dshbase

插件目录 / Developer / upstream-radar

upstream-radar

已验证 · 实测可装 MicroMilo

✓ 持续维护 2 位贡献者 纯 TypeScript

查看 GitHub ↗ ← 返回插件目录

12Stars
1Forks
7未关闭 issue
TypeScript语言
2026-09-18最近推送
跨平台平台

功能简介

插件漏洞和破坏性变更影响监控

✅
我们的评价
可用 — 实测通过,早期项目

插件漏洞和破坏性变更影响监控 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

Upstream Radar

Always-on compatibility testing for DeepSeek Harness plugins—across headless, Web, and TUI.

简体中文 · CI npm GitHub stars Apache-2.0

Upstream Radar binds exact plugin bytes to an exact DSH host and runtime, lets an
Agent derive a bounded environment from repository instructions and prior
evidence, then proves the relationship in disposable GitHub VMs. It runs again
when the ecosystem changes or evidence expires, so it tests the current
version—not only the diff.

It is built for the DeepSeek Harness (DSH)
plugin ecosystem. A static review is evidence about a package; an isolated
runtime review is evidence about one exact plugin × DSH × Node/profile pair.
Neither is presented as a timeless compatibility badge or a security certificate.

Listed by the DSH ecosystem in
awesome-dsh-plugin,
awesome-deepseek-harness, and
awesome-deepseek-harness-plugins.

The problem

A source repository can be green while the package users install is not ready
for the current DSH host:

  • the README advertises a version that was never published;
  • a plugin imports a newer DSH package than its peer range allows;
  • package.json and the lockfile describe different releases;
  • an install-time build or dependency script needs tools the user does not have;
  • a DSH host dependency is missing, so the dependency graph cannot be completed.

These are ecosystem relationship problems. They are easy to miss when the two
repositories are checked separately.

What Radar does

  1. Build one exact compatibility record (IR). Align the npm artifact,
    source commit, DSH host, runtime/profile, dependency paths, and advisories.
  2. Derive the environment. An Agent reads declared installation guidance
    and failed evidence, then emits only a bounded install plan.
  3. Prove each execution plane. Fresh, secret-free runners exercise headless
    load, Chromium Web boot, or a real PTY TUI interaction.
  4. Keep the result alive. DSH/plugin/dependency changes and evidence expiry
    trigger retests; confirmed failures become fixable reports and clean retests
    close the loop.
flowchart TB
  Trigger["Schedule / upstream change / evidence expiry"] --> IR["Exact IR: plugin bytes ↔ DSH ↔ runtime ↔ dependencies"]
  IR --> Agent["Agent derives a bounded install plan"]
  Agent --> VM{"Fresh secret-free GitHub VM"}
  VM --> Headless["Headless: install → register → load"]
  VM --> Web["Web: Chromium → boot handoff → client bundle"]
  VM --> TUI["TUI: PTY → frame → input → declared shutdown"]
  Headless --> Ledger["Versioned evidence ledger + reverse impact index"]
  Web --> Ledger
  TUI --> Ledger
  Ledger --> Decision{"Plugin-attributable failure?"}
  Decision -->|"yes"| Issue["Produce one fixable maintainer report"]
  Decision -->|"no / detector gap"| Hold["Hold the report and calibrate"]
  Issue -->|"author ships a fix"| Trigger
  Hold --> Trigger

The Agent may choose declared build packages, profile setup, and the next bounded
retry. Exact fingerprints decide which cell a report can satisfy, and the
disposable runner—not the model—establishes the result. Missing evidence can
never become a pass.

Try a real check

No local DSH profile is needed for this first check. It reviews one exact
published artifact without executing plugin code:

npx --yes [email protected] inspect \
  @sanqi-normal/[email protected] \
  --deep --fail-on never

This historical DSH plugin release returns review / incomplete because its
published host dependency chain reaches an unavailable package. That is a
useful, reproducible release/host-contract report—not a claim of malicious
behavior. See the full evidence report.

To review your own public repository without installing it:

npx --yes [email protected] scan \
  https://github.com/owner/dsh-plugin \
  --fail-on never

The repository scan reads source manifests, DSH metadata, and lockfiles. It does
not install dependencies, run lifecycle scripts, load the plugin, start DSH, or
call an LLM.

Run it on every change

Copy one of the maintained workflows into your repository:

The isolated headless and
Web/TUI observers use fresh
GitHub-hosted runners. They are not your workstation and receive no project or
model secrets.

Evidence from the ecosystem

The current 100-plugin compatibility feed
records 87 observed compatible, 9 needs review, 0 reproduced incompatible,
and 4 not observed
. Its execution-plane ledger contains 22 exact Web/TUI
cells; all 22 now pass in isolated GitHub VMs.

The nine review cells are not hidden failures. Seven have a green Web proof but
retain separate headless host/peer-contract evidence; two retain known old DSH
host-package ranges tracked by existing maintainer issues. Radar keeps those
facts visible without calling a working browser plugin broken.

The first non-headless cells now run in GitHub-hosted VMs:

Exact cell Observed proof Result
[email protected] × DSH 0.1.1-rc.2 × Web HTTP 200, DSH boot handoff, declared client bundle fetched, no browser/page errors Compatible
@deepseek-harness-tui/[email protected] × DSH 0.1.1-rc.2 × TUI Real PTY frame, keyboard input, documented double-Ctrl-C exit, code 0 Compatible
@linxin666/[email protected] × DSH 0.1.1-rc.2 × Web Agent-approved four dependency builds; aggregate client bundle returned 200; boot manifest, app mount, and plugin materialization matched Compatible
[email protected] × DSH 0.1.1-rc.2 × Web VM observed a node-pty build gate; DeepSeek approved only that exact dependency; the secret-free retry passed install, host, browser interaction, and shutdown Compatible

The better-sidebar run demonstrates the closed loop: dynamic evidence found a
build requirement absent from the headless plan; DeepSeek checked the exact
manifest, README, and VM log; a fingerprint-bound policy approved only
node-pty; then a separate runner with no model secrets established the pass.
This was Radar's environment gap, so no plugin issue was filed. Earlier TUI and
Web detector mistakes were handled the same way: held, corrected, and rerun
instead of being sent to authors.

As of 2026-08-25, Radar has filed 13 maintainer-facing reports. The outcome is
more useful than the raw count:

Outcome Reports
Fix shipped and rechecked (5) Sanqi #5 (0.5.5), HDC #3 (0.7.3), Voice #2 (0.2.6), Msg Hub #1, Toolbox Web #1
Boundary reviewed or documented (3) Msg Hub #3, Spotlight #5 / PR #7, WSL Workspace #6 — closed without claiming a runtime fix
Still open (5) Anan #1, Verification Receipt #3, dshscan #1, OAuth #14, Composer Expand #1

“Closed” is not automatically “fixed.” The full domain report index
records the evidence, validation level, PR coverage, and remaining boundary for
every report.

If Upstream Radar helps the DSH ecosystem stay compatible, please give it a Star ⭐

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 upstream-radar」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:MicroMilo/upstream-radar

Headless(CLI)profile:

dsh plugin --profile headless add github:MicroMilo/upstream-radar

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →