DeepSeek Harness 插件

dff652/deepseek-harness-community-plugins#dsh-ai-asset-hub

Star 数 ★ 1 分类 工具与能力 收录于 2026-08-24

将 DeepSeek Harness 连接到部署方管理的 AI Asset Hub MCP 服务,并提供八个经过审查的只读资产工具。

安装

# Release 预构建包

dsh plugin --profile web add "https://github.com/dff652/deepseek-harness-community-plugins/releases/download/dsh-ai-asset-hub-v0.1.1/dff652-dsh-ai-asset-hub-0.1.1.tgz"

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:dff652/deepseek-harness-community-plugins#path:/packages/dsh-ai-asset-hub

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

该插件的 README 只有英文版本。

Configuration-only DeepSeek Harness bundle for an already installed AI Asset Hub executable. It mounts the official @deepseek-ai/dsh-mcp-client peer and starts a deployment-owned aiah mcp command; it does not copy AIAH handlers, store credentials, ship a provider binary or expose build/apply/rollback.

Pinned combination

Item Pin
DeepSeek Harness 0.2.0-rc.2
@deepseek-ai/dsh-mcp-client 0.2.0-rc.2

Deployment contract

The DSH service must define DSH_AIAH_COMMAND as a non-blank absolute path to a reviewed aiah executable. A missing, blank or relative value is rejected during activation; the bundle never asks the operating system to resolve a provider command through PATH. That executable, its version and its SHA-256 belong to the deployment, not this package. The package always passes mcp as the only argument.

DSH 0.2.0-rc.2 reports a failed optional plugin as an activation warning and can keep other plugins running. Rejection means this entry exposes no AIAH tools; it does not require the whole Web host to exit. The activation check inspects the settled Loader entry and tool registry.

Install an exact package version or reviewed tarball into a disposable DSH profile first. A source checkout is not release acceptance.

dsh plugin --profile <profile> add -w ./dff652-dsh-ai-asset-hub-0.1.3.tgz
dsh --profile <profile> --dump-config

Remove the bundle without deleting the separately managed provider or its data:

dsh plugin --profile <profile> remove @dff652/dsh-ai-asset-hub
dsh --profile <profile> --dump-config

Keep the prior reviewed tarball and digest before an upgrade so the same commands can restore it if acceptance fails.

Configuration-only activation check

From a repository checkout, the package-specific DSH negative activation check requires a reviewed DSH runtime and fails clearly if dsh is unavailable. The script is intentionally kept out of the published five-file package. It uses a temporary DSH home and never starts a provider or touches a live profile:

node tests/dsh-ai-asset-hub-activation.acceptance.mjs

The check covers unset, blank and relative DSH_AIAH_COMMAND values. It is kept outside npm test because CI environments without DSH must not silently skip real activation acceptance.

Reviewed tool names

mcp__aiah__aiah_asset_status
mcp__aiah__aiah_diff
mcp__aiah__aiah_doctor
mcp__aiah__aiah_migration_readiness
mcp__aiah__aiah_migration_status
mcp__aiah__aiah_scan
mcp__aiah__aiah_validate
mcp__aiah__aiah_version

The accepted candidate is read-only. Provider-side tests remain authoritative for the zero-write invariant because DSH does not turn MCP annotations such as readOnlyHint into an authorization system.

Package contract

The package declares dsh.bundle.patch in package.json and pins the official MCP client as an exact peer dependency. Deployment-specific command paths, provider homes, endpoints and credentials stay outside this package.

The package includes its MIT LICENSE so the license notice travels with every independently distributed tarball.

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →

社区评论

评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。