wwumit
dsh-compliancehub
Remote skill provider for DeepSeek Harness: install skills from a JSON catalog via ctx.skills
- Stars
- 0
- Language
- TypeScript
- Created
- Aug 16, 2026
- Updated
- Aug 16, 2026
Introduction
wwumit · 治理驱动的 AI 技能生态 — 规则 → 检查 → 评分 → 报告
产品线:合规(compliancehub)· 股票 · 工具 · 数据层 catalog
dsh-compliancehub
Remote skill provider for DeepSeek Harness:
install skills from a JSON catalog through the standard ctx.skills registry —
no manual folder copying.
list()— fetch + validate a curated catalog, expose its skills to the registryget()— fetch theSKILL.mdbody on demand from the owning repo- Fail-soft semantics: a catalog outage yields an incomplete observation (consumers keep their last-good catalog), never an authoritative empty list
Install
npm install @wwumit/dsh-compliancehub
# peer deps: @deepseek-ai/cordis, @deepseek-ai/dsh-skill
Usage (composition)
import { Context } from '@deepseek-ai/cordis'
import * as skillHub from '@wwumit/dsh-compliancehub'
export function apply(ctx: Context) {
ctx.plugin(skillHub, {
catalogUrl: 'https://wwumit.github.io/skills-catalog/catalog.json',
// providerName: 'hub' // unique name on ctx.skills
// rank: 250 // duplicate-name resolution (lower wins)
// requestTimeoutMs: 10000
// baseUrl: 'https://raw.githubusercontent.com'
// branch: 'main'
})
}
Once loaded, DSH's model session catalog includes the provider's skills and the
model can invoke them via the built-in skill tool.
Catalog format
{
"schemaVersion": 1,
"disclosureSchemaVersion": "0.2",
"updatedAt": "2026-08-16T00:00:00Z",
"skills": [
{
"name": "ccpa-check",
"fullName": "wwumit/skills-compliance-intl",
"skillFullName": "wwumit/skills-compliance-intl/skills/ccpa-check",
"description": "CCPA/CPRA compliance check …",
"repo": "wwumit/skills-compliance-intl",
"version": "2.2.4",
"disclosure": { "cloud": true, "network": ["https://compliancehub.cn"], "offlineMode": true },
"files": ["SKILL.md", "scripts/ccpa-check.py"]
}
],
"repos": [
{ "fullName": "wwumit/skills-compliance-intl", "skillCount": 9,
"cloudSkills": ["ccpa-check", "coppa-check", "gdpr-check", "hipaa-check"] }
]
}
Generate a catalog from a skill workspace with the included
catalog/build-catalog.mjs script (curated via catalog/curated.json).
Verified (DSH 实机验证)
verify-dsh.ts 在真实 DSH 运行时验证通过(SkillRegistry + provider 注册):
✅ ctx.skills.list() → 21 个技能(provider 层合并后)
✅ ctx.skills.get('ccpa-check') → 正文 {n} 字节
- 验证方式:注册
ctx.skills.registerProvider→ 真实list()/get()调用线上 catalog - 结果随版本演进记录在 CHANGELOG.md;目录收录方可用此作为"含实测结果"证据
Disclosure (DISCLOSURE v0.2 开放数据层)
catalog 提供双颗粒度披露(市场/目录构建期单请求抓取消费):
{
"disclosureSchemaVersion": "0.2",
"skills": [
{ "name": "ccpa-check", "fullName": "wwumit/skills-compliance-intl",
"skillFullName": "wwumit/skills-compliance-intl/skills/ccpa-check",
"disclosure": { "cloud": true, "network": ["https://compliancehub.cn"],
"offlineMode": true, "apiKeys": [{"env": "COMPLIANCEHUB_API_KEY", "storage": "file-0600"}],
"jurisdiction": ["US-CA"], "retention": "session" } }
],
"repos": [
{ "fullName": "wwumit/skills-compliance-intl", "skillCount": 9,
"cloudSkills": ["ccpa-check", "coppa-check", "gdpr-check", "hipaa-check"] }
]
}
- 21 个精选技能全部披露:4 个云端评分(compliancehub.cn)+ 17 个纯本地(cloud:false)
- 声明源 = SKILL.md frontmatter(snake_case);聚合源 = catalog.json(camelCase);构建脚本
build-catalog.mjs可复现 - 披露检查由
skill-compliancev1.4.0 自动执行(D1/D3/D4 完整性 + 声明-代码一致性 + 宿主依赖)
Development
pnpm install
pnpm test # vitest (mocked fetch)
pnpm build # tsc → lib/
Model Experience
Request context and condition
What the model sees
No system-prompt prose is added by this package. Skills served by the provider
appear in the standard model session catalog (<available_skills>) exactly like
locally installed skills, with name and description from the catalog.
Token effect
Zero direct token contribution: the provider only feeds the shared skills catalog,
whose rendering cost is owned by the DSH skill consumer (@deepseek-ai/dsh-tool-skill).
KV Cache effect
Independent of model requests; no prompt-prefix contribution, so cache reuse is unaffected by provider activity.
Known Limitations and Deferred Work
- Body-only fetch —
get()currently fetchesSKILL.mdonly; script/resource files listed in the catalog manifest are not yet downloaded into a local cache (resourceBaseresolution is future work). - Catalog caching —
list()refetches on every call; a TTL cache keyed by the resolved catalog URL is planned. - Auth — no support yet for private catalogs or signed URLs.