dsh-web
zhu1090093659
DeepSeek Harness (DSH) Web 插件聚合生态 · 万物皆插件,通过创意工坊分发||DeepSeek Harness (DSH) Web Plugin Aggregation Ecosystem · Everything is a plugin, distributed via the Creative Workshop
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:bauerelizabeth07139/MDSM
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
MDSM — Male DeepSeek Mascot for the DeepSeek Harness Web GUI: a mascot character generated from a supplied photo, shipped inside the plugin, worn by the harness as its background, its brand mark, and its settings surface.

--dsw-alias-bg-base, --dsw-specific-sidebar-fill, --dsw-alias-bg-layer-1/2) are faded to the configured opacity so the wallpaper actually shows through instead of hiding behind an opaque shell, and the root background is cleared for it.background-position, all applied live.sidebar.brand.mark and conversation.hero.brand.mark slots./api/MDSM/...), so the browser never reaches outside, and stamps the config into the HTML so the GUI comes up already dressed.DeepSeek Harness Desktop — install it from the application, not from a shell: open Plugins in the sidebar, choose Add plugin, enter
https://github.com/bauerelizabeth07139/MDSM
and switch the new MDSM bundle on. The Desktop application boots the reserved desktop profile, so the command below installs into a different profile that the Desktop app never reads.
dsh CLI (web profile) — install it into the profile you boot:
dsh plugin --profile web add bauerelizabeth07139/MDSM
No git on the machine? pnpm resolves a git shorthand with git ls-remote, so an owner/repo or github: spec fails with 'git' is not recognized when git is missing from PATH. Install the published tarball over plain HTTPS instead — that path never calls git:
dsh plugin --profile web add https://codeload.github.com/bauerelizabeth07139/MDSM/tar.gz/main
The same address works in the Desktop application's Plugins → Add plugin dialog. Pin the revision by replacing main with a commit SHA (/tar.gz/<sha>) when you want a fixed build.
Any spec the plugin manager accepts works — a GitHub shorthand, a full git URL, or a local checkout:
dsh plugin --profile web add https://github.com/bauerelizabeth07139/MDSM.git
dsh plugin --profile web add C:\path\to\MDSM
Then open Settings → MDSM Male DeepSeek Mascot. Uninstall with dsh plugin --profile web remove MDSM.
The config lives at $DSH_HOME/MDSM.json (default ~/.dsh/MDSM.json) and is edited by the Settings section; it is also reachable over HTTP.
| Field | Default | Meaning |
|---|---|---|
wallpaper |
true |
Wear the MDSM artwork as the GUI background |
brand |
true |
Replace the sidebar and hero logos with the MDSM avatar |
surfaceOpacity |
60 |
Shell surface opacity in % — lower shows more of the wallpaper, higher keeps the shell opaque (25–100) |
blur |
0 |
Gaussian blur applied to the wallpaper, in px (0–24) |
scrim |
35 |
Palette-matched wash over the wallpaper — black in the dark theme, white in the light theme — for a readable transcript, in % (0–90) |
position |
center |
Wallpaper background-position: center, left, right, top, bottom |
| Route | Method | Purpose |
|---|---|---|
/api/MDSM/config |
GET / PUT |
Read / write the config (writes are same-origin only) |
/api/MDSM/wallpaper |
GET |
The 16:9 background artwork |
/api/MDSM/mark |
GET |
The square avatar artwork |
/api/MDSM/diag |
GET / POST |
Last browser-side diagnostic report (mount state, surface overrides, errors) |
Every value is clamped server-side; unknown keys are dropped.
The character starts from a supplied photo and is produced with the SenseAudio image generation API in image-to-image / reference-consistency mode (POST /v1/image/sync, model doubao-seedream-5-0-260128, reference = the photo, plain white studio backdrop requested) — the model family documented as 参考一致性生成. The shipped assets are then derived from that generation without further AI editing:
assets/MDSM-cutout.png — the raw transparent cutout.assets/MDSM.jpg — the character on a soft light card (README and Settings preview).assets/MDSM-mark.jpg — a square head-to-torso crop, centred on the detected face, for the brand marks.assets/MDSM-wallpaper.jpg — 1536×864, the extracted character at the right third with a soft ground shadow and faint bokeh.No build step, no runtime dependencies (React and @deepseek-ai/cordis are peers supplied by the harness).
npm test # node >= 22: host routes/config/stamp tests + client DOM-stub tests + the safety audit
lib/index.js — the host half: config file, three routes, HTML boot stamp.lib/client.js — the browser half: wallpaper layer, surface fade, brand-mark slots, Settings section.cordis.patch.yml — the loader row that makes both halves load.An appearance layer has no business spawning a process, reaching a network, or
reading a secret. Both halves are held to that, and test/security.test.mjs
fails if either stops holding:
| Surface | Host half | Browser half |
|---|---|---|
| Processes | none — node:child_process is never imported |
none |
| Files | one file: $DSH_HOME/MDSM.json, written temp-then-rename |
no filesystem access |
| Network | none (it serves four routes, it calls none) | only its own same-origin routes: /api/MDSM/config, /api/MDSM/diag, /api/MDSM/wallpaper, /api/MDSM/mark |
| Credentials | none | none, and no token in localStorage |
| Dynamic code | no eval, no new Function, no vm |
none, and no raw markup injection |
| Install time | nothing runs: no install, prepare or prepack hook |
— |
| Dependencies | zero runtime dependencies | — |
The full statement, including what the config file holds and what a malformed request can do, is in SECURITY.md.
The community standard is an audit plus a five-level verification: compose, boot smoke, health scan, full boot, functional test. Levels 1–4 say "it loads"; level 5 says "it paints". The evidence for this package:
| Level | Check | Result |
|---|---|---|
| L1 compose | the profile composes with the bundle mounted | dsh --profile desktop --dump-config (the application composes it on start) |
| L2 smoke | the loader mounts both halves | npm test — host and client suites |
| L3 health | static audit of the shipped files | node test/security.test.mjs → 11/11; plugin_audit.py → 0 high findings |
| L4 boot | the host half registers its routes and the boot stamp | test/host.test.mjs |
| L5 functional | the background, avatar and Settings section actually render and save | test/client.test.mjs, plus a live GUI check with the Settings card |
The manifest declares what the Harness and the plugin catalogs read without activating the plugin:
| Field | Value |
|---|---|
dsh.bundle.patch |
./cordis.patch.yml — what makes this package an installable profile bundle |
dsh.client |
platform: web, so the browser half ships with the bundle |
locale/en.json, locale/zh.json |
card title and description (meta.title, meta.description) |
icon |
./assets/MDSM-mark.jpg — the card artwork (SVG/PNG/JPEG/WebP, at most 256 KiB) |
exports |
./package.json and ./locale/*.json, the two subpaths the readers resolve |
Both locale files and the icon are resolved through the package specifier, so a
package that keeps exports sealed without these subpaths shows up under its
bare package name instead of its title.
... is not valid JSONThe Harness Host reads each profile manifest as JSON before it loads any
plugin, so one stray , before the opening { of a manifest makes the read
throw and the application stop. The Desktop recovery action "Disable
third-party plugins" cannot repair it: it re-reads the same broken manifest.
Find the damaged file — the Desktop application boots $DSH_HOME/profiles/desktop
($DSH_HOME defaults to ~/.dsh):
$home = if ($env:DSH_HOME) { $env:DSH_HOME } else { Join-Path $env:USERPROFILE '.dsh' }
Get-ChildItem (Join-Path $home 'profiles\*\package.json'), (Join-Path $home 'profiles\*\node_modules\*\package.json') -ErrorAction SilentlyContinue |
ForEach-Object { try { $null = Get-Content $_ -Raw | ConvertFrom-Json; "OK $_" } catch { "BAD $_" } }
A BAD file whose first non-space character is a comma is otherwise intact:
delete that one character. Deleting the whole file also works when it is the
profile manifest — the next start re-creates it from the shipped template and
only the bundle selection is lost, because installed packages stay in the
profile's node_modules; switch MDSM back on from Plugins. While the
manifest is broken, neither dsh plugin nor the Plugins page can run.
MDSM(Male DeepSeek Mascot,DeepSeek 男性吉祥物) —— DeepSeek Harness 网页端美化插件:由你提供的照片经 AI 生成的角色形象随插件一起分发,由 Harness 当作背景、品牌标识与设置项穿在身上。
--dsw-alias-bg-base、--dsw-specific-sidebar-fill、--dsw-alias-bg-layer-1/2)按设定透明度调淡,背景才能真正透出来。sidebar.brand.mark 与 conversation.hero.brand.mark 插槽,把侧栏与会话标题处的 logo 换成 MDSM 方形头像。/api/MDSM/...),浏览器无需访问外部网络;配置同时被盖进 HTML,页面一打开就是美化后的样子。桌面版 DeepSeek Harness:请在应用内安装——侧栏 Plugins → Add plugin,填入
https://github.com/bauerelizabeth07139/MDSM
然后打开 MDSM 这个 bundle。桌面版启动的是保留 profile desktop,而下面的命令行会把插件装进另一个 profile,桌面版不会读取它。
dsh 命令行(web profile):装进你实际启动的 profile。
dsh plugin --profile web add bauerelizabeth07139/MDSM
机器上没有 git? pnpm 解析 git 形式的依赖时会调用 git ls-remote,owner/repo、github:
这类写法在 PATH 里找不到 git 时会直接报 'git' 不是内部或外部命令。改成用 HTTPS 直接下载 tarball
即可,这条路径完全不需要 git:
dsh plugin --profile web add https://codeload.github.com/bauerelizabeth07139/MDSM/tar.gz/main
同样的地址也能填进桌面版的 Plugins → Add plugin。想要固定版本,把 main 换成提交 SHA
(/tar.gz/<sha>) 即可。
随后打开 Settings → MDSM Male DeepSeek Mascot。卸载:dsh plugin --profile web remove MDSM。
配置文件为 $DSH_HOME/MDSM.json(默认 ~/.dsh/MDSM.json),字段与取值范围见上方英文表格;服务端会做钳制并丢弃未知字段。
人物形象由 SenseAudio 图片生成接口的图生图/参考一致性模式生成(POST /v1/image/sync,模型 doubao-seedream-5-0-260128,reference 传入你的照片,提示词要求纯白影棚背景);之后的抠图与合成均为本地像素处理,不再经过 AI:近白掩码从画面边缘洪泛填充,只有与背景连通的浅色区域变透明,人物自身的白色(衬衫、高光)保持不透明,掩码再腐蚀 1px 并羽化以消除白边。三张素材(角色卡、方形头像、16:9 壁纸)全部由此裁切合成。
npm test # 需要 node >= 22,无任何运行时依赖
装扮层没有理由启动进程、访问网络或读取密钥。两个半都被这样约束,test/security.test.mjs
在这条线被越过时会直接失败:
| 面 | 宿主半 lib/index.js |
浏览器半 lib/client.js |
|---|---|---|
| 进程 | 无 —— 从不 import node:child_process |
无 |
| 文件 | 只读写一个文件:$DSH_HOME/MDSM.json,先写临时文件再改名 |
没有任何文件系统访问 |
| 网络 | 无(它只提供四条路由,不调用任何路由) | 只调自己的同源路由:/api/MDSM/config、/api/MDSM/diag、/api/MDSM/wallpaper、/api/MDSM/mark |
| 密钥 | 无 | 无,也不往 localStorage 写 token |
| 动态代码 | 无 eval、无 new Function、无 vm |
无,也不注入原始 HTML |
| 安装期 | 什么都不跑:没有 install / prepare / prepack 钩子 |
— |
| 依赖 | 零运行时依赖 | — |
完整说明(配置文件里到底存了什么、畸形请求能做到什么)见 SECURITY.md。
社区标准是"先审计、后五级验证":组合 → 启动冒烟 → 健康检查 → 全量启动 → 功能实测。 前四级只说"能加载",第五级才说"真的画出来了"。本包的证据:
| 级别 | 检查 | 结果 |
|---|---|---|
| L1 组合 | profile 带上本 bundle 能组合 | 应用启动时组合 desktop profile(dsh --profile desktop --dump-config) |
| L2 冒烟 | loader 挂载两个半 | npm test —— host 与 client 两套测试 |
| L3 健康 | 对发布文件做静态审计 | node test/security.test.mjs → 11/11;plugin_audit.py → 0 条 high |
| L4 全量启动 | 宿主半注册路由与启动戳 | test/host.test.mjs |
| L5 功能实测 | 背景、头像、设置卡片真的渲染并保存 | test/client.test.mjs,外加带设置卡片的实机 GUI 检查 |
manifest 里声明了 Harness 与插件目录在不激活插件的情况下会读取的字段:
| 字段 | 值 |
|---|---|
dsh.bundle.patch |
./cordis.patch.yml —— 让这个包成为可安装 profile bundle 的关键 |
dsh.client |
platform: web,浏览器半随 bundle 一起分发 |
locale/en.json、locale/zh.json |
卡片标题与描述(meta.title、meta.description) |
icon |
./assets/MDSM-mark.jpg —— 卡片配图(SVG/PNG/JPEG/WebP,上限 256 KiB) |
exports |
./package.json 与 ./locale/*.json,读取方解析的这两个子路径 |
两个语言文件与图标都是通过包名解析的:若 exports 没有开放这两个子路径,插件在列表里
只会显示裸包名,而不是这里的标题。
... is not valid JSONHost 在加载任何插件之前会把每个 profile manifest 当作 JSON 读取;只要某个
manifest 开头的 { 之前多出一个 ,,这次读取就会抛错,应用随之停止。桌面版
的「禁用第三方插件」恢复按钮修不好它,因为它会重新读取同一个坏文件。
定位损坏的文件(桌面版启动的是 $DSH_HOME/profiles/desktop,$DSH_HOME 默认
为 ~/.dsh):
$home = if ($env:DSH_HOME) { $env:DSH_HOME } else { Join-Path $env:USERPROFILE '.dsh' }
Get-ChildItem (Join-Path $home 'profiles\*\package.json'), (Join-Path $home 'profiles\*\node_modules\*\package.json') -ErrorAction SilentlyContinue |
ForEach-Object { try { $null = Get-Content $_ -Raw | ConvertFrom-Json; "OK $_" } catch { "BAD $_" } }
报告为 BAD 且第一个非空白字符是逗号的文件,其余内容是完好的:删掉那一个逗号
即可。如果坏的是 profile manifest 本身,直接删除整个文件也可以——下次启动会按
内置模板重建,只会丢失 bundle 的勾选记录,已安装的包仍留在 profile 的
node_modules 里,在 Plugins 页面重新打开 MDSM 即可。manifest 损坏期间,
dsh plugin 与 Plugins 页面同样无法工作。
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: theme、wallpaper。