Back to home

luoyuejun9

dsh-plugin-forge

Human-gated DeepSeek Harness plugin creation, verification, and release studio

Stars
1
Language
TypeScript
Created
Aug 16, 2026
Updated
Aug 16, 2026

Introduction

dsh-plugin-forge

dsh-plugin-forge is a human-gated Plugin Studio for DeepSeek Harness. It turns a plugin idea into a versioned specification, a safe project scaffold, verification evidence, an isolated DSH installation check, and—only after explicit human confirmation—a public GitHub/npm release.

It supports four v0.1 templates: tool-command, skill-wrapper, stateful, and bundle.

Install

dsh plugin --profile web add dsh-plugin-forge@0.1.0

Reload the DSH Web profile. The plugin contributes /forge and a replayable Plugin Forge card in chat. It targets DSH 0.1.0-rc.6.

Workflow

/forge doctor
/forge new dsh-my-plugin --type tool-command --title "My plugin" --description "A focused DSH capability"
/forge continue <forge-id>
/forge run <forge-id>          # scaffold
/forge continue <forge-id>
/forge run <forge-id>          # implementation assistance
/forge continue <forge-id>
/forge run <forge-id>          # verification
/forge continue <forge-id>
/forge release <forge-id> --dry-run
/forge publish <forge-id> --fingerprint <sha256>

/forge continue is the only way to move one workflow stage forward. Models can read status, validate, run checks, and write bounded implementation files, but cannot approve a stage, create a repository, or publish a package.

Safety model

  • Generated projects must be new directories beneath the active DSH workspace.
  • Model writes are limited to src/, test/, schemas/, and docs/; templates, dependencies, release configuration, .git, and credentials are protected.
  • Dependencies are compared against a small DSH/TypeScript allowlist.
  • Verification runs npm install --ignore-scripts, typecheck, test, build, pack preview, secret scan, and a clean DSH profile install.
  • Publishing requires the current release fingerprint. Any project change invalidates the intended release plan.
  • Forge invokes existing git, gh, and npm sessions but never reads or stores their credentials.

Web Studio card

The chat card is a native DSH Conversation Node. It rebuilds status from durable forge/* session events, so status survives replay and loading more chat history. The card provides concise stage, check, detail, and next-command context. It uses system typography, instant progress feedback, and reduced-motion/contrast fallbacks.

Development

npm install
npm run check
npm pack --dry-run

MIT licensed. 中文文档