dsh-engineering-skills
by chenyinrusi
DeepSeek Harness、Claude Code、Codex:18维代码审查、CI故障分类、shell安全、冗余/边界审计、跨仓库模式吸收 - 纯Markdown,无需安装。
Five engineering-discipline skills for AI coding agents (DeepSeek Harness, Claude Code, Codex): 18-dimension code review, CI failure triage, shell safety, redundancy/boundary audit, and cross-repo pattern absorption - pure markdown, no install.
安装
dsh plugin --profile web add github:chenyinrusi/dsh-engineering-skillsGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
Engineering-discipline skills distilled from a large production agent-system codebase: systematic code review, CI failure triage, shell safety, redundancy/boundary auditing, cross-repo pattern absorption, and release engineering.
Six markdown skills for AI coding agents (DeepSeek Harness, Claude Code, Codex, or any agent that reads SKILL.md). They are methodology-first — no code to install, no runtime, no lock-in: copy the skills/ directory and the agent loads them.
Skills
| Skill | What it does |
|---|---|
| code-review-methodology | 18-dimension, 3-pass code review framework: execution/integration → architecture/systems → reliability/correctness, plus multi-angle iterative review, E2E-test review angles, migration review angles, and 12+ derived rules |
| ci-diagnosis-and-fix | Systematic triage and repair when GitHub Actions CI turns wholesale red: find the failing run → pull the failing step's log → classify the root cause → fix → verify |
| shell-safety | Hard ban on interactive CLI commands (more/less/pause/choice/start /WAIT) that freeze headless agent sessions, with non-interactive equivalents, a mandatory timeout rule, and a pre-flight checklist |
| redundancy-and-boundary-audit | Repo-level duplication triage with a falsifiable sync test and A/B/C classification (true duplicate / same-name-different-concept / same-shape-different-domain), plus boundary, naming, and multi-angle verification |
| repo-analysis | 5-phase cross-repository architecture audit: scan → pattern extraction (7-primitive taxonomy) → gap mapping → value judgment → structured output, with a batch flow for 5+ repos |
| release-engineering | End-to-end release of a Python package to GitHub + PyPI + awesome lists: name-availability checks, data-files packaging (with the glob-flattening pitfall), repo/tag/topics, twine upload, clean-venv verification, and one-repo-per-PR aggregation entries |
Install
From PyPI — the pack also ships as a data-only Python package with an installer CLI:
pip install "dsh-engineering-skills"
dsh-engineering-skills list # see the 6 skills
dsh-engineering-skills install ~/.dsh/skills # DeepSeek Harness user skills dir
The wheel contains the same SKILL.md files (packaged as data-files, no code
dependencies); the CLI just copies them into any agent's skills directory.
From source / generic agents — copy the skills into your agent's skills directory:
# DeepSeek Harness (user-level skills dir is ~/.dsh/skills, i.e. $DSH_HOME/skills)
cp -r skills/* ~/.dsh/skills/
# Claude Code
cp -r skills/* ~/.claude/skills/
# Codex
cp -r skills/* ~/.codex/skills/
Each skill is a self-contained SKILL.md with YAML frontmatter (name, description, keywords) — no dependencies, no build step.
Why these skills
They come from real incidents and audits, not theory. Notable provenance:
shell-safetyexists because a session froze for 12 minutes onfindstr ... | more +0waiting for a keypress that never arrived.redundancy-and-boundary-auditencodes the A/B/C duplication classification that keeps "same name" from being treated as "duplicate" — a domain model / API DTO pair is legitimate layering, and only asymmetric change is drift.code-review-methodologyaccumulates review angles only after each one caught a real bug (single-pass review finds ~30% of bugs in cross-cutting features).ci-diagnosis-and-fixdocuments the two failure modes that turn CI wholesale red: a nonexistent dependency version, and the old$GITHUB_OUTPUTsyntax on newer runners.release-engineeringencodes the flow proven across three same-day releases (a CLI+MCP audit tool, an MCP server, and this skill pack): PyPI name collisions, data-files path flattening, token-scope failures, andrequires-pythonvs verify-venv mismatches all bit once and are now written down.
Validation
python scripts/validate_skills.py # checks frontmatter + body of every SKILL.md
License
MIT © 2026 Chen (Jarry) Pan
原始 README: https://github.com/chenyinrusi/dsh-engineering-skills/blob/main/README.md ↗
同类插件
查看全部 →
deepseek-harness
从仓库或系统描述生成经过校验的自包含交互式架构图、流程图、时序图、数据流图和生命周期图。

dsh-plugin
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。

dsh-tongflow
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。

helloagents
AI 编码 CLI 的工作流层:技能、项目知识、交付检查、更安全的配置写入与可恢复执行

dsh-ai-novel-writer
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。

rea
用 agent 逆向任何东西:从应用行为到原生二进制