Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #dsh-plugin

dsh-jumpserver

通过对话查询与管理 JumpServer:资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色,使用 AccessKeyID/AccessKeySecret(HTTP 签名)鉴权。

we39 @we39 ⬇ 1 ★ 0 main

安装

dsh plugin --profile web add github:we39/dsh-jumpserver
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

通过对话查询与管理 JumpServer:资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色,使用 AccessKeyID/AccessKeySecret(HTTP 签名)鉴权。

该插件未提供要点说明,请参考仓库 README。

dsh-plugin
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/we39/dsh-jumpserver
许可证未标注(见仓库)
主要语言main
下载量1
GitHub 星标0
最近推送2026-09-14
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# dsh-jumpserver

[简体中文](./README.zh-CN.md)

A DeepSeek Harness plugin for querying and managing JumpServer assets through conversation, authenticated with a JumpServer AccessKeyID/AccessKeySecret pair (HTTP Signature).

## Why dsh-jumpserver

- Inspect JumpServer assets, users, accounts, permissions, sessions, command audit logs, user groups, command filters, asset-tree nodes, and RBAC roles/bindings through conversation.
- Manage assets, accounts, users, permissions, user groups, command groups, command filters, asset-tree nodes, and custom RBAC roles/bindings, plus password/MFA/SSH-key resets for users.
- Every write operation triggers a mandatory native user-approval prompt — the model cannot bypass it.
- Secrets, passwords, public keys, MFA secrets, and account passphrases are redacted from read responses before they reach the model.
- Authenticate with JumpServer's native HTTP Signature scheme (`hmac-sha256`); the AccessKeySecret stays in the local DSH credential store.

## Requirements

| Component | Supported baseline |
| --- | --- |
| Node.js | 20.11 or newer |
| DeepSeek Harness | `0.1.2-rc.1` |
| JumpServer | REST API `v1` (Access Key authentication) |

## Installation (for the agent)

For local development, install from the local path:

```bash
npm ci
dsh plugin --profile add link:/absolute/path/to/dsh-jumpserver
```

Once published, install a released, immutable tag whenever possible:

```bash
dsh plugin --profile add github:we39/dsh-jumpserver#v
```

Install the mutable development branch only for testing:

```bash
dsh plugin --profile add github:we39/dsh-jumpserver
```

Restart the selected DSH profile after installation. On Windows, use an absolute `link:C:/path/to/dsh-jumpserver` path.

## Configuration

In DSH Web, open **Settings → Plugins → JumpServer asset lookup**.

Configure:

- **JumpServer URL**: the absolute base URL, for example `https://jumpserver.example.com`.
- **Access Key**: create one from the JumpServer web console under your personal API Key list.
- **Secret Key**: paired with the Access Key above.

The Access Key/Secret Key use DSH's privileged loopback credential RPC — write-only, the stored values are never read back or displayed. The URL is stored in the `jumpserver` settings namespace as a non-secret field, so it is read back in plaintext and shown in the card for verification.

HTTP and HTTPS both work out of the box — internal deployments without TLS certificates can use an `http://` URL with no extra setup. To enforce HTTPS only, disable it in plugin configuration:

```yaml
allowInsecureHttp: false
```

The credential reference names default to `JUMPSERVER_ACCESS_KEY_ID` / `JUMPSERVER_ACCESS_KEY_SECRET` and can be changed with `akRef` / `skRef` in the plugin configuration.

### JumpServer permissions

Create the AccessKey under a JumpServer account that only has read access to the assets you want visible to the assistant. Avoid using a super-admin account's key for this integration.

## Tools

53 tools (12 read-only / 41 write) across 10 domains. All write tools require native user approval.

| Domain | Tools | Scope |
| --- | --- | --- |
| Assets | 5 | assets, details, create/update/delete |
| Users | 7 | users, details, create/update/delete, password/MFA/SSH-key reset |
| Accounts | 5 | asset accounts, details, create/update/delete |
| Permissions | 5 | asset-permission rules, details, create/update/delete |
| Sessions & Audit | 2 | terminal sessions, command audit logs |
| User Groups | 5 | groups, details, create/update/delete |
| Command Groups | 5 | command-pattern groups, details, create/update/delete |
| Command Filters | 5 | security filters, details, create/update/delete |
| Asset Tree | 6 | nodes, details, create/update/delete, move |
| RBAC | 8 | roles, bindings, create/update/delete |

See **[docs/tools.md](docs/tools.md)** for the full per-tool reference (name, method, path, description).

Session termination and ticket approval are intentionally out of scope.

## Security and data boundaries

- The AccessKeySecret never enters tool arguments, model messages, logs, or Git.
- Account secrets/passphrases and user passwords/public keys/MFA secrets are explicitly excluded from every **read** tool's output, field by field.
- Authenticated requests reject HTTP redirects to avoid forwarding signed requests to another origin.
- Non-loopback HTTP is disabled by default (see `allowInsecureHttp`).
- Requests have cooperative cancellation, timeouts, and bounded response sizes.
- Error responses expose only a bounded status/detail description.
- `id` parameters are validated as JumpServer UUIDs before being placed in a request path, preventing path injection.
- All returned fields (names, addresses, comments, usernames, etc.) are treated as untrusted data, not model instructions.

## Development

```bash
npm ci
npm run verify
```

Tests use Node's built-in test runner and mocked JumpServer responses.

## Structure

- `index.js` — generic execution engine + full endpoint catalog + write-approval gateway
- `client.js` — settings-page form card (slot key `jumpserver`)
- `cordis.patch.yml` — bundle patch (insert id `jumpserver` / name `dsh-jumpserver`)
- `docs/tools.md` — full tool reference
- `test/index.test.js` — `node:test` unit tests

## License

MIT

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。