插件目录 / Network / dsh-kimi-bridge
dsh-kimi-bridge
已验证 · 实测可装 pandashere
功能简介
dsh-kimi-bridge — DSH 插件(桥接)
可用 — 实测通过,早期项目
dsh-kimi-bridge — DSH 插件(桥接) 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-kimi-bridge
English | 中文
A dual-face (host + browser) plugin for DeepSeek Harness (dsh) that bridges the
Kimi CLI (kimi-code) into the harness — the Kimi counterpart ofdsh-codex-bridge, built on the same architecture.
Why
A dsh agent often wants a second opinion or a parallel coding pass from an
external coding agent (Moonshot Kimi). Doing that by hand — spawningkimi -p, capturing the stream, polling, wiring the output back — is exactly
the kind of scaffolding a harness plugin exists to remove. This plugin makes
Kimi a first-class dsh citizen:
- Calls Kimi as a tool —
call_kimirunskimi -p <prompt> --output-format stream-jsonin the session's working
directory, withasync(returns immediately; multiple calls run in
parallel) andblock(waits for the final answer) modes, pluskimi_statusto poll andkimi_abortto cancel. - Continues the same session —
kimi_steerresumes a settled Kimi
session with a new message (kimi -S <session_id> -p …). Kimi sessions are
bound to their working directory — the plugin locks cwd to the session
working directory, so resume inside one dsh session holds. The session is
linear: the parent must be the latest record, and one session can have only
one active continuation. - Shows the whole agent loop — the Kimi tab in the conversation pane
(on par with Chat, Trajectory, and Codex) observes each session live:
status, prompt, an Agent Loop waterfall (messages, tool rows with
arguments, collapsible tool output, turn separators), the transcript, and
the final answer — pushed through the session projection channel.
Design stance: this is a UX channel, not a security boundary — andkimi -p runs with permission:"auto" internally, so there is no CLI sandbox
flag. The default reviewOnly mode therefore runs Kimi under a managed home
whose [tools] allowlist is read-only (Read/ReadMediaFile/Grep/Glob;
no Bash/Write/Edit/MCP), enforced again before tool execution. SettingreviewOnly: false opts into the user's unrestricted home — an explicit
operator choice, never called a sandbox. allowedAgents, maxParallel, andmaxSessionsPerSession bound resource amplification, and a finitedefaultTimeoutMs bounds Kimi's print mode (which can otherwise wait ~25 days
on background work).
Installation
Requirements: Node.js 22 or newer, @deepseek-ai/[email protected], and an
authenticated Kimi CLI available as kimi (or set kimiPath). The plugin
does not copy credentials into the repository or dsh telemetry. InreviewOnly mode, the managed Kimi home symlinks the CLI's existing auth files
so the CLI remains the credential owner.
Build, validate, and pack the standalone bundle from the plugin directory:
npm install
npm run check
npm pack
Install the generated tarball into a DSH profile, then restart dsh web.
Installing the source directory as a link is not supported because host peers
are supplied by the DSH profile:
npx @deepseek-ai/[email protected] plugin --profile web add ./dsh-kimi-bridge-0.1.0.tgz
npx @deepseek-ai/[email protected] web
The browser half is served at /plugins/dsh-kimi-bridge/client.js and appears
in the conversation pane. Verify it against a running default Web profile:
curl -s http://127.0.0.1:3080/plugins/dsh-kimi-bridge/client.js | head
To update, build a tarball with a newer package version, remove the installed
bundle, add the new tarball, and restart. To uninstall:
npx @deepseek-ai/[email protected] plugin --profile web remove dsh-kimi-bridge
Config
| Key | Default | Meaning |
|---|---|---|
kimiPath |
kimi |
kimi executable (absolute path or PATH lookup) |
reviewOnly |
true |
run kimi under a managed home whose [tools] allowlist is read-only |
kimiHome |
'' |
source Kimi home for config/auth ('' = KIMI_CODE_HOME, else ~/.kimi-code) |
reviewHomeDir |
'' |
managed review home ('' = $DSH_HOME/kimi-review-home) |
maxTimeoutMs |
1800000 |
hard cap on any session timeout (30 min) |
defaultTimeoutMs |
600000 |
default lifetime per kimi session (10 min) |
maxParallel |
3 |
global cap on concurrent kimi processes |
maxSessionsPerSession |
8 |
cap on live kimi sessions per dsh session |
maxRetained |
16 |
retained (settled) records per dsh session (oldest evicted) |
maxPromptChars |
16384 |
prompt length cap (argv prompt; NUL rejected; longer prompts are rejected) |
maxTranscriptChars |
16384 |
transcript cap recorded in events/projections |
maxLoopSteps |
32 |
bounded agent-loop window (steps kept in the record/projection) |
maxLoopBytes |
16384 |
serialized-byte cap for the loop window (UTF-8; oldest completed steps evicted) |
allowedAgents |
roots |
who may call call_kimi: roots | all |
killGraceMs |
10000 |
SIGTERM → SIGKILL grace (kimi headless cleanup takes up to 8s) |
Tools
call_kimi—{ prompt, mode?: async|block, model?, timeout_ms?, kimi_session_id? }.asyncstarts and returns immediately (parallel);blockwaits for the answer (or, withkimi_session_id, waits on a
previously started session). A cancelled blocking wait aborts the kimi
session.kimi_status— list the current session's kimi sessions (status, prompt
preview, progress).kimi_abort—{ kimi_session_id }; SIGTERM the process group, then
SIGKILL afterkillGraceMs.kimi_steer—{ kimi_session_id, prompt, mode?: async|block, model?, timeout_ms? }. Continue a settled parent session (kimi -S <session_id> -p …; must run from the same directory, which the plugin guarantees); the
new record links back viaparentand inherits the parent's model. A
post-restart parent works as long as its record carries the kimi session id.
Model Experience
The Kimi tab (conversation pane, after Codex):
- Left column — every kimi session of the current dsh session, with status
dot, prompt preview, and relative time. Click to select. - Right column — status badge, meta (id/kimiId/cwd/model/duration/exit/
error), the prompt, and an Activity | Text toggle:- Activity — the Agent Loop waterfall: messages, tool rows (tool name,
running/done/failed, duration, exit code,truncatedmarker; output
auto-expands on failure), turn separators, and a "N steps dropped" marker
when the bounded window evicted older steps. - Text — the streamed transcript and the final answer.
- Activity — the Agent Loop waterfall: messages, tool rows (tool name,
State changes ride the session projection channel (kimi/session events,kimi/sessions projection), so the tab updates live and survives page refresh
(history replay).
Known Limitations and Deferred Work
- One shot per call, then continuation.
call_kimiruns a freshkimi -p; live mid-run steering is not available in the CLI (kimi-code's
thinking is not written tostream-jsoneither, so the tab never guesses
reasoning from stderr). - The loop window is recent-activity, not an audit trail. Older steps are
physically evicted undermaxLoopSteps/maxLoopBytes; the canonical dsh
session log still holds the whole-value snapshots, but the tab only shows
the retained window. reviewOnlyis a tool allowlist, not a sandbox. It is enforced by the
kimi[tools]switch before execution; a genuinely sandboxedworkspace-writeneeds OS-level isolation (container/namespace).- POSIX-only process groups. Abort uses
detached+ negative-pidkill;
a Windows port needs Job Object /taskkill /Ttree termination. - Telemetry redaction covers dsh exports only. Kimi's own telemetry is
disabled viaKIMI_DISABLE_TELEMETRY=1on the child.
Development
npm run check # typecheck + tests + compliance
npm run build # host (tsc) + client bundle (esbuild, __ModuleLoader__ ABI)
The client bundle speaks the harness __ModuleLoader__.load({id, factory})
protocol with the platform module table as externals; the host half follows
the bundle format from create-dsh-plugin.
License
MIT
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-kimi-bridge」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:pandashere/dsh-kimi-bridge Headless(CLI)profile:
dsh plugin --profile headless add github:pandashere/dsh-kimi-bridge 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
给 agent 网络能力——请求、API、代理或协议——让它能触达外部系统。
适合谁
任务涉及网络的人——调 API、抓资源或与远端服务通信。
二次开发建议
适配器和请求整形是缝——加协议、鉴权处理器、重试和端点抽象。