DamonKoy/dsh-plugins
Codex-inspired enhancement plugin family for DeepSeek Harness: secret-redactor / approve-for-me / mcp-client-v2 / memories / system-proxy / usage-cost
Listed
0
Dev, Memory, Security, Tools, Usage
Bundle verified
Preview
What it does
DamonKoy/dsh-plugins#dsh-approve-for-me: Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine. DamonKoy/dsh-plugins#dsh-mcp-client-v2: Enhanced MCP client: paginated tool discovery, non-blocking startup, mcp_tool_search, hand-rolled stdio/streamable-http transports. DamonKoy/dsh-plugins#dsh-memories: Project-scoped persistent key-value memories with set/get/list/delete/search model tools and JSON-file storage. DamonKoy/dsh-plugins#dsh-secret-redactor: Automatic secret redaction in tool results: masks API keys, tokens, JWTs, private keys and configured secrets before the model sees them. DamonKoy/dsh-plugins#dsh-system-proxy: System proxy detection (scutil/env/PAC) with a status tool and a proxy_export bash snippet tool. DamonKoy/dsh-plugins#dsh-usage-cost: Token usage and cost tracking with daily/session budget alerts and a usage_report tool.
Best for
- DSH users who want a modular set of operational enhancements covering approvals, secret redaction, MCP discovery, project memories, proxy detection, and usage costs.
- Security-conscious workflows that need tool-result secret masking and fail-closed automated approval rules.
- Projects that benefit from project-scoped persistent key-value memories or searchable MCP tool discovery.
- Teams monitoring token use and daily or session budgets while working through system proxies.
Not ideal for
- Users seeking one single-purpose plugin rather than selecting among six independent enhancement packages.
- Workflows that do not use MCP servers, persistent project memory, system proxies, automated approvals, or budget tracking.
- Environments requiring every component to have the same verification maturity; the evidence marks usage-cost hooking as still under verification.
README
dsh-plugins
DSH(DeepSeek Harness)增强插件家族,对标 OpenAI Codex 0.147 的实用功能。
| 包 | 功能 | Codex 对应版本 | 状态 |
|---|---|---|---|
| dsh-secret-redactor | 敏感信息脱敏(工具输出自动掩码 + redact_text 工具) | 0.147 secrets redaction | ✅ 已验证(真实会话脱敏生效) |
| dsh-approve-for-me | 自动审批审核(只读自动放行 / 危险命令自动拒绝 / 全自动模式) | 0.147 –approve-for-me | ✅ 策略引擎 7/7 单测通过 |
| dsh-mcp-client-v2 | MCP 客户端增强(分页工具发现 / 非阻塞启动 / 工具搜索) | 0.147 MCP 2026-07-28 | 见包内 README |
| dsh-memories | 项目记忆系统(按 scope 持久化键值记忆) | 0.145 memories | ✅ 已实现 |
| dsh-system-proxy | 系统代理检测与导出(scutil / env / PAC) | 0.143 PAC/WPAD | 见包内 README |
| dsh-usage-cost | 用量/成本统计与预算提醒(llm/stream usage 挂钩) | 0.144 usage credits | 挂钩验证中 |
安装
# 单个安装
dsh plugin --profile web add link:~/dsh-plugins/packages/<name>
# 或全部
for p in dsh-secret-redactor dsh-approve-for-me dsh-mcp-client-v2 dsh-memories dsh-system-proxy dsh-usage-cost; do
dsh plugin --profile web add link:~/dsh-plugins/packages/$p
done
重启 dsh web 生效。
架构说明
每个包都是标准 DSH Cordis 插件:
-
package.json声明dsh.bundle.patch(可被dsh plugin add与 dshmarket 识别) -
cordis.patch.yml是插件行(bundle patch) -
lib/index.js是 Host 半区(纯 JS ESM,无构建步骤) - 配置统一放在
~/.dsh/<name>.json,每次使用即时重读
登记
- awesome-dsh-plugin 精选目录:见 registry/REGISTRATION.md(PR-ready 行)
- dsh-web-ui community.json:同上(PR-ready 条目)
- 仓库已打
dsh-plugintopic(登记前置要求)
License
MIT
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.