dsh-resource-center

by Xs1KVerOA

0 工具与能力github未核验到 manifest收录于 08-17

dsh-resource-center 是 DeepSeek Harness 的资源中心插件。它把工作区会话树、服务管理和其他插件 Activity 统一到一个 VSCode 风格的侧栏中,并把服务配置与操作页面切换到 Harness 的中央内容区。

dsh-resource-center is a resource-center plugin for DeepSeek Harness. It unifies the workspace session tree, service management and other plugin activities into a VSCode-style sidebar, and moves service configuration and operation pages into the Harness central content area.

安装

dsh plugin --profile web add github:Xs1KVerOA/dsh-resource-center

GitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试

安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗

安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。

README

目录

DeepSeek Harness 插件集合仓库。每个插件都保留独立的 package.json、 cordis.patch.yml、源码、测试和 README,可以单独安装、验证和打包;根目录只负责 集合说明与 npm workspace 编排。

插件

目录 包名 主要能力
resource-center-plugin/ dsh-resource-center 工作区侧栏、服务管理、Web Fuzzer、MITM、用量统计
dsh-security/ dsh-security 渗透测试、代码审计 preset、结构化 API/报告
dsh-dex/ dsh-dex Dex OIDC 登录、session/workspace/事件流用户隔离

dsh-resource-center 已内置 Web Testing Host/API 和 Test 侧栏。同一个 profile 不要再额外安装 dsh-web-testing,否则会重复注册相关能力。

快速开始

获取仓库

git clone git@github.com:Xs1KVerOA/dsh-plugin.git
cd dsh-plugin

也可以使用 HTTPS:

git clone https://github.com/Xs1KVerOA/dsh-plugin.git

安装到 DSH profile

安装两个插件:

npx @deepseek-ai/dsh plugin --profile web add ./resource-center-plugin
npx @deepseek-ai/dsh plugin --profile web add ./dsh-security
npx @deepseek-ai/dsh --profile web --dump-config

只需要单个能力时,可以只安装对应目录。profile 中的 bundle 列表由 dsh plugin 命令维护,不要手动编辑 profile manifest。

使用本地安装脚本

install.sh 默认安装资源中心,也支持切换到任意插件目录:

./install.sh --dry-run
./install.sh --plugin-dir "$PWD/dsh-security" --dry-run

本地源码启动(推荐)

开发和安全加固验证统一使用源码 Harness 启动器,不使用 npx @deepseek-ai/dsh web。启动器会在每次启动前重建 Harness Host/Client 库和资源中心客户端 bundle,确认 web profile 的插件仍然链接到当前源码, 并在发现旧产物、错误链接或端口冲突时拒绝启动:

./start-local.sh --check
./start-local.sh

它实际执行的是 pnpm dsh --profile web --host 127.0.0.1 --port 3080,工作目录 为同级的 deepseek-harness 源码 checkout。可通过 DSH_ROOT、DSH_PROFILE、 DSH_HOST 和 DSH_PORT 覆盖默认值。npx 仅用于 profile 的安装/管理, 不作为运行时入口,从而避免临时 npx cache 继续加载旧的加固 bundle。

开发与验证

根目录 workspace 安装依赖时使用:

npm install --legacy-peer-deps
npm run check
npm test
npm run pack

DSH core packages 由 Harness profile 提供,可能没有对应的独立 npm 版本; --legacy-peer-deps 可避免 npm 从 registry 解析这些 profile-provided peers。

也可以单独验证插件:

npm --prefix resource-center-plugin test
npm --prefix dsh-security test
npm --prefix resource-center-plugin pack --dry-run
npm --prefix dsh-security pack --dry-run

npm run check 会执行 JavaScript 语法检查、客户端 bundle 检查和 DSH release 兼容性检查;npm test 会运行两个插件的 Host/Client/存储测试。

安全边界

  • 只在获得授权的目标上使用服务管理、Web Fuzzer 和 MITM 功能。
  • 资源中心默认只绑定本机,代理默认不自动启动,并拒绝私有目标。
  • SSH、数据库、容器、远程命令和写入类操作可能产生真实副作用。
  • 密码、私钥和云密钥由 Harness credentials 服务管理,不应提交到仓库。
  • node_modules、构建产物、release tarball、profile 数据和本机运行统计不会提交。

更详细的功能、配置和兼容性说明见各插件目录下的 README。

原始 README: https://github.com/Xs1KVerOA/dsh-plugin/blob/main/README.md ↗