依赖拓扑安全:装前预测 + 装后检测 @deepseek-ai/dsh-* 多副本、版本漂移与插件私包,防 Symbol 键冲突崩溃(Cannot read properties of undefined (reading 'prepare'))。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:DeLightor/dsh-depguard
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
English | 中文
装前预测 + 装后检测 DeepSeek Harness 的依赖拓扑冲突,防止 Symbol 键崩溃。
你装插件时崩过这个吗?
Cannot read properties of undefined (reading 'prepare')
根因是 discussion #1337:@deepseek-ai/dsh-tools 等核心包出现第二份物理副本时,JS Symbol 键(每次求值都不同)会让 ctx.tools[scheduler] 变 undefined,一次工具调度就崩,还会在会话里留下孤儿 tool_calls,之后每轮 400 INVALID_REQUEST 死锁。
本插件只做检测 + 修复建议,绝不自动修复——修复交给 dsh-undo-plugin、dsh-boot-guard 等第三方插件,保持模块化。
两个工具
dsh_depguard_predict — 装前预测(社区空白)
装新插件之前,静态拉取它的 manifest(npm 包 / github:owner/repo / 本地路径),与当前 runtime 的 @deepseek-ai/dsh-* 基准比对:
| 信号 | 风险 |
|---|---|
dependencies 直接含核心包 |
🔴 CRITICAL → NOT_RECOMMENDED(私包 = 第二份副本) |
peerDependencies 版本范围与 runtime 不符 |
🟡 WARNING → CAUTION(版本漂移风险) |
预测基于静态声明,实际解析受 lockfile/nodeLinker 影响——装上后请再跑 check 确认。
dsh_depguard_check — 装后检测
扫描落盘依赖拓扑,三项检测:
| 检测 | 严重度 | 说明 |
|---|---|---|
duplicate-copy |
CRITICAL/WARNING | 同一核心包多份物理副本(realpath 去符号链接;同名同版本也算——Symbol 冲突本质是两次求值) |
version-drift |
WARNING | 副本版本与 runtime 基准不一致 |
vendored-service |
CRITICAL | 社区插件把核心包打进自己的 node_modules(应 peerDependencies) |
每条 finding 带 fix 字段,给出修复建议命令(交给第三方修复插件执行)。
安装
# npm(推荐,预构建免授权)
dsh plugin --profile web add dsh-depguard
# GitHub 源码
dsh plugin --profile web add github:DeLightor/dsh-depguard
# 本地开发
dsh plugin --profile web add ./dsh-depguard
重启后,在会话里说「检查一下我的插件依赖」或「装 X 之前预测一下冲突」即可。
测试
node --test # 11 个用例:多副本/漂移/私包/符号链接去重/装前预测
安全声明
- 只读:不写任何 profile 文件、不改配置、不自动跑 pnpm。
- 零依赖:
dependencies为空;@deepseek-ai/*一律peerDependencies——本插件自己绝不引入第二份核心包。 - 检测 ≠ 修复:发现问题只报告 + 给建议,动手由你或第三方回滚插件完成。
被收录于
awesome-dsh-plugin 精选列表(PR 提交后),可通过 dsh-market 插件市场与 dsh-find-plugin 检索安装。
License
MIT
English
Predict (pre-install) and detect (post-install) dependency-topology conflicts in DeepSeek Harness to prevent Symbol-key crashes like Cannot read properties of undefined (reading 'prepare').
dsh_depguard_predict— fetch a target plugin's manifest and compare itsdependencies/peerDependenciesagainst your runtime baseline before installing.dsh_depguard_check— scan the on-disk dependency tree for duplicate@deepseek-ai/dsh-*copies (realpath-deduped; same-name-same-version still counts — Symbol keys differ per module evaluation), version drift, and plugins vendoring core services.
Detection + fix suggestions only; remediation is left to third-party plugins (dsh-undo-plugin, dsh-boot-guard). Read-only, zero runtime dependencies, @deepseek-ai/* as peerDependencies only.
dsh plugin --profile web add dsh-depguard
node --test # 11 tests
MIT
链接
同类插件
yjh051108/dsh-routing-suite★ 6995
一个仓库三件套:DSH 插件包的运行时注入器(注入、热重载、卸载、开发侧挂区一键转正、路由自愈,外带设置页插件管理:列出、卸载、拖入文件夹内化)、任务感知的思维模式路由 agent 预设(router-standard / router-spec / router-react)、以及分级两级任务协议(commit_star / lock_stage / revise_do / edit_plan / mark_task / redteam_verdict 六个工具,任务状态落盘)。注入器实现直接在库内,安装的是它自己的行为而不是一份依赖清单。
strukto-ai/mirage#dsh★ 3667
把文件系统与 bash 提供者换成 mirage 虚拟工作区:文件工具与 shell 命令作用于挂载的资源(RAM、S3、Redis、Slack、Gmail、Notion、Postgres)而非宿主磁盘,支持按挂载点设置读/写/执行模式、按命令选择沙箱(进程内 monty、pyodide、quickjs;远程 docker、e2b、daytona),并可在虚拟终端中安装 CLI(git、gh、slack、linear、ntn、gws,或自行注册的程序树)作为命令头词。
hust-open-atom-club/oh-dsh★ 325
社区发行版:TUI、桌面端与 Web UI 统一体验,分层安装、一步到位。
weijiafu14/pi2dsh★ 208
Pi Host ABI 兼容引擎:装一次之后,npm 上的 Pi 扩展原包经 `dsh plugin add <pi-package>` 直接作为 DSH 原生插件挂载。已在官方 DSH 上端到端验证 pi-mcp-adapter(完整 MCP 管理面:OAuth、resources、prompts、MCP Apps、elicitation、sampling)、@tintinweb/pi-subagents、pi-code、pi-hermes-memory、pi-background-tasks;`pi2dsh inspect` 在安装前报告一个包的兼容情况。
lire1131/dsh-undo-savepoint★ 167
DSH 撤销/回退系统:配置变更自动存档,一键撤销/恢复/回退到任意版本,支持 WebUI 与离线 CLI/GUI 工具(DSH 启动失败也能救)。
Fishquito7/dsh-skill-mcp-panel★ 158
在 DSH Web 设置中管理技能与 MCP 服务器:技能卡片热启停、工作区作用域、分组、批量迁移与拖拽导入,以及 stdio/HTTP MCP 增删改查、连接测试、密钥脱敏,并附带统一 dsh-panel 命令行。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。