DeepSeek Harness plugin

dsh-github-chenyimi

GitHub 集成插件 for DeepSeek Harness:一次认证(GITHUB_TOKEN 或 OAuth Device Flow)后模型可直接调用 GitHub REST API 完成建仓、推送、提 PR、管 issue、搜索等 45 个工具;常规读写直接放行,删除/force push/合并 PR/关 issue 等危险操作保留审批门;token 存于 DSH

Jump to install

Source facts

Repository
ChenYiming-aaa/dsh-github
Latest update
Aug 19, 2026
Category
Tools & Capabilities
GitHub stars
1
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/ChenYiming-aaa/dsh-github
Plugin: dsh-github-chenyimi
Author: ChenYiming-aaa

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-github — DeepSeek Harness 的 GitHub 集成插件

对标 opencode 的 GitHub MCP server:一次配置认证,长期可用。模型在对话中直接调用 github_* 工具完成建仓、推送、提 PR、管 issue、搜索代码等 GitHub 事务,不再每次操作 都要求临时授权

  • 零依赖(只用 Node 22+ 内置 fetch),45 个工具,全部走 GitHub REST API v3
  • 认证持久化:GITHUB_TOKEN(环境变量 / DSH credentials 服务)或 OAuth Device Flow

(浏览器授权一次,token 自动写入 $DSH_HOME/.credentials.yaml,重启 DSH 依然有效)

  • 审批策略:读操作 + 常规写操作直接放行;删除仓库/文件/分支、force push、合并 PR、

关闭 issue/PR 保留审批门

  • 安全:token 只进 Authorization 请求头,绝不落日志;错误信息与工具输出做防御性脱敏

快速开始

1. 安装插件(web + desktop 两个 profile)

powershell -ExecutionPolicy Bypass -File .\install.ps1
# 只装一个 profile:powershell -ExecutionPolicy Bypass -File .\install.ps1 -Profiles desktop

安装脚本会: 1. 把插件包复制到 %USERPROFILE%\.dsh\profiles\node_modules\dsh-github\ 2. 在 webdesktop 两个 profile 的 cordis.patch.yml 追加注册条目(幂等)

重启 DSH Desktop(或重载 web profile)后生效。

2. 配置认证(二选一,均持久生效)

方式 A — Personal Access Token(推荐先试这个)

# 1) 在 GitHub → Settings → Developer settings → Personal access tokens 生成
#    (需要 repo、read:org、user 权限)
# 2a) 环境变量(最简单)
setx GITHUB_TOKEN "ghp_xxx"        # 新开的终端/重启 DSH 后生效
# 2b) 或写入 DSH credentials($DSH_HOME/.credentials.yaml,密码学托管、不落日志)
#     DSH 设置页 → 凭据 → 新增 GITHUB_TOKEN → 粘贴 token

方式 B — OAuth Device Flow(浏览器授权一次)

1. 在 GitHub 创建一个 OAuth App(Settings → Developer settings → OAuth Apps), Authorization callback URL 填任意合法 URL(如 https://github.com) 2. 把 Client ID 填入插件配置(两个 profile 的 cordis.patch.yml):

- insert:
    - id: github
      name: dsh-github
      config:
        tokenRef: GITHUB_TOKEN
        approvalGate: true
        timeoutMs: 30000
        oauthClientId: Ov23liXXXXXXXX
        oauthClientSecretRef: GITHUB_OAUTH_CLIENT_SECRET   # 推荐:凭据引用
        # 或直接内联(不推荐明文):oauthClientSecret: xxxx

3. 设置 Client Secret 凭据:DSH 设置页新增 GITHUB_OAUTH_CLIENT_SECRET (或环境变量 GITHUB_OAUTH_CLIENT_SECRET)。GitHub 的 device flow 换取 token 必须携带 client secret。 4. 重启 DSH,新会话中对模型说「用 github_auth_login 登录 GitHub」, 浏览器打开返回的网址、输入用户码,授权一次即可;token 自动持久化,之后长期可用。

> GitHub device-flow 的 access token 长期有效、没有 refresh token 机制; > 若失效(表现为 401),调用 github_auth_logout 清除后重新登录即可。

3. 验证

新会话中让模型执行:

  • github_get_me —— 应返回当前 GitHub 用户(等价 opencode 的 get_me)
  • github_auth_status —— 认证来源与有效性

常用流程示例

一键上传项目(建仓 → 推送 → 开 PR 全流程,常规操作无审批弹窗):

github_upload_project(repo: "my-app", description: "我的应用",
  files: [{path: "README.md", content: "# my-app"}, {path: "src/main.js", content: "..."}],
  create_pull_request: true)

手把手流程(等价 opencode push 多文件的体验):

1. github_create_repository(name: "my-app", private: true)
2. github_create_branch(owner, repo, branch: "feature/init")
3. github_push_files(owner, repo, branch: "feature/init", message: "init", files: [...])
4. github_create_pull_request(owner, repo, title: "init", head: "feature/init", base: "main")
5. github_merge_pull_request(owner, repo, pull_number: 1, merge_method: "squash")  # 🔒 需审批

工具清单

见 [TOOLS.md](./TOOLS.md)(45 个工具分 9 类,含危险操作清单)。

审批门规则

操作工具/参数审批
删除仓库github_delete_repository🔒
删除文件github_delete_file🔒
删除分支github_delete_branch🔒
force pushgithub_push_files + force: true🔒
合并 PRgithub_merge_pull_request🔒
关闭 issue / 关闭 PRgithub_update_issue / github_update_pull_request + state: closed🔒
其余读/写✅ 直接放行

审批通过 tools/pre-executectx.approval 实现(与 DSH 内置 dsh-user-approval 一致):allowed-once 才放行,拒绝/取消/无审批通道一律 fail closed。 config.approvalGate: false 可关闭审批门(不推荐)。

配置项

配置默认说明
tokenRefGITHUB_TOKENPAT 凭据引用名(env / credentials 键名)
oauthClientIdGitHub OAuth App Client ID(Device Flow)
oauthClientSecretClient Secret(直接内联,不推荐)
oauthClientSecretRefGITHUB_OAUTH_CLIENT_SECRETClient Secret 凭据引用(推荐)
oauthScoperepo,read:org,userDevice Flow 申请的 scope
approvalGatetrue危险操作审批门开关
timeoutMs30000GitHub 请求超时

开发与测试

node tests/run-all.mjs    # 需要本机安装 DSH Desktop(loader 引用其 dsh-tools)

测试覆盖:

  • validate-tools.mjs — 45 个工具经 DSH 真实 dsh-tools 的 schema 编译/校验、render 健壮性
  • validate-apply.mjs — apply() 生命周期 + 审批门行为(危险→ask、常规→放行)
  • approval-gate.mjs — 危险操作分类单测
  • redaction.mjs — 验收:token 不出现在日志/错误/工具输出
  • push-upload.mjs — 内存版 GitHub API 上的多文件推送与一键上传流程(建仓→推送→开 PR)

架构

index.js                插件入口:apply() 注册审批门 + systemPrompt 引导 + 45 个工具
lib/client.js           GitHub REST 客户端(fetch、错误映射、token 脱敏)
lib/auth.js             PAT/credentials 解析 + OAuth Device Flow 状态机
lib/approval.js         危险操作分类 + tools/pre-execute 审批门
lib/push.js             共享推送实现(blob→tree→commit→ref)
lib/format.js           输出渲染 / presentCall 辅助
lib/tools/*.js          分域工具定义(auth/repos/issues/pulls/commits/search/releases/orgs/workflow)

许可

MIT