Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心

augmentor-dsh-extension-plugin

Augmentor for DeepSeek Harness:DSH 插件与 Chrome 扩展,可从任意 DSH 会话操作用户真实浏览器并保存聊天会话。

manoloremiddi @manoloremiddi ⬇ 1 ★ 1 master

安装

dsh plugin --profile web add github:manoloremiddi/augmentor-dsh-extension-plugin
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

Augmentor for DeepSeek Harness:DSH 插件与 Chrome 扩展,可从任意 DSH 会话操作用户真实浏览器并保存聊天会话。

该插件未提供要点说明,请参考仓库 README。

  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/manoloremiddi/augmentor-dsh-extension-plugin
许可证MIT
主要语言master
下载量1
GitHub 星标1
最近推送2026-08-28
收录日期2026-09-19
分类工具与能力

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# Augmentor, powered by DSH

**Augmentor** turns any DeepSeek Harness (DSH) web session into a browser
operator: a Chrome side panel chats with your DSH app, and the agent drives
your *real* browser — live accessibility snapshot, click, type, tab switching —
with the user watching every action pulse on the actual page. Chats are real
DSH sessions in a dedicated directory, and **Save** attaches the current chat
to a DSH workspace.

```
┌─ Chromium (MV3 extension) ─────────────────┐   ┌─ Your machine ─────────────────────────────────────────────┐
│ side panel: chat UI (real DSH sessions)    │   │ pipe.mjs — native messaging host (Node, loopback)          │
│ sw.js: native port + browser executor +    │   │  ├─[POST /api/]──────────────▶ running DSH app      │
│  work-tab injection (page veil, overlays)  │   │  ├─[WS /api/events.mux|host]◀───────── downlink frames      │
└──────────────┬─────────────────────────────┘   │  └─[WS ]──────▶ dsh-augmentor plugin│
               │ native messaging (token-gated)  │        /api handshake + pipe channel + browser tools +     │
               └────────────────────────────────▶│        chat lifecycle (save-to-workspace)                 │
                                                 └────────────────────────────────────────────────────────────┘
```

No sidecar runtime, no second DSH process: the extension talks to the **running**
DSH app over its stock `/api` surface (the pipe is the browser's loopback
stand-in client, because the extension's Origin is refused by the DSH trust
fence — by design).

## Components

| path | what it is |
| --- | --- |
| `extension/` | MV3 Chrome extension: side panel chat, service worker (native port + browser executor), page veil, work-tab overlays, theme tokens |
| `pipe.mjs` | native messaging host: loopback bridge to the DSH app's `/api` surface, downlinks, plugin channel |
| `plugin/` | the `dsh-augmentor` DSH plugin (npm package + git bundle): `/api/augmentor` handshake, pipe WS channel, `browser_*` tools, chat lifecycle |
| `wire.mjs` | the shared wire primitives (frame codec + pending table) used by all three runtimes — one implementation, three consumers |
| `install-native-host.sh` | installs the Chromium native-messaging-host manifest + the per-machine channel token |
| `test/` | e2e suites (m3, sw, panel, chrome, m2, tools) + `install-proof.mjs` (deterministic fresh-user install proof) + `plugin/tests/boot/` |
| `PROPOSAL-plugin-architecture.md` | the architecture record: milestones M1–M4, audit findings S/D/F, decisions |

## Install

Prereqs: Node.js (v22.19+ or v24+), a running `dsh web` instance, a
Chromium-based browser (Chrome/Chromium/Edge; Firefox & Safari are "coming
soon" — the native-messaging + content-injection stack is Chromium-specific
today).

1. **Clone**

   ```sh
   git clone https://github.com/ManoloRemiddi/augmentor-dsh-extension-plugin.git
   ```

2. **Load the extension** — `chrome://extensions` → *Developer mode* →
   *Load unpacked* → pick the `extension/` directory. Note the extension ID.

3. **Install the native host**

   ```sh
   ./install-native-host.sh
   ```

   Writes the NMH manifest (points at `pipe.mjs`), creates the per-machine
   action-channel token (`~/.dsh/augmentor-ws-token`, 0600) if missing, and
   installs the repo's Node dependencies (root + `plugin/`) if missing.

4. **Mount the plugin into your DSH profile**

   ```sh
   dsh plugin --profile web add /plugin
   ```

   (or from npm: `dsh plugin --profile web add dsh-augmentor`.)
   Restart the `dsh web` session so the profile composes the plugin layer.

   > **pnpm users — first 24h after a release:** `dsh plugin` forwards to
   > pnpm, and pnpm ≥ 11 enforces a ~24h *minimum release age* (supply-chain
   > protection) — silently installing the newest version that passes. Right
   > after a publish, the bare name can therefore resolve to the **previous**
   > release. `npm view dsh-augmentor version` shows the newest; to get it
   > immediately, pin it: `dsh plugin --profile web add dsh-augmentor@`.
   > The bare name self-heals once the release is a day old.

5. **Reload the extension** (it reconnects the native port; a brief SW
   reconnect blip is normal). Open a side panel session, type a prompt, and
   the agent can now see and drive the active work tab.

## Security posture

- **The DSH trust fence is why the pipe exists — it is not bypassed.** The
  DSH app's `/api` refuses requests from foreign browser origins (the
  extension's `chrome-extension://` origin included, by design). `pipe.mjs`
  is a loopback stand-in client: it runs locally as the user and talks to
  the app over `127.0.0.1`, which is exactly what the fence permits.
- **No new remote surface.** Every hop is loopback (extension ↔ pipe via
  native messaging, pipe ↔ app via `127.0.0.1`); nothing this stack adds is
  reachable from other hosts. The trust boundary is the local OS user:
  anything that can already read your home directory is not blocked by this
  stack (and could already do the same things directly against the app).
- **The action channel is secret-gated.** The `browser_*` commands flow over
  a WS channel the plugin authenticates with a per-machine token
  (`$DSH_HOME/augmentor-ws-token`, 0600, created by the installer or first
  boot; a configured `actionToken` wins). The pipe presents it in the WS
  handshake header and the plugin compares it in constant time; a local
  process without that file cannot drive your browser.
- **The in-panel "Trust-fence probe"** (≣ Sessions → *Probe*) is a diagnostic
  that shows the fence working as designed (extension-origin requests
  refused, loopback requests accepted). It probes; it does not bypass.

## Development

```sh
# full e2e battery (six suites) — run from the repo root:
cd test && node m3-e2e.mjs && node sw-e2e.mjs && node panel-e2e.mjs \
  && node chrome-e2e.mjs && node m2-e2e.mjs && node tools-e2e.mjs

# plugin boot test:
sh plugin/tests/boot/run.sh
```

The suites are hermetic: each creates its own marker session (and archives it
on cleanup), never touches user sessions, and the live-browser suites (m3,
chrome, m2) run against the real local DSH app + a real Chrome profile.

# deterministic install proof — the documented journey, end to end, on a fresh
# DSH home + fresh Chromium profile (never touches your real ~/.dsh):
node test/install-proof.mjs                 # clone → boot → plugin → ext → NMH → pipes:1
PROOF_LLM=1 node test/install-proof.mjs     # + a real agent drives the headless browser
PROOF_SOURCE=npm PROOF_LLM=1 node test/install-proof.mjs   # npm plugin path (once published)
# knobs: PROOF_REPO, CHROME_BIN, PROOF_PORT, PROOF_KEEP=1 — see the script header.

## License

MIT.

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。