": "patch",
"reason": "Cannot find package 'some-plugin'",
"disabledAt": 1786799000000,
"autoDisabled": true,
"profile": "/home/me/.dsh/profiles/web"
}
],
"fixStartedAt": 1786799001000,
"fixActionIds": ["some-plugin"],
"fixWorkspace": "/home/me/.dsh/plugin-maintenance",
"fixLogFile": "/home/me/.dsh/plugin-maintenance/plugin-safety-fix.log"
}
POST 同一端点即视为用户已叉掉告警,文件重置为
{"at": 0, "actions": []};下一条新告警会重新生成。
安装
dsh plugin --profile web add github:Seryta/dsh-plugin-safety
安装后重启 dsh-web(host 半部需要进程重新 import;client.js 是静态服务, 重启前刷新页面也能拿到新逻辑)。
如果同时想要启动前预检(推荐),把随包脚本放到 $DSH_HOME/scripts 并
挂到 systemd ExecStartPre:
mkdir -p ~/.dsh/scripts
cp ~/.dsh/profiles/web/node_modules/dsh-plugin-safety/scripts/check-profile-plugins.py \
~/.dsh/scripts/check-profile-plugins.py
ExecStartPre=-/home/<you>/.dsh/scripts/check-profile-plugins.py
(- 前缀表示预检失败不阻断启动;脚本对能自动禁用的失败返回 0,
对无法自动禁用且需人工处理的失败返回 1)。
验证
npm test # host/脚本/客户端逻辑测试,全部使用假 dsh,不创建真实会话
node --check index.js
python3 -m py_compile scripts/check-profile-plugins.py
本仓库的测试覆盖:
- 预检发现坏插件 → 自动禁用、备份、落盘告警、启动一次修复会话;
- 重复预检不重复启动;新增坏插件只补启动一次;
- 直接写
notice.json→ host GET 前补建修复会话,第二次 GET 不重复; - POST 清除告警;无告警返回
notice: null; - 客户端弹窗持久渲染、× 关闭、以及
fixStartedAt有无时的如实文案。
已知边界
- 浏览器只在页面加载时 poll 一次;页面开着期间新写入的告警会在下次刷新 时出现(与“刷新/重开仍在”的持久语义一致)。
- 自动修复会话是 headless DSH 任务;它本身无法修复时会在会话内报告阻塞 原因,host 不会阻塞重试。
$DSH_HOME会被 host 与预检脚本一致尊重;systemd 预检通常不设置该 变量,因此走默认~/.dsh。
License
MIT
原始 README: https://github.com/Seryta/dsh-plugin-safety/blob/master/README.md ↗
同类插件
查看全部 →
dsh-anchored-standard
两阶段 DeepSeek Harness 预设:先 Minimal 对齐的 bootstrap,再切完整 Standard 工具(Project2 98/99)

PicGo-Core
极致的图片上传引擎,CLI 与 API 双支持

awesome-deepseek-harness
DeepSeek Harness(DSH)及其优秀社区插件的精选指南。

awesome-deepseek-harness
DeepSeek Harness (DSH)生态系统:来自dsh-external/hub和公共dsh-plugin主题的精选插件、工具和基础设施。

AI-Novel-Writer
本地优先 AI 小说创作工作台,提供 Windows/macOS 桌面版与 DeepSeek Harness 插件开发预览,支持角色、大纲、章节蓝图、审稿修稿和本地模型。

mcp-for-stata
MCP-for-Stata:把 Stata 集成进你的 agent