← Back to home@bauerelizabeth07139

MDSM

MDSM (Male DeepSeek Mascot) appearance layer for the DeepSeek Harness Web GUI: chat wallpaper with opacity, blur and scrim controls, an avatar brand mark, and a Settings section.

Stars
0
Language
JavaScript
Created
Sep 30, 2026
Updated
Oct 5, 2026
GitHub repo

Introduction

MDSM

dsh.so risk

MDSM — Male DeepSeek Mascot for the DeepSeek Harness Web GUI: a mascot character generated from a supplied photo, shipped inside the plugin, worn by the harness as its background, its brand mark, and its settings surface.

MDSM character MDSM wallpaper

What it does

  • Chat background — the shipped 16:9 artwork is mounted as a fixed, click-through layer behind the whole GUI. The shell's surface tokens (--dsw-alias-bg-base, --dsw-specific-sidebar-fill, --dsw-alias-bg-layer-1/2) are faded to the configured opacity so the wallpaper actually shows through instead of hiding behind an opaque shell, and the root background is cleared for it.
  • Controls — opacity of the shell surfaces, wallpaper blur, a dark scrim for readability, and background-position, all applied live.
  • Brand mark — the square MDSM avatar replaces the logo in the sidebar and the conversation hero through the stock sidebar.brand.mark and conversation.hero.brand.mark slots.
  • Settings section — an 「MDSM Male DeepSeek Mascot」 page in Settings edits everything, with previews of both artworks, and applies on save.
  • Tab icon — the browser tab favicon follows the same MDSM avatar while the brand mark is on, and the stock icons come back when it is switched off.
  • Host half — serves the artwork and the config from the local DSH web server (/api/MDSM/...), so the browser never reaches outside, and stamps the config into the HTML so the GUI comes up already dressed.

Install

DeepSeek Harness Desktop — install it from the application, not from a shell: open Plugins in the sidebar, choose Add plugin, enter

https://github.com/bauerelizabeth07139/MDSM

and switch the new MDSM bundle on. The Desktop application boots the reserved desktop profile, so the command below installs into a different profile that the Desktop app never reads.

dsh CLI (web profile) — install it into the profile you boot:

dsh plugin --profile web add bauerelizabeth07139/MDSM

No git on the machine? pnpm resolves a git shorthand with git ls-remote, so an owner/repo or github: spec fails with 'git' is not recognized when git is missing from PATH. Install the published tarball over plain HTTPS instead — that path never calls git:

dsh plugin --profile web add https://codeload.github.com/bauerelizabeth07139/MDSM/tar.gz/main

The same address works in the Desktop application's Plugins → Add plugin dialog. Pin the revision by replacing main with a commit SHA (/tar.gz/<sha>) when you want a fixed build.

Any spec the plugin manager accepts works — a GitHub shorthand, a full git URL, or a local checkout:

dsh plugin --profile web add https://github.com/bauerelizabeth07139/MDSM.git
dsh plugin --profile web add C:\path\to\MDSM

Then open Settings → MDSM Male DeepSeek Mascot. Uninstall with dsh plugin --profile web remove MDSM.

Configuration

The config lives at $DSH_HOME/MDSM.json (default ~/.dsh/MDSM.json) and is edited by the Settings section; it is also reachable over HTTP.

FieldDefaultMeaning
wallpapertrueWear the MDSM artwork as the GUI background
brandtrueReplace the sidebar and hero logos with the MDSM avatar
surfaceOpacity60Shell surface opacity in % — lower shows more of the wallpaper, higher keeps the shell opaque (25–100)
blur0Gaussian blur applied to the wallpaper, in px (0–24)
scrim35Palette-matched wash over the wallpaper — black in the dark theme, white in the light theme — for a readable transcript, in % (0–90)
positioncenterWallpaper background-position: center, left, right, top, bottom
RouteMethodPurpose
/api/MDSM/configGET / PUTRead / write the config (writes are same-origin only)
/api/MDSM/wallpaperGETThe 16:9 background artwork
/api/MDSM/markGETThe square avatar artwork
/api/MDSM/diagGET / POSTLast browser-side diagnostic report (mount state, surface overrides, errors)

Every value is clamped server-side; unknown keys are dropped.

Artwork provenance

The character starts from a supplied photo and is produced with the SenseAudio image generation API in image-to-image / reference-consistency mode (POST /v1/image/sync, model doubao-seedream-5-0-260128, reference = the photo, plain white studio backdrop requested) — the model family documented as 参考一致性生成. The shipped assets are then derived from that generation without further AI editing:

  • Extraction — a near-white mask is flood-filled from the image border, so only the background-connected light area becomes transparent; the character's own whites (shirt, highlights) stay opaque. The mask is eroded by 1px and feathered to avoid a light fringe.
  • assets/MDSM-cutout.png — the raw transparent cutout.
  • assets/MDSM.jpg — the character on a soft light card (README and Settings preview).
  • assets/MDSM-mark.jpg — a square head-to-torso crop, centred on the detected face, for the brand marks.
  • assets/MDSM-wallpaper.jpg — 1536×864, the extracted character at the right third with a soft ground shadow and faint bokeh.

Development

No build step, no runtime dependencies (React and @deepseek-ai/cordis are peers supplied by the harness).

npm test   # node >= 22: host routes/config/stamp tests + client DOM-stub tests + the safety audit
  • lib/index.js — the host half: config file, three routes, HTML boot stamp.
  • lib/client.js — the browser half: wallpaper layer, surface fade, brand-mark slots, Settings section.
  • cordis.patch.yml — the loader row that makes both halves load.

Safety

An appearance layer has no business spawning a process, reaching a network, or reading a secret. Both halves are held to that, and test/security.test.mjs fails if either stops holding:

SurfaceHost halfBrowser half
Processesnone — node:child_process is never importednone
Filesone file: $DSH_HOME/MDSM.json, written temp-then-renameno filesystem access
Networknone (it serves four routes, it calls none)only its own same-origin routes: /api/MDSM/config, /api/MDSM/diag, /api/MDSM/wallpaper, /api/MDSM/mark
Credentialsnonenone, and no token in localStorage
Dynamic codeno eval, no new Function, no vmnone, and no raw markup injection
Install timenothing runs: no install, prepare or prepack hook—
Dependencieszero runtime dependencies—

The full statement, including what the config file holds and what a malformed request can do, is in SECURITY.md.

Five-level verification

The community standard is an audit plus a five-level verification: compose, boot smoke, health scan, full boot, functional test. Levels 1–4 say "it loads"; level 5 says "it paints". The evidence for this package:

LevelCheckResult
L1 composethe profile composes with the bundle mounteddsh --profile desktop --dump-config (the application composes it on start)
L2 smokethe loader mounts both halvesnpm test — host and client suites
L3 healthstatic audit of the shipped filesnode test/security.test.mjs → 11/11; plugin_audit.py → 0 high findings
L4 bootthe host half registers its routes and the boot stamptest/host.test.mjs
L5 functionalthe background, avatar and Settings section actually render and savetest/client.test.mjs, plus a live GUI check with the Settings card

Plugin metadata

The manifest declares what the Harness and the plugin catalogs read without activating the plugin:

FieldValue
dsh.bundle.patch./cordis.patch.yml — what makes this package an installable profile bundle
dsh.clientplatform: web, so the browser half ships with the bundle
locale/en.json, locale/zh.jsoncard title and description (meta.title, meta.description)
icon./assets/MDSM-mark.jpg — the card artwork (SVG/PNG/JPEG/WebP, at most 256 KiB)
exports./package.json and ./locale/*.json, the two subpaths the readers resolve

Both locale files and the icon are resolved through the package specifier, so a package that keeps exports sealed without these subpaths shows up under its bare package name instead of its title.

Troubleshooting

The application does not start: ... is not valid JSON

The Harness Host reads each profile manifest as JSON before it loads any plugin, so one stray , before the opening { of a manifest makes the read throw and the application stop. The Desktop recovery action "Disable third-party plugins" cannot repair it: it re-reads the same broken manifest.

Find the damaged file — the Desktop application boots $DSH_HOME/profiles/desktop ($DSH_HOME defaults to ~/.dsh):

$home = if ($env:DSH_HOME) { $env:DSH_HOME } else { Join-Path $env:USERPROFILE '.dsh' }
Get-ChildItem (Join-Path $home 'profiles\*\package.json'), (Join-Path $home 'profiles\*\node_modules\*\package.json') -ErrorAction SilentlyContinue |
  ForEach-Object { try { $null = Get-Content $_ -Raw | ConvertFrom-Json; "OK   $_" } catch { "BAD  $_" } }

A BAD file whose first non-space character is a comma is otherwise intact: delete that one character. Deleting the whole file also works when it is the profile manifest — the next start re-creates it from the shipped template and only the bundle selection is lost, because installed packages stay in the profile's node_modules; switch MDSM back on from Plugins. While the manifest is broken, neither dsh plugin nor the Plugins page can run.

中文

MDSM(Male DeepSeek Mascot,DeepSeek 男性吉祥物) —— DeepSeek Harness 网页端美化插件:由你提供的照片经 AI 生成的角色形象随插件一起分发,由 Harness 当作背景、品牌标识与设置项穿在身上。

功能

  • 聊天背景:内置 16:9 素材作为不可点击的全屏背景层;同时把界面的表面色令牌(--dsw-alias-bg-base、--dsw-specific-sidebar-fill、--dsw-alias-bg-layer-1/2)按设定透明度调淡,背景才能真正透出来。
  • 可调参数:界面不透明度、背景模糊、暗色遮罩、壁纸位置,改动即时生效。
  • 品牌标识:通过官方的 sidebar.brand.mark 与 conversation.hero.brand.mark 插槽,把侧栏与会话标题处的 logo 换成 MDSM 方形头像。
  • 设置页:Settings 里的「MDSM Male DeepSeek Mascot」页面提供素材预览与全部开关,保存即生效。
  • 标签页图标:品牌标识开启时,浏览器标签页小图标也换成同一张 MDSM 头像;关闭后恢复官方图标。
  • 宿主半:由本地 DSH Web 服务直接提供素材与配置接口(/api/MDSM/...),浏览器无需访问外部网络;配置同时被盖进 HTML,页面一打开就是美化后的样子。

安装

桌面版 DeepSeek Harness:请在应用内安装——侧栏 Plugins → Add plugin,填入

https://github.com/bauerelizabeth07139/MDSM

然后打开 MDSM 这个 bundle。桌面版启动的是保留 profile desktop,而下面的命令行会把插件装进另一个 profile,桌面版不会读取它。

dsh 命令行(web profile):装进你实际启动的 profile。

dsh plugin --profile web add bauerelizabeth07139/MDSM

机器上没有 git? pnpm 解析 git 形式的依赖时会调用 git ls-remote,owner/repo、github: 这类写法在 PATH 里找不到 git 时会直接报 'git' 不是内部或外部命令。改成用 HTTPS 直接下载 tarball 即可,这条路径完全不需要 git:

dsh plugin --profile web add https://codeload.github.com/bauerelizabeth07139/MDSM/tar.gz/main

同样的地址也能填进桌面版的 Plugins → Add plugin。想要固定版本,把 main 换成提交 SHA (/tar.gz/<sha>) 即可。

随后打开 Settings → MDSM Male DeepSeek Mascot。卸载:dsh plugin --profile web remove MDSM。

配置

配置文件为 $DSH_HOME/MDSM.json(默认 ~/.dsh/MDSM.json),字段与取值范围见上方英文表格;服务端会做钳制并丢弃未知字段。

素材来源

人物形象由 SenseAudio 图片生成接口的图生图/参考一致性模式生成(POST /v1/image/sync,模型 doubao-seedream-5-0-260128,reference 传入你的照片,提示词要求纯白影棚背景);之后的抠图与合成均为本地像素处理,不再经过 AI:近白掩码从画面边缘洪泛填充,只有与背景连通的浅色区域变透明,人物自身的白色(衬衫、高光)保持不透明,掩码再腐蚀 1px 并羽化以消除白边。三张素材(角色卡、方形头像、16:9 壁纸)全部由此裁切合成。

开发

npm test   # 需要 node >= 22,无任何运行时依赖

安全

装扮层没有理由启动进程、访问网络或读取密钥。两个半都被这样约束,test/security.test.mjs 在这条线被越过时会直接失败:

面宿主半 lib/index.js浏览器半 lib/client.js
进程无 —— 从不 import node:child_process无
文件只读写一个文件:$DSH_HOME/MDSM.json,先写临时文件再改名没有任何文件系统访问
网络无(它只提供四条路由,不调用任何路由)只调自己的同源路由:/api/MDSM/config、/api/MDSM/diag、/api/MDSM/wallpaper、/api/MDSM/mark
密钥无无,也不往 localStorage 写 token
动态代码无 eval、无 new Function、无 vm无,也不注入原始 HTML
安装期什么都不跑:没有 install / prepare / prepack 钩子—
依赖零运行时依赖—

完整说明(配置文件里到底存了什么、畸形请求能做到什么)见 SECURITY.md。

五级验证

社区标准是"先审计、后五级验证":组合 → 启动冒烟 → 健康检查 → 全量启动 → 功能实测。 前四级只说"能加载",第五级才说"真的画出来了"。本包的证据:

级别检查结果
L1 组合profile 带上本 bundle 能组合应用启动时组合 desktop profile(dsh --profile desktop --dump-config)
L2 冒烟loader 挂载两个半npm test —— host 与 client 两套测试
L3 健康对发布文件做静态审计node test/security.test.mjs → 11/11;plugin_audit.py → 0 条 high
L4 全量启动宿主半注册路由与启动戳test/host.test.mjs
L5 功能实测背景、头像、设置卡片真的渲染并保存test/client.test.mjs,外加带设置卡片的实机 GUI 检查

插件元数据

manifest 里声明了 Harness 与插件目录在不激活插件的情况下会读取的字段:

字段值
dsh.bundle.patch./cordis.patch.yml —— 让这个包成为可安装 profile bundle 的关键
dsh.clientplatform: web,浏览器半随 bundle 一起分发
locale/en.json、locale/zh.json卡片标题与描述(meta.title、meta.description)
icon./assets/MDSM-mark.jpg —— 卡片配图(SVG/PNG/JPEG/WebP,上限 256 KiB)
exports./package.json 与 ./locale/*.json,读取方解析的这两个子路径

两个语言文件与图标都是通过包名解析的:若 exports 没有开放这两个子路径,插件在列表里 只会显示裸包名,而不是这里的标题。

疑难解答

应用无法启动,报 ... is not valid JSON

Host 在加载任何插件之前会把每个 profile manifest 当作 JSON 读取;只要某个 manifest 开头的 { 之前多出一个 ,,这次读取就会抛错,应用随之停止。桌面版 的「禁用第三方插件」恢复按钮修不好它,因为它会重新读取同一个坏文件。

定位损坏的文件(桌面版启动的是 $DSH_HOME/profiles/desktop,$DSH_HOME 默认 为 ~/.dsh):

$home = if ($env:DSH_HOME) { $env:DSH_HOME } else { Join-Path $env:USERPROFILE '.dsh' }
Get-ChildItem (Join-Path $home 'profiles\*\package.json'), (Join-Path $home 'profiles\*\node_modules\*\package.json') -ErrorAction SilentlyContinue |
  ForEach-Object { try { $null = Get-Content $_ -Raw | ConvertFrom-Json; "OK   $_" } catch { "BAD  $_" } }

报告为 BAD 且第一个非空白字符是逗号的文件,其余内容是完好的:删掉那一个逗号 即可。如果坏的是 profile manifest 本身,直接删除整个文件也可以——下次启动会按 内置模板重建,只会丢失 bundle 的勾选记录,已安装的包仍留在 profile 的 node_modules 里,在 Plugins 页面重新打开 MDSM 即可。manifest 损坏期间, dsh plugin 与 Plugins 页面同样无法工作。

License

MIT