Dsh Upgrade Audit
NanmiCoder/dsh-auto-mode
Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…
DeepSeek Harness(DSH)插件的设计、开发、装载验证、版本迁移与发布审查指引(版本感知)。在用户要为 DSH Desktop 开发插件、把 Pi/Hermes 插件迁移到 DSH、做隔离装载实验、排查插件在真实宿主的行为、跟进 DSH 版本升级适配,或在发布前做机械审查与验收(dsh.bundle / dsh.client 双面包工件契约、inject/external…
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-dev --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dsh-plugin-dev .claude/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .claude/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-devType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-dev --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/dsh-plugin-dev .agents/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .agents/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-dev --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/dsh-plugin-dev .cursor/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .cursor/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cat-xierluo/legal-skills.git --path skills/dsh-plugin-dev--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-dev --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/dsh-plugin-dev .gemini/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .gemini/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-devInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/dsh-plugin-dev .github/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .github/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cat-xierluo/legal-skills dsh-plugin-dev --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cat-xierluo/legal-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/dsh-plugin-dev .opencode/skills/dsh-plugin-dev && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dsh-plugin-dev" agent skill from https://github.com/cat-xierluo/legal-skills/tree/main/skills/dsh-plugin-dev into .opencode/skills/dsh-plugin-dev/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-plugin-dev", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dsh-plugin-devDeepSeek Harness(DSH)插件的设计、开发、装载验证、版本迁移与发布审查指引(版本感知)。在用户要为 DSH Desktop 开发插件、把 Pi/Hermes 插件迁移到 DSH、做隔离装载实验、排查插件在真实宿主的行为、跟进 DSH 版本升级适配,或在发布前做机械审查与验收(dsh.bundle / dsh.client 双面包工件契约、inject/external…
Dsh Plugin Dev is an agent skill from cat-xierluo/legal-skills. DeepSeek Harness(DSH)插件的设计、开发、装载验证、版本迁移与发布审查指引(版本感知)。在用户要为 DSH Desktop 开发插件、把 Pi/Hermes 插件迁移到 DSH、做隔离装载实验、排查插件在真实宿主的行为、跟进 DSH 版本升级适配,或在发布前做机械审查与验收(dsh.bundle / dsh.client 双面包工件契约、inject/external 对账、主题变量、类型化 locale)时使用。不要用于普通 npm 包审查或与 DSH 无关的 agent 项目。
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `CHANGELOG.md`, `config/harness-path.example.yaml` and `references/desktop-load-and-isolation.md`).
It works with DeepSeek and npm. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c077fcc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dsh Plugin Dev loads about 1.5k tokens when it runs, and up to ~18k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 374 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from cat-xierluo/legal-skills at commit c077fcc, republished under its MIT licence (© cat-xierluo). 374 words, ~1,548 tokens.
.claude/skills/dsh-plugin-dev/SKILL.md (or your agent's skills folder). This skill also uses 14 other files; get the full folder from GitHub.DSH 插件开发指引 Skill(2026-09-29 由 dsh-plugin-lint 并入吸收:开发主线 + 机械审查一体)。沉淀来源:dsh-plugins 仓库全程开发实测(真实 DSH Desktop 2.0.15 / 内嵌运行时 0.1.7-rc.2,五次隔离装载实验、14 个 PR 的独立审查修复)+ dsh-contract-copilot 0.1.2 期开发实测。
本技能不代替实现者:创建插件时先做设计预检,实现后回来做正式验收——审查器与生产者不混同责任。
scripts/lint.mjs → 机械审查层(版本感知,规则清单见下)scripts/test-lint.mjs → 自测(自包含 fixture,证明每条规则抓得住无效样本、放行有效对照)config/harness-path.example.yaml → 复制为 config/harness-path.local.yaml 填本地 harness 仓库路径(不提交)templates/plugin-quality-report.md → 正式审查的报告模板(结论带 NOT_VERIFIED 语义)node:module.isBuiltin),无第三方包——脚本开箱即用。/Applications/DSH Desktop.app/.../node_modules/@deepseek-ai/)是另一事实源,二者对照用。dsh.bundle.patch → cordis.patch.yml,insert 行 id/name 均 string)、半体范围(先 Host-only 再 client)、服务依赖(inject——硬依赖缺失插件等待不激活)、零依赖原则(@deepseek-ai/* 视为宿主 external)。要点见 host-plugin-essentials。Pi 插件 DSH 化起手切片(PR #37 三插件实证):新建打包层三件套(package.json/patch/index.mjs,Pi 源码一字不动、不 import)+ bizlink 消费者(owner kind 命名空间)+ 自检链(只断言自身命名空间)——mock 级先行,装载验证批量入用户窗口。起手后的领域平移走 porting-semantics:源码去 flopi-candidate 找全量、语义出处行号锚定、偏离只许更严方向、外部 IO 一律注入缝 + 缺省 fail-closed(PR #42/#45/#46/#49/#51 实证)。type: module、入口用 .mjs(实测组合回归);ctx.provide + ctx.logger.info 启动标记 + ctx.effect 返回 disposer。类型查找先搜 dsh-tool-cordis/lib/types/api-catalog.js 与各包 README.zh.md——内嵌树 .d.ts 已剥离,包 lib 导出面查不到 ≠ 全树缺失。stateVersion、通知只走 wire、真实 turn id 是数字);业务对象↔会话关联走共享服务(dsh-bizlink 先例:owner 在 revision 权威处做乐观并发);模型调用与一切公共能力先查官方复用(official-capabilities:目录 + 查证方法;已核 ctx.llm 为唯一受支持模型调用入口,勿自建)。@deepseek-ai/dsh-web-app;官方 bundle 从安装锚点解析,本地插件放符号链接即可零物化装载)、DSH_HOME 隔离启动、宿主日志找激活标记、SIGTERM 分步退出、恢复生产(profile-selection 快照/恢复)。ctx.get)、域 schema 只在 open 边界校验、写路径须过真实域校验的回归用例(防 best-effort 吞错造成静默失效)依次核过。headless 验证入口与证据纪律见 pitfalls-log「宿主验证与证据纪律」节(每轮异名落盘、driver/dump 同 commit 互证、门序断言确认前道门未短路、计数器须真注入、文件级≠记录级、离线桩≠网络失败)。scripts/lint.mjs)node skills/dsh-plugin-dev/scripts/lint.mjs <插件目录> --harness-root <DSH 源码仓库>
node skills/dsh-plugin-dev/scripts/test-lint.mjs # 自测,退出码 0 = 全部规则自证有效harness 根解析优先级:--harness-root 参数 → DSH_HARNESS_ROOT 环境变量 → config/harness-path.local.yaml。--json 追加机器可读行;退出码 = FAIL 数。规则节:§0 harness 溯源(版本/commit/模块表)|§1 package.json 版本漂移|§2 dsh.bundle|§3 exports 入口|§4 dsh.client(inject 目标声明、external 自引用/越界)|§5 client 工件(banner/footer、bare require ↔ 模块表、构建 external 对账)|§6 主题变量声明集对账|§7 类型化 locale 与 CJK 硬编码|§8 卫生|§9 文档版本残留。
| 模式 | 时机 | 必做 |
|---|---|---|
| 设计预检 | 写代码前 | 过一遍 development-standards 契约节 + 本 SKILL 踩坑;事件/slot 名先溯源 |
| 快速审查 | 第三方/草稿 | 机械 + 事实 + 契约;结论带 NOT_VERIFIED |
| 正式验收 | 发布/声称完成前 | 全部 + 候选绑定证据(commit + 干净 profile 安装 + boot 无错 + 工具真实调用 + 浏览器渲染截图;缺任一 → NOT_VERIFIED) |
审查工作原则(继承自 lint 1.0.0):先机械后语义;版本感知不冻结假设;对 harness 的每个 API/事件/slot 引用必须溯源到源码路径(实测案例:文档写过不存在的 CLI flag 与 agent/post-step 事件);不采信自报 PASS;客观缺陷 fail-closed,语义不确定只出 WARN/NOT_VERIFIED 绝不出假 PASS。
latest = 内嵌版;next 是预发布无桌面内嵌)。错位研究必须按实物重核。DSH_HOME 隔离目录 + 合成数据;不读生产 sessions/凭据/settings;动共享 userData 前快照后恢复;关生产实例前后向用户报备。open -a 转发给未死尽的实验实例。一个开发切片:结构校验 → mock 集成测试 →(有条件时)隔离装载宿主日志证据 → 独立审查处置 → 文档与踩坑回写。发布验收按上节正式模式。缺装载证据明标 NOT_VERIFIED,不宣称"已在真实宿主可用"。
ctx.llm 模型调用、ctx.jobs 会话内长任务、packages/schedule 持久定时、ctx.tools 模型工具注册、ctx.storageDomain 持久 KV——后两条含零依赖实现姿势;插件 Config/settings 表单机制与 domain/changed 存储域变更事件——含手写 schema 三暗门与进程内边界)与待查清单。maoscripts/dsh-plugins(evidence 与 PR 审查修复记录,本 Skill 事实的原始出处)。--harness-root 读取的当前事实,不预置版本号。© cat-xierluo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 14 other files (scripts, references) in skills/dsh-plugin-dev of cat-xierluo/legal-skills.
Open the folder on GitHubat commit c077fcc
Dsh Plugin Dev next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dsh Plugin Dev this skillcat-xierluo/legal-skills | 713 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Dsh Upgrade AuditNanmiCoder/dsh-auto-mode | 165 | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| OpenGUI Installer for DSHCore-Mate/OpenGUI | 1.8k | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Studyalaliqing/claude-paper | 344 | — | ~2.5k | Automated safety check: Notes | MIT | |
| Daily Briefleiting-eric/DailyBrief | 364 | — | ~3k | Automated safety check: Notes | MIT | |
| Skin Developerningbainb/deepseek-harness-desktop | 776 | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause |
NanmiCoder/dsh-auto-mode
Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…
Core-Mate/OpenGUI
Installs and verifies the latest stable OpenGUI release in a DeepSeek Harness web profile on macOS without disturbing existing plugins or settings.
alaliqing/claude-paper
A skill your agent uses when the user wants to read, study, analyze, or deeply understand a research paper (PDF).
leiting-eric/DailyBrief
Operational knowledge for the daily-brief digest pipeline (this project).
ningbainb/deepseek-harness-desktop
Build a new skin for the dsh-web-ui skin collection (DSH Web GUI) and publish it into the skin-center plugin — scaffold with scripts/dsh-skin-new, author skin.json plus the apply/dispose +…
Nagi-ovo/dsh-find-plugins
用户想给 DeepSeek Harness 找插件时使用:「有没有插件能……」「帮我装个 XX」 「生态里有什么好玩的」。从全 GitHub 的 dsh-plugin topic 发现跨个人与组织的 公开仓库,筛选候选,等用户拍板,先汇报这个插件要什么权限,再从仓库声明判断 安装方式并验证挂载。只负责找和装;开发新插件转 make-dsh-plugin。
cat-xierluo/legal-skills
Converts a lawyer's ordinary complaint or a described case into the Supreme People's Court's elements-style Word template, with layout checks on the result.
cat-xierluo/legal-skills
Analyzes raw lecture transcripts for verbal tics, pacing, time use and promise follow-through, with optional slide-by-slide comparison and cross-session tracking.
cat-xierluo/legal-skills
Detects and rewrites machine-sounding patterns in the body text of Chinese articles while keeping the author's facts, headings and legal terms intact.
cat-xierluo/legal-skills
Finds GitHub projects mentioned in articles or screenshots and stars them, tracks updates to your starred repos, and builds an HTML dashboard to browse them.
cat-xierluo/legal-skills
Sets up or incrementally updates AGENTS.md and CLAUDE.md for legal professionals, with a minimal safety baseline and a check that a new session loads and follows the rules.
cat-xierluo/legal-skills
Chinese-language skill that organizes a case file into a multi-role mock trial with judge, parties and clerk, producing a transcript, issue review and a to-strengthen list.
DeepSeek Harness(DSH)插件的设计、开发、装载验证、版本迁移与发布审查指引(版本感知)。在用户要为 DSH Desktop 开发插件、把 Pi/Hermes 插件迁移到 DSH、做隔离装载实验、排查插件在真实宿主的行为、跟进 DSH 版本升级适配,或在发布前做机械审查与验收(dsh.bundle / dsh.client 双面包工件契约、inject/external…. Dsh Plugin Dev is an agent skill from cat-xierluo/legal-skills.
Run `npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a claude-code`. Or copy the skill folder (skills/dsh-plugin-dev in cat-xierluo/legal-skills) into .claude/skills/dsh-plugin-dev in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a codex`. Or copy the skill folder (skills/dsh-plugin-dev in cat-xierluo/legal-skills) into .agents/skills/dsh-plugin-dev in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cat-xierluo/legal-skills --skill dsh-plugin-dev -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsh-plugin-dev, .gemini/skills/dsh-plugin-dev, .github/skills/dsh-plugin-dev and .opencode/skills/dsh-plugin-dev in your project.
Going by SKILL.md and its folder, Dsh Plugin Dev needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Dsh Plugin Dev is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Dsh Plugin Dev: Dsh Upgrade Audit (NanmiCoder/dsh-auto-mode, 165 stars), OpenGUI Installer for DSH (Core-Mate/OpenGUI, 1.8k stars), Study (alaliqing/claude-paper, 344 stars) and Daily Brief (leiting-eric/DailyBrief, 364 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cat-xierluo (a GitHub user) maintains it in cat-xierluo/legal-skills, which has 713 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on October 6, 2026.
Source: cat-xierluo/legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.