Deterministic AST code graph and architecture intelligence tool for call hierarchies, blast radius, circular dependencies, domain slices, and full-stack API contracts.
Install
# from npm (prebuilt)
dsh plugin --profile web add @trench-xinxin/dsh-tool-lens
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:trench-xinxin/dsh-tool-lens
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
DeepSeek Lens is a high-performance, deterministic AST code graph and architectural analysis tool plugin designed for the DeepSeek Harness agent foundation.
It empowers AI Agents with deep codebase topological awareness, enabling instant module dependency exploration, disambiguated symbol call hierarchies, OOP inheritance tracing, circular dependency audits, architectural coupling metrics, Git diff change impact audits, domain architecture slicing, and full-stack API contract tracking.
⚡ Zero-Config All-in-One Launcher (No Extra Setup Required)
💡 Stand-alone Execution: You do NOT need to pre-install
@deepseek-ai/dsh, nor do you need to start any background Harness services beforehand.
Running the command below will automatically download the runtime, handle port allocation, and launch the complete Web UI with Lens pre-loaded:
# 🚀 Zero-config launch full Web UI (Out of the box)
npx @trench-xinxin/dsh-tool-lens
# Or execute a one-off prompt directly in terminal
npx @trench-xinxin/dsh-tool-lens "Use lens tool to audit circular dependencies in this workspace"
Once launched, your browser can access the Web UI at the indicated local address (e.g. http://127.0.0.1:3080 or http://127.0.0.1:3081).
🌟 Core Features (v2.0)
📦 Module & Dependency Topology (
dependencies)- Precise static analysis of ES and CommonJS
import/exportdeclarations. - Full Re-export Resolution: Supports
export * from './mod'and named aliased re-exports. - Path Mapping: Automatically resolves
tsconfig.jsoncompilerOptions.pathsaliases (e.g.,@/*).
- Precise static analysis of ES and CommonJS
📞 Scope-Disambiguated Call Hierarchies (
call_graph)- Resolves functions, arrow functions, and class member methods.
- 4-Tier Scope Awareness: Prioritizes same-file, explicit imports (
import { fn }), and namespace imports (Mod.fn), completely eliminating false positives from duplicate function names across the workspace. - OOP Heritage Extraction: Extracts
extendsandimplementsrelations for classes and interfaces.
💥 Tiered Refactoring Blast-Radius Analysis (
impact)- Assesses downstream and upstream impact of changing or removing symbols.
- 3-Tier Risk Classification:
- 🔴 Tier 0 Direct Breaking: External callers and direct importers breaking on signature changes.
- 🟡 Tier 1 Internal Cascading: Functions/methods within the same file/class affected by cascade.
- 🔵 Tier 2 Transitive Importers: Upstream modules transitively importing this file.
🔄 Circular Dependency Auditing (
circular)- Tarjan SCC and DFS cycle detection algorithm detects closed loops (e.g.
A -> B -> C -> A). - Outputs full cycle loops and involved file lists to avoid runtime initialization deadlocks.
- Tarjan SCC and DFS cycle detection algorithm detects closed loops (e.g.
🧭 Shortest Call Path Exploration (
action: path)- Bidirectional BFS algorithm traces shortest execution paths and intermediate hops between any two symbols.
🧹 Dead Code & Unused Symbol Audit (
action: unused)- Discovers unreferenced symbols and orphan files with zero afferent callers ($Ca = 0$).
🛡 Architecture Layer Governance (
action: lint)- Enforces architectural boundary rules (e.g.
views/**cannot directly importinfra/**) to prevent layer decay.
- Enforces architectural boundary rules (e.g.
📝 Git Diff Impact & Test Recommender (
action: diff_impact)- Scans uncommitted working tree diffs or commit ranges, traces upstream breaking callers, and recommends targeted regression test suites.
🧩 Domain Architecture Subgraph Slicing (
action: slice)- Extracts compact, high-cohesion domain slices (Ego-Networks) around seed symbols, computing cohesion scores and boundary dependencies.
🌐 Full-Stack Cross-Language API Contracts (
action: api_contracts)- Automatically links frontend HTTP requests (
fetch,axios,request) to backend route controllers (Java Spring, Python FastAPI, Go Gin), forming full-stack end-to-end call graphs.
- Automatically links frontend HTTP requests (
🌍 Polyglot Ecosystem Drivers (
Java / Python / Go / Rust / TS / SFC)- Java (
.java):package, Maven/Gradle paths,class,interface,extends,implements, and class method invocations. - Python (
.py):def,classinheritance,self.method(), and relative/absolute package imports. - Go (
.go):packagescopes,go.modmodule paths, Struct Embedding, and Receiver methods. - Rust (
.rs):modmodules,struct,trait,impl Trait for Struct, and method calls. - Vue 3 & Svelte (
.vue,.svelte): Full support for<script setup>and<template>component references.
- Java (
📄 License
MIT License © 2026 Trench / DeepSeek Lens Contributors.
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 31789
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 4052
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1130
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 499
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 482
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 445
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.