truelove-dreamer/dsh-plugin-git-workflow

DeepSeek Harness plugin: first-class Git workflow tools for the model — repo status, diffs, commit creation with validated messages, recent history, and branches. No bare-shell git calls; every invocation is a shell-free execFile with path and message validation.

Bundle 已验证 未知 JavaScript 未知
Bundle 已验证

已收录

2

Git

Bundle 已验证

版本未知
语言JavaScript
许可证未知
在 GitHub 查看

预览

第 1 个预览,共 2 个:truelove-dreamer/dsh-plugin-git-workflow
第 2 个预览,共 2 个:truelove-dreamer/dsh-plugin-git-workflow

功能介绍

一等公民的 Git 工具:status / diff / log / commit / branch,参数与路径校验、零 shell 调用,杜绝注入。

适合

  • 需要结构化 Git status、diff、log、commit 与 branch 操作的 Agent。
  • 要求在执行 Git 操作前校验提交信息和所选路径的仓库。
  • 希望获得可解析 Git 结果,同时保留 Harness 沙箱与审批行为的工作流。

不适合

  • 需要 push、pull、rebase 或其他 Git 网络操作的工作流;插件不包含这些功能。
  • 需要创建提交的只读会话;沙箱策略会拒绝 git add 与 commit。
  • 需要提交但尚未配置 Git user.name 和 user.email 的仓库。
  • 要求 git_log 文件输出可靠显示非常规编码路径的场景。

README

dsh-plugin-git-workflow

DeepSeek Harness 插件:给模型提供一等公民的 Git 工作流工具 —— 仓库状态、diff、规范 commit、历史、分支,不再需要裸 bash/pwsh 手搓 git。

背景

DSH 内置没有任何 git 工具。模型只能通过 bash/pwsh 调用 git,输出原始、易错、难解析,还容易把用户输入拼进 shell 命令(注入风险)。这个插件把 Git 变成结构化、安全、可解析的工具集。

工具

工具 作用
git_status 分支、upstream、ahead/behind、staged / unstaged / untracked / conflicts 清单(porcelain 解析)
git_diff 工作区 diff 或 staged diff(--cached),支持 --stat 摘要、路径过滤、行数截断
git_log 最近提交(hash/日期/subject),可选 files 列出每个提交改动的文件
git_commit 校验 message 后 git add(可选路径)+ git commit -m;清晰报出 “nothing to commit”
git_branch 本地分支列表,标记当前分支

安装

dsh plugin --profile web add dsh-plugin-git-workflow

挂载(profile cordis.patch.yml 或 agent preset):

- insert:
    - id: git-workflow
      name: dsh-plugin-git-workflow

使用

git_status                        # 看当前仓库状态
git_diff                          # 看未暂存改动
git_diff staged: true             # 看已暂存改动
git_commit message: "fix: ..."    # 提交(全部已暂存内容)
git_commit message: "feat: ..." paths: ["src/a.js"]   # 先 add 再提交
git_log count: 20 files: true     # 最近 20 条 + 改动文件
git_branch                        # 分支列表

所有工具都接受 workdir(默认会话工作目录,相对路径按会话目录解析)。

设计说明

  • 零 shell 注入:所有 git 调用经 harness 的 shell 执行器(ctx.shell)运行,参数逐个引号转义,用户输入不可能被解释为 shell 语法——同时继承沙箱与审批语义(read-only 会话无法 commit)。
  • 输入校验:commit message 非空、≤2000 字符、无 NUL;路径拒绝绝对路径与 .. 穿越(反斜杠归一化后检查),保证不越出仓库。
  • 纯逻辑可单测:解析(porcelain / diff-stat / log / branch)与校验全部在 lib/git.js 纯函数里,npm test 零依赖。
  • 结构化输出:每个工具返回带 schema 的 JSON,render 输出可读文本;失败返回 { ok:false, exitCode, message } 而非裸报错。

诚实边界

  • git 调用经 harness 的 shell 执行器(ctx.shell)运行,继承沙箱与审批语义;路径校验是词法级的,符号链接/工作树外路径依赖 git 自身约束。read-only 模式下写操作(git add / commit)会被沙箱拒绝。
  • commit 需要仓库已配置 user.name/user.email(git 自身报错会透传)。
  • git_log 的 files 解析假设 --name-status 输出格式;非常规编码的路径可能显示不完整。
  • 不含 push / pull / rebase 等网络操作(后续版本可加,需审批语义配合)。

本地开发

cd plugins/dsh-plugin-git-workflow
npm test          # node --test,零依赖

接线集成测试(需 harness checkout 的 Cordis):见仓库根 test-wiring.mjs。

常见问题常见问题

在启用了 DSH 的终端中执行已验证命令 dsh plugin --profile default add github:truelove-dreamer/dsh-plugin-git-workflow。命令会解析公开 package 元数据,并保持插件与本页展示的目录身份一致。