dsh-plugin-auto-install

by dd598

0 插件市场与管理github未核验到 manifest收录于 08-16

Windows 下让 DeepSeek Harness (DSH) 自动执行 DSH 插件安装流程的动态 Cordis 插件:显式版本解析、沙箱 danger-full-access 授权自动升级

安装

dsh plugin --profile web add github:dd598/dsh-plugin-auto-install

GitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试

安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗

安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。

README

目录

Windows 下让 DeepSeek Harness (DSH) 自动执行插件安装流程的动态 Cordis 插件——纯直连,无代理 平台:Windows · 工作区示例:D:\DshTest · 已实测:@liustack/modlens@3.17.0

English README

把《DSH 插件安装流程(纯直连·无代理)》固化成模型工具 dsh_plugin_install: 只要遇到 DSH 插件安装操作,就自动执行完整流程——解析显式版本、执行安装、安装后验证、沙箱授权自动升级,全程无需手工敲命令。


为什么需要它

在 Windows 的 DSH Web GUI 里手工安装插件(dsh plugin --profile web add <pkg>@<ver>)有一串已知的坑:

坑 说明
Windows TLS 栈 curl / Invoke-WebRequest 走 Windows schannel,会报凭据错误(SEC_E_NO_CREDENTIALS);只有 Node fetch(自带 OpenSSL)可用
@latest 门禁 DSH 有 release-age 门禁,必须写显式版本号,@latest 可能装到旧版报 declares no dsh.bundle
沙箱拦截形态隐蔽 workspace-write 沙箱会拦掉写 C:\Users\<user>\.dsh\profiles\web 与 pnpm store,但失败表现为 ERR_SQLITE_ERROR unable to open database file / pnpm failed(pnpm store 数据库在工作区外打不开),不是带标记的 [sandbox: file access denied]
装完要重启 安装成功后需重启 DSH 才生效

本插件把以上全部自动化,并在沙箱拦截时自动弹授权框请求 danger-full-access 并重试一次。


插件内部执行的流程

开始
 │
 ├─ 1. 解析显式版本: fetch(<pkg>/latest).version(绝不 @latest)
 │      └─ 无 version 字段时判失败,绝不误装 @undefined
 │
 ├─ 2. 执行安装: node <dshBin> plugin --profile web add <pkg>@<version>
 │      └─ 沙箱拦截(denied 标记 或 sqlite/EPERM/pnpm failed 特征失败)
 │           → 自动请求 danger-full-access 授权 → 重试一次
 │
 ├─ 3. 验证安装: profile 的 package.json 中 dependencies 与
 │      dsh.profile.bundles 都应包含该包
 │
 └─ 4. 返回结构化结果(ok / version / verified / exitCode / 输出尾部 / 是否需重启)

用法

方式一:动态插件(当前会话,推荐)

在 DSH 会话中让 Agent 执行:

  1. cordis_define(kind: new,idPrefix: dshi)——把 plugin/host.js 里的 module.exports 对象内容作为 code.host(或直接粘贴 apply 的函数体);
  2. cordis_run(mode: run)激活;
  3. 之后工具 dsh_plugin_install 出现在工具列表中,遇到安装操作自动调用。

方式二:长期挂载(重启后仍生效)

把 plugin/host.js 挂进 agent preset 的 agent.cordis.yml(如 standard 的副本),或加入 host composition;它依赖宿主已挂载的 shell / sandboxPolicy / approval / tools 服务。

工具参数 dsh_plugin_install

参数 必填 说明
package ✔ npm 包名,如 @liustack/modlens
version 显式版本;缺省自动解析最新版
profile DSH profile,默认 web
profileRoot DSH 主目录(含 profiles),默认 C:\Users\jiang\.dsh(用于安装后验证)
nodePath node.exe 路径覆盖(默认 D:\ruanjian\NodeJs\node.exe)
dshBin DSH CLI bin.js 路径覆盖
dryRun true 时只解析版本,不安装(无副作用自检)
sandbox_permissions 预申请沙箱升级(workspace-write / danger-full-access),需配 justification

返回:{ ok, package, version, message, installExitCode, outputTail, sandboxMode, sandboxDenied, verified, restartRequired }。

示例:

dsh_plugin_install(package: "@liustack/modlens")
→ ok: true, version: 3.17.0, verified: true, sandboxMode: danger-full-access
  "installed @liustack/modlens@3.17.0 into profile web (direct) and verified
   (dependencies: yes; dsh.profile.bundles: yes). Restart DSH..."

实现要点

  • 动态工具:harness.defineTool + harness.registerTool 注册,随插件 Fiber 自动回收;
  • 命令执行:走宿主 ctx.shell(Windows 上为 pwsh 执行器),按会话沙箱策略逐条 resolve/run;
  • 纯直连:完全没有代理回退——所有网络步骤都用 Node fetch 直连 registry.npmjs.org(不经过 Windows schannel);
  • 沙箱升级:复刻 @deepseek-ai/dsh-sandbox 的 approveEscalation 语义——严格变宽阶梯(read-only → workspace-write → danger-full-access)+ ctx.approval.request 授权,动态代码无需 import;
  • 失败识别:looksSandboxBlocked() 同时识别显式 sandbox.denied 与 sqlite/EPERM/pnpm 特征失败(实测 workspace-write 下拦截表现为后者);
  • 安装后验证:解析 profile 的 package.json,确认包同时出现在 dependencies 与 dsh.profile.bundles;
  • 入参校验:包名/版本/profile 严格字符集;路径参数仅禁 PowerShell 单引号/换行,防注入且不误拒 Windows 路径。

自检记录(v1.0.0 实测)

  • ✔ 版本解析返回 3.17.0
  • ✔ dryRun 零副作用自检通过
  • ✔ 真实安装:workspace-write 首试被拦 → 自动升级 danger-full-access → 重试成功(Done in 1.3s using pnpm),随后验证 dependencies 与 dsh.profile.bundles 均包含该包
  • ✔ 不存在的包:干净失败(VERSION NONE),不会误装 @undefined
  • ✔ 已知边界:动态插件为进程/会话级,重启 DSH 后需重新定义(见"方式二"固化)

相关文档

License

MIT

原始 README: https://github.com/dd598/dsh-plugin-auto-install/blob/main/README.zh-CN.md ↗