返回目录
其他 插件

dsh-xray

alloevil/dsh-xray

X-ray for your DeepSeek Harness — see what's actually loaded, why, and what it costs you.

Stars
2
Forks
0
Issues
3
更新
今天

PROJECT TOPICS

项目标签

INSTALL REFERENCE

安装参考

未验证
dsh plugin --profile web add github:alloevil/dsh-xray

该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。

PROJECT README

README

dsh-xray — X-ray for your DeepSeek Harness

npm CI license JavaScript

X-ray for your DeepSeek Harness — see what's actually loaded, why, and what it costs you.

🇨🇳 中文文档


The Problem

dsh --dump-config shows you the composed tree. The plugin panel shows you a flat list. Neither tells you why a plugin is there, what breaks if you disable it, or what it silently costs you.

dsh-xray does.

Status: 0.2.x — static + runtime imaging. Static commands work even when dsh cannot boot; deps/health and the agent tool need the plugin mounted.


CLI Commands

npx dsh-xray attribute   # which layer introduced each row, and who patched it since
npx dsh-xray conflicts   # rows whose fields have multiple writers, and who wins
npx dsh-xray diff        # declared (static layers) vs actual (dump-config) tree
npx dsh-xray snapshot    # content-addressed lockfile of the effective composition
npx dsh-xray deps [svc]  # service dependency graph: providers, consumers, disable-cascade
npx dsh-xray health      # plugin lifecycle health: failed fibers, pending injects, transitions
npx dsh-xray cost        # estimated context-token cost per model-facing tool schema
npx dsh-xray shadow      # services provided by multiple plugins
npx dsh-xray audit       # static scan of out-of-tree plugins for sensitive touchpoints

Features

🔍 Layer Attribution

Which layer introduced each active plugin: kernel bundle, profile dependency, cordis.patch.yml insert, or repository source.

📊 Declared vs. Actual Diff

Installed-but-inactive, uninstalled-but-lingering patch rows — all surfaced.

⚡ Conflict Detection

Plugins patching the same config row, and which one silently wins.

📸 Composition Snapshot

Export the effective composition as a lockfile; reproduce it elsewhere.

🌐 Service Dependency Graph

Who provides and consumes each service; what cascades if you disable X.

💊 Runtime Health

Per-plugin fiber lifecycle state, startup failures, transition history.

🤖 Agent Self-Introspection

The xray_composition tool lets agents inspect their own capability set.

🛡️ Capability Audit

Heuristic static scan: network egress, shell, filesystem, env, eval.

Agent Tool

Mounted in the tree, dsh-xray registers an xray_composition tool (view: summary | deps | health | cost | shadow), so an agent can answer:

"What capabilities do I have?" / "What plugin provides X?" / "Why is Y unavailable?"

— about itself.


Safety Stance

dsh-xray reads; it never runs.

  • Loader !!js expressions in patch files are parsed as opaque markers and never evaluated
  • The CLI never executes plugin code (audit is a pattern scan over source text)
  • The mounted plugin writes only under $DSH_HOME/xray/
  • See SECURITY.md

Install

dsh plugin --profile web add dsh-xray

All commands take --profile <name> (default web) and --json.

Command Behavior
diff Exits 1 when the trees disagree
health Exits 1 when any plugin is unhealthy
attribute, conflicts, snapshot Fully static — work even when dsh cannot start
deps, health Read runtime snapshot at $DSH_HOME/xray/runtime.json

Capabilities

Diagnostic imaging for a running composition — complementary to dsh-doctor (rescue & recovery).

Feature Category
Layer attribution 🔍 Inspection
Declared vs. actual diff 🔍 Inspection
Conflict detection 🔍 Inspection
Composition snapshot 📦 Export
Service dependency graph 🌐 Runtime
Runtime health 🌐 Runtime
Agent self-introspection 🤖 AI
Capability audit 🛡️ Security
Service shadowing 🌐 Runtime
Context cost 💰 Optimization

License

MIT

CLASSIFICATION EVIDENCE

分类依据

项目类型插件
功能分类其他
规则置信度

系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: 无有效分类标签。