DeepSeek Harness 插件

skill-bartender

任务到技能配对元技能:懒人阶梯最小化加载、可编辑路由表、隔离-SkillSpector 扫描-人工确认的安装流程。

跳到安装方式

来源信息

GitHub 仓库
akqwpeter-prog/skill-bartender
最近更新
2026年8月18日
分类
Skills 与任务指令
GitHub stars
1

安装

默认先复制一段 Prompt,让 Agent 读页面和仓库;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读页面和仓库。

请先不要安装。阅读这个 DeepSeek Harness 插件,说明它解决什么问题、会访问哪些文件、网络或密钥,以及如何安装和卸载。

插件页面:https://deepseekplugins.org/zh/plugins/akqwpeter-prog/skill-bartender
GitHub:https://github.com/akqwpeter-prog/skill-bartender
插件名:skill-bartender
作者:akqwpeter-prog
安装命令:dsh plugin --profile web add github:akqwpeter-prog/skill-bartender

确认前不要执行安装命令。

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

<div align="center">

<img src="docs/social-preview.png" alt="skill-bartender — task-to-skill pairing for DeepSeek Harness" width="100%">

<br>

🍸 skill-bartender

Mix the right skill cocktail for every task — and never pour an untasted bottle.

![License: MIT](LICENSE) ![SkillSpector CI](https://github.com/akqwpeter-prog/skill-bartender/actions/workflows/scan.yml) ![DeepSeek Harness](https://github.com/topics/dsh-plugin) ![Self-scan](docs/skillspector-report.json) ![Laziness ladder](README.md#-why) ![Platforms](README.md#-quick-start) ![Docs](docs/lang/README_ZH.md)

<br>

Your agent already sees a catalog of skill names and descriptions — but it over-pours: loads too many skills, loads the wrong ones, or misses the one workflow skill that composes the task. skill-bartender is the meta-skill that fixes the pour:

  • 🪜 Laziness ladder — zero skills when plain tools suffice; one skill

when one matches; workflow over hand-composed atomics; unsure → don't load.

  • 🍷 Routing table — a user-editable task→skill map (references/policy.md)

that overrides the defaults.

  • 🔐 Safe cellar — a needed skill missing? Quarantine → SkillSpector scan

→ explicit human approval → install. Never auto-installs.

  • 🧠 Learn — loaded-but-unused skills get logged and skipped next time.
  • 🧪 Taste test — audit installed skills and rewrite weak descriptions

into "when-to-use" sentences.

[Why](#-why) · [What you get](#-what-you-get) · [Quick start](#-quick-start) · [See it in action](#-see-it-in-action) · [Usage](#-usage) · [Security model](#-security-model-read-this) · [FAQ](#-faq) · [Examples](#-examples) · [Layout](#-layout) · [License](#-license)

[English](README.md) · [简体中文](docs/lang/README_ZH.md)

</div>

---

🤔 Why

Most agents treat the skill catalog as an all-you-can-eat buffet. skill-bartender treats it as a bar with a taste test:

skill-bartenderTypical catalog behavior
Skills loaded per taskusually one; zero when plain tools sufficewhatever matches, however many
Workflow skills✅ preferred — never hand-assemble atomics❌ often missed or hand-composed
Unsure about a match❌ don't load (miss beats false pour)⚠️ loads "just in case"
Installing a missing skill🔐 quarantine → scan → human approval⚠️ downloads straight into the skills dir
Auto-install❌ never, by design⚠️ often silent
Learns from unused loads✅ logged, skipped next time❌ no memory

Why the "laziness ladder"? A wrong skill body stays in conversation history forever; a missed load only costs one tool round-trip. The best load is the load never made (spirit: ponytail).

✨ What you get

CapabilityWhat it doesWhere
🪜 Laziness ladderStop at the first rung that holds: 0 no skill → 1 one skill → 2 workflow skill → 3 unsure, don't loadall platforms
🍷 Routing tableTask→skill map in references/policy.md; URL-keyed families (doc/drive/wiki/sheets/base/slides) routed by path patternall platforms
🔐 Safe cellarMissing skill: search → quarantine dir → SkillSpector scan → scripts shown to human (default deny) → explicit yes → install; source + commit hash + verdict recordedDSH, Claude Code, Codex
🧠 LearnUnused loads logged and skipped for the same task type next time; chronic no-shows get offered for removalDSH
🧪 Taste testOn request: list installed skills, rewrite weak descriptions into trigger-phrase form (under the 500-char catalog cap)on request

⚡ Quick start

One file, three platforms:

# DeepSeek Harness
mkdir -p ~/.dsh/skills/skill-bartender
cp skills/skill-bartender/SKILL.md ~/.dsh/skills/skill-bartender/
cp -r skills/skill-bartender/references ~/.dsh/skills/skill-bartender/

# Claude Code
mkdir -p ~/.claude/skills/skill-bartender
cp skills/skill-bartender/SKILL.md ~/.claude/skills/skill-bartender/

# Codex
mkdir -p ~/.codex/skills/skill-bartender
cp skills/skill-bartender/SKILL.md ~/.codex/skills/skill-bartender/

Or install as a DeepSeek Harness bundle:

dsh plugin --profile web add github:akqwpeter-prog/skill-bartender

Then say "skill-bartender" once, or paste the routing table into your AGENTS.md for always-on routing. Full examples: [docs/EXAMPLES.md](docs/EXAMPLES.md).

📸 See it in action

The pour flow in one picture: stop at the first rung that holds, and never install without a taste test.

<img src="docs/screenshots/how-it-works.png" alt="How the pour works: laziness ladder (0 plain tools, 1 one match, 2 workflow, 3 unsure) plus the safe cellar (quarantine → SkillSpector scan → human approval → install)" width="100%">

🚀 Usage

Four ways to use it:

WayHowWhen
A. Say the nameIn any session, just say "skill-bartender"One-off or first-time setup
B. Always-on routingPaste the routing table into AGENTS.mdEvery task routes through the ladder
C. Request a pour"Which skill fits this task?"Choosing among skills
D. Cellar audit"Audit my installed skills"Taste test: weak descriptions get rewritten

skill-bartender must itself be loaded once (user gesture or task match) — it never self-triggers, and never pre-loads "just in case".

🔐 Security model (read this)

  • Skills are instructions, and instructions can be adversarial (prompt

injection). SkillSpector is a filter, not a guarantee.

  • scripts/ in any skill is code — never executed without human review.
  • Human approval is mandatory for every install. No silent installs, ever.
  • This skill scans itself clean: SkillSpector 0 findings (score 0 / SAFE)

— [docs/skillspector-report.json](docs/skillspector-report.json).

  • Security policy: [SECURITY.md](SECURITY.md).

❓ FAQ

Does it auto-install missing skills? No. Every download goes to a quarantine dir, gets scanned with SkillSpector, and is copied into the skills root only after explicit human approval. A passing scan is a filter, not a guarantee — prompt injection survives static scans, so scripts are shown to the human and default-deny.

What if SkillSpector isn't installed? uv tool install git+https://github.com/NVIDIA/skillspector.git, or run the manual checklist in references/policy.md.

Does it work with Claude Code and Codex? Yes — the same SKILL.md installs on all three platforms in ~15 seconds.

How is this different from DshMarket / dsh-find-plugin / dsh-plugin-autoevo? They find, search, and auto-install plugins. skill-bartender adds the routing policy (ladder + routing table) and the quarantine-then-approve discipline. Use it alongside the ecosystem, not instead of it.

How is it evaluated? The routing policy ships with a gold-task suite: [docs/eval.md](docs/eval.md).

🎁 Examples

  • [docs/EXAMPLES.md](docs/EXAMPLES.md) — real routing cases, cellar installs, audits.
  • [docs/ROUTING-GUIDE.md](docs/ROUTING-GUIDE.md) — how to write your own task→skill rules.
  • [docs/eval.md](docs/eval.md) — gold-task suite for the routing policy.

🗺️ Layout

skill-bartender/
├── skills/
│   └── skill-bartender/
│       ├── SKILL.md             # the skill itself (one file, three platforms)
│       └── references/policy.md # user-editable routing table
├── docs/
│   ├── screenshots/how-it-works.png
│   ├── eval.md                  # gold-task suite
│   ├── EXAMPLES.md / ROUTING-GUIDE.md
│   ├── skillspector-report.json # self-scan: 0 findings
│   ├── social-preview.png       # banner (regenerate via scripts/)
│   └── lang/README_ZH.md        # 简体中文
├── scripts/
│   ├── make-banner.py           # composes docs/social-preview.png
│   ├── make-diagram.py          # composes the how-it-works diagram
│   └── validate.py              # local structure validation
├── cordis.patch.yml / index.js / package.json   # DSH bundle manifest
└── LICENSE (MIT)

🤝 Join the DSH plugin ecosystem

DeepSeek Harness developer preview is still in its testing phase for Harness developers; core plugins and base APIs will keep iterating. We look forward to exploring the upper limits of intelligence together with developers worldwide, on top of open-source, open, reusable, and composable infrastructure.

> This repo is tagged dsh-plugin and > listed in the awesome-dsh-plugin > curated list. PRs, issues and translations are welcome.

📄 License

[MIT](LICENSE). Ponytail (MIT) is referenced, not bundled — tribute in the SKILL.md.