Introduction¶
The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In real-world development, from accumulating expert methods and building skill packages to performing pre-release compliance checks and dependency security scans, developers often have to handle multiple stages manually. dsh-plugin-tools provides a toolchain designed to automate the plugin/skill development and release process through installation via DSH’s line-level catalog.
What Is It¶
This is a plugin tool provider maintained by wwumit. It installs multiple core tools from the line-level catalog via ctx.skills, covering the entire lifecycle from development assistance to compliance review.
Core Features¶
This plugin package integrates the following tools:
- expert2skill (Expert Method Accumulator)
Guides developers through interviews to convert expert experience into a rules library JSON file and generate a runnable skill package. - skill-compliance (Release Compliance Checker)
Checks disclosure completeness, disclaimers/red-line statements, finance-sensitive terms, and dependency security to ensure the skill package meets the STANDARD §7/§9 standard. - dependency-scan (Supply Chain Dependency Scan)
Scans host shadowing, pinned versions, high-risk baselines, and peer dependency integrity, aligning with the DEP checks inskill-compliance. - malware-scan (Malware Static Detection)
Detects remote execution, obfuscated execution, data exfiltration, persistence, credential access, and dangerous call chains. - bundle-lint (Bundle Structure Consistency Validation)
Validates bundle structure consistency (BND-001~007) and aligns with the official rule changes 08-17~08-24. - runtime-probe (Real-runtime list/get verification)
Verifies plugin registration and functionality in a real DSH runtime and generates an evidence contract report containingverifiedBy,verifiedAt, andreportUrl. - awesome-lint (awesome-dsh-plugin Inclusion Pre-check)
Checks.ymlfile extensions, category enums (including identity), unknown fields, locale consistency, and description boundaries to pre-check compliance with the awesome-dsh-plugin inclusion criteria.
Installation and Enablement¶
Before use, make sure the required peer dependencies are installed: @deepseek-ai/cordis and @deepseek-ai/dsh-skill.
npm install @wwumit/dsh-plugin-tools
Enable the plugin:
import { Context } from '@deepseek-ai/cordis'
import * as pluginTools from '@wwumit/dsh-plugin-tools'
export function apply(ctx: Context) {
ctx.plugin(pluginTools, {
catalogUrl: 'https://wwumit.github.io/skills-catalog/catalog-plugin-tools.json',
})
}
After installation, use ctx.skills.list() to retrieve the tool list, and use ctx.skills.get('tool-name') to invoke a specific tool.
Verification and Disclosure¶
This plugin has been verified in a real DSH runtime using verify-dsh.ts, confirming that ctx.skills.list() returns 4 tools and that SKILL.md can be fetched correctly.
According to Disclosure v0.3, the 3 core tools under this plugin are all set to cloud: false, meaning they run purely locally.
CI Gate Template¶
The repository provides the templates/ci/plugin-gate.yml template. Copy this template to the .github/workflows/ directory of the target plugin repository to automatically run build, bundle-lint, skill-compliance, dependency-scan, and malware-scan on push or PR. A failure in any step blocks the release process.
Development¶
The project uses pnpm for dependency management.
pnpm install
pnpm test # 运行 vitest(模拟 fetch)
pnpm build # 编译 TypeScript 到 lib/ 目录
Summary¶
dsh-plugin-tools provides a complete plugin development and compliance checking solution. By leveraging its capabilities in expert knowledge accumulation, compliance checking, dependency scanning, and runtime verification, developers can significantly improve the quality and security of skill packages.
- Catalog Page: https://www.skillhub.cn/plugins/wwumit/dsh-plugin-tools
- Source Repository: https://github.com/wwumit/dsh-plugin-tools