Skip to content
dsh.fish
Bundle

dsh-plugin-forge

Human-gated DeepSeek Harness plugin creation, verification, and release studio

Source
luoyuejun9
stars
1 stars
License
MIT
Updated
Updated yesterday

Readme

# dsh-plugin-forge

`dsh-plugin-forge` is a human-gated Plugin Studio for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness). It turns a plugin idea into a versioned specification, a safe project scaffold, verification evidence, an isolated DSH installation check, and—only after explicit human confirmation—a public GitHub/npm release.

It supports four v0.1 templates: `tool-command`, `skill-wrapper`, `stateful`, and `bundle`.

## Install

```bash
dsh plugin --profile web add dsh-plugin-forge@0.1.0
```

Reload the DSH Web profile. The plugin contributes `/forge` and a replayable Plugin Forge card in chat. It targets DSH `0.1.0-rc.6`.

## Workflow

```text
/forge doctor
/forge new dsh-my-plugin --type tool-command --title "My plugin" --description "A focused DSH capability"
/forge continue <forge-id>
/forge run <forge-id>          # scaffold
/forge continue <forge-id>
/forge run <forge-id>          # implementation assistance
/forge continue <forge-id>
/forge run <forge-id>          # verification
/forge continue <forge-id>
/forge release <forge-id> --dry-run
/forge publish <forge-id> --fingerprint <sha256>
```

`/forge continue` is the only way to move one workflow stage forward. Models can read status, validate, run checks, and write bounded implementation files, but cannot approve a stage, create a repository, or publish a package.

## Safety model

- Generated projects must be new directories beneath the active DSH workspace.
- Model writes are limited to `src/`, `test/`, `schemas/`, and `docs/`; templates, dependencies, release configuration, `.git`, and credentials are protected.
- Dependencies are compared against a small DSH/TypeScript allowlist.
- Verification runs `npm install --ignore-scripts`, typecheck, test, build, pack preview, secret scan, and a clean DSH profile install.
- Publishing requires the current release fingerprint. Any project change invalidates the intended release plan.
- Forge invokes existing `git`, `gh`, and `npm` sessions but never reads or stores their credentials.

## Web Studio card

The chat card is a native DSH Conversation Node. It rebuilds status from durable `forge/*` session events, so status survives replay and loading more chat history. The card provides concise stage, check, detail, and next-command context. It uses system typography, instant progress feedback, and reduced-motion/contrast fallbacks.

## Development

```bash
npm install
npm run check
npm pack --dry-run
```

MIT licensed. [中文文档](README.zh.md)

Install

dsh plugin --profile web add github:luoyuejun9/dsh-plugin-forge#45f78fb59140af6ecd23aba1599fe9697ba53df5

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
Source