Plugin directory / Developer / qqbot-clawbot
qqbot-clawbot
Verified · install-tested on dsh twinsant
What it does
QQ bot bridge plugin for DeepSeek Harness (QQ Open Platform WebSocket gateway)
Works — verified, early-stage project
QQ bot bridge plugin for DeepSeek Harness (QQ Open Platform WebSocket gateway) It installs cleanly and boots without issues in our testing. It's early-stage but functional.
“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
QQ Bot Bridge
A persistent https://github.com/deepseek-ai/deepseek-harness host plugin that connects a QQ Open Platform robot (AppID + AppSecret) and bridges its messages into a per-day session of a chosen workspace.Features
- **Binding** — Settings → QQ Bot in the web UI (AppID + AppSecret with an eye toggle); the host half starts the WebSocket gateway on change. - **Bidirectional bridge** — forwards inbound text / voice transcription / images into aqqbot-YYYY-MM-DD session and sends the agent's reply back to QQ.
- **Persistence** — AppID / Secret / workspace / sender allowlist in $DSH_HOME/qqbot-clawbot/state.json (mode 600); reconnects on restart.
- **Sender allowlist (TOFU)** — the first sender after binding is trusted; others are dropped.
- **C2C only by default** — TOFU assumes the first sender is the owner, which is unsafe in groups. Group / guild / dm messages are dropped unless QQBOT_ALLOW_GROUP=true (still TOFU-gated).
- **Media hardening** — image download restricted to Tencent CDN hosts, capped at 20 MB. Images attach inline only when the target model supports vision.
- **Human-in-the-loop (HITL) approval** — escalating a sandboxed action prompts ⚠️ 需要审批 … 回复「允许」或「拒绝」 in QQ with the tool's arguments; the tool blocks until you reply. C2C chats only — group-triggered approvals fall through to the web UI.
Tools
| Tool | Purpose | | --- | --- | |qqbot_list_workspaces | list candidate workspaces |
| qqbot_status() | query binding/connection status |
| qqbot_unbind() | unbind and disconnect |
Binding is done from the web UI: Settings → QQ Bot (AppID / AppSecret / workspace), stored in the qqbot settings namespace; the host half auto-connects on change.
Install
This package builds inside a https://github.com/deepseek-ai/deepseek-harness workspace checkout. 1. Place (or symlink) this directory atpackages/qqbot/qqbot-clawbot in the harness repo, then run pnpm install at the repo root.
2. Build the two halves:
``sh
node_modules/.bin/tsc -b packages/qqbot/qqbot-clawbot/tsconfig.client.json
cd packages/qqbot/qqbot-clawbot && ../../../node_modules/.bin/tsdown --env.DSH_BUILD_FACE client
`
3. Create a robot at https://q.qq.com/ and copy its AppID + AppSecret.
4. Register the plugin by package name in ~/.dsh/profiles/web/cordis.patch.yml:
`yaml
- insert:
- id: qqbot-clawbot
name: '@deepseek-ai/dsh-qqbot-clawbot'
`
5. Restart dsh web`, open Settings → QQ Bot, and enter the AppID + AppSecret (eye toggle reveals the secret).
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install qqbot-clawbot for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:twinsant/qqbot-clawbot Headless (CLI) profile:
dsh plugin --profile headless add github:twinsant/qqbot-clawbot Test report
Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.
When to use it
Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.
Who it's for
Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.
For developers — extending it
The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.