插件目录 / Developer / dsh-tool-git
dsh-tool-git
已验证 · 实测可装 lxj808624
功能简介
dsh-tool-git — DSH 插件(工具)
可用 — 实测通过,早期项目
dsh-tool-git — DSH 插件(工具) 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-tool-git
Structured, safe Git tool family for DeepSeek Harness (dsh).
Coding agents reach for git constantly, but the stock runtime only offers raw bash.dsh-tool-git gives the model eight structured tools that run git through a
shell-free subprocess runner and return canonical JSON values — plus atools/pre-execute safety gate that stops destructive git operations
(force push, hard reset, rebase, amend, branch deletion, …) before they happen,
whether the model calls them through these tools or through a shell tool.
- No shell injection: every command goes through
execFilewith an explicit
argument array. Model-supplied paths and messages are never string-interpolated. - Machine output: porcelain v2,
--numstat, and--formatrecords are parsed
into structured JSON, not prose. - Safety by default: destructive operations are denied with an explanation
unless you opt intoask(approval prompt) orallow.
Tools
| Tool | What it does |
|---|---|
git_status |
Working tree state: branch, ahead/behind, staged / unstaged / untracked files |
git_diff |
Per-file insertion/deletion stats, optional unified patch, --cached / rev bases |
git_log |
Commit history: hash, author, date, subject, body; maxCount, rev range, path filter |
git_branch |
Branches with upstream and ahead/behind tracking state |
git_stage |
Stage explicit paths, or all / tracked-only changes |
git_commit |
Create a commit with a message; returns hash and statistics |
git_stash |
list / push / pop stashes, with conflict-safe pop |
git_show |
One commit: metadata, per-file stats, optional patch |
git_fetch |
Download refs from a remote without touching the worktree |
git_pull |
Fast-forward-only by default; reports not-fast-forward / conflict outcomes |
git_remote |
List configured remotes with fetch/push URLs |
git_checkout |
Switch branches, or create and switch (-b); never discards changes |
Every tool accepts an optional repoDir argument and reports the resolved
repository root in its result.
Safety gate
The gate listens on tools/pre-execute and inspects every tool call:
The plugin's own tools — e.g.
git_commitwithamend: true.Shell tools —
bash,tool:bash,bash_persistent,terminal,tool:terminal,pwsh— scanning their command text for destructive git
invocations such as:push --force/--force-with-lease·push --delete·reset --hard·clean -f·branch -d/-D·tag -d·rebase·pull --rebase·commit --amend·checkout --/checkout ./checkout -f·switch -f·restore(discarding worktree) ·rm -r·update-ref -d·filter-branchPattern matching is per-command: it never crosses
|,;, or newline
boundaries, sogit add . && git push --forceis still caught but innocent
compound commands are not misread.
This is a policy guardrail, not a sandbox. An agent that can run arbitrary
code can always route around a string matcher (aliases, -c rewrites,
scripting). The gate exists to make accidental destructive calls fail loudly
with an explanation — deliberate destructive work is authorized through the
configured policy, not by bypassing the gate.
Install
npm (recommended) — from any directory:
dsh plugin --profile web add dsh-tool-git
From GitHub (or a local checkout / tarball):
dsh plugin --profile web add github:lxj808624/dsh-tool-git#v0.1.3
Then restart dsh --profile web. For GitHub installs, pnpm asks you to
allowlist the prepare build script once (see the
official packaging guide).
Configuration
All options are optional; the defaults are shown below:
# profile-level or bundle patch config for the tool-git row
- id: tool-git
name: dsh-tool-git
config:
workDir: '' # repo discovery start dir (default: process cwd)
gitPath: git # git executable
destructivePolicy: deny # deny | ask | allow
extraDestructivePatterns: [] # extra case-insensitive regexes for the gate
logMaxCommits: 20 # git_log default count (cap 100)
diffContextLines: 3 # patch context lines for git_diff / git_show
deny(default) — destructive calls are rejected with the pattern name and
an explanation.ask— destructive calls go through the runtime's approval seam
(ctx.approval); without a mounted approval service they degrade todeny.allow— the gate passes everything through.
Development
Prerequisites: Node.js ≥ 22.19 and pnpm. The project is self-contained — all@deepseek-ai/* types resolve from the published public API (0.0.1-rc.5 line)
installed as devDependencies, so no deepseek-harness checkout is required.
pnpm install
pnpm run typecheck # tsc against the public @deepseek-ai/* API
pnpm test # vitest: boots the plugin, runs real git in temp repos
pnpm run build # tsc declarations + tsdown bundle (lib/index.mjs)
The tests create a disposable repository, register the plugin on a Cordis
context with the real dsh-tools runtime, and execute every tool through the
full pipeline (tools/pre-execute → dispatch → tools/result).
Publish
dsh.bundle.patchinpackage.jsonpoints atcordis.patch.yml, sodsh plugin addactivates the plugin as a profile layer.preparerunstsdown --config tsdown.prepare.config.ts, which transpilessrc/without project references — so GitHub installs build cleanly without
a sibling harness checkout. Prefer publishing prebuilt tarballs / npm
packages to avoid pnpm's build-script allowlist.
License
Contributors
- taonokenshin — found and fixed the
dsh-toolspeer-resolution issue that crashed the host tool dispatcher on
DeepSeek Harness 0.1.0-rc.6 (#1, #2).
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-tool-git」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
Web profile:
dsh plugin --profile web add dsh-tool-git Headless(CLI)profile:
dsh plugin --profile headless add dsh-tool-git 包信息
npm:dsh-tool-git · 版本 — · 实测环境 dsh 0.1.0-rc.6
实测报告
端到端验证通过:dsh 0.1.0-rc.6 上 L1 安装 + L2 加载 + L3 运行问答。
使用场景
扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。
适合谁
想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。
二次开发建议
工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。