Skip to content

Latest commit

 

History

132 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Hi, I'm PerryLink 👋

GitHub stars GitHub followers GitHub repos OpenSSF Scorecard Glama npm packages npm downloads 30d
MCP Registry awesome-dsh-plugin Listed on DSH Directory DSH Market Gitee mirror
dshfind dshfind downloads across the family DSH Desktop Market source Certified dsh-auto-review plugins

Building the DeepSeek Harness plugin ecosystem: 42 open-source plugins in a 48-repo family, 47 of them PerryLink-owned — security, workflows, research, messaging bridges, developer experience — plus the DSH Desktop Market catalog, a plugin-certification registry and the dsh-plugin-doctor CI checker. All 42 ship CI and a Gitee mirror, five-language docs held to the same section count, install command and configuration keys by a gate in each repo's own CI, and the dsh.bundle contract; 158,593 npm downloads over the trailing 30 days. I also contribute upstream to Cordis — the plugin-core framework DeepSeek Harness is built on — and to deepseek-ai projects, including a merged FlashMLA fix.

DeepSeek Harness turned "everything is a plugin" into an ecosystem. I build the plugins I wish existed — engineering-discipline guardrails, runtime panels, cross-session memory, and verifiable research engines — and publish them the way production software deserves.

Outside the family: 43 external repositories carry a merged pull request of mine together with a commit attributed to this account, and 20 of them are above a thousand stars — Tencent's teamai-cli, DeepSeek's FlashMLA, cordiverse's Cordis, the ACP repositories Zed and JetBrains jointly govern, ruvnet's ruflo, and the DSH catalogs — part of the 348 merged pull requests this account has outside PerryLink/*. The measurements behind the family's own judgment layer are published as a paper with a DOI: When a Judgment Layer's Self-Reported Fields Lie, a three-layer measurement (Laya, TypeSafe Jev, DeepSeek-V4.1-Flash) run on laya-mcp and jevcore, with a Chinese translation and the artifact archived separately.


📣 Latest — 2026-10-05

  • The attribution test this section runs on was replaced, because both cheaper probes fail in the direction that flatters the page. /contributors is a computed list capped at 100 entries and it returns no entry for yibie/awesome-jev, whose default branch carries one of this account's commits — the 09-25 round read that false negative into the text as an uncredited merge and printed the row anyway, so it said both things at once — and /commits?author=<login> returns an empty array for pan17/dsh-wechat, whose default branch holds three commits authored by this account. The rule now runs on the probe it actually names, defaultBranchRef.target.history with author:{id}, which reads real history: 43 external repositories carry a commit of ours, 317 merges sit inside them, two further repositories took 33 of ours with no commit credited, and 20 rows clear a thousand stars. The single repository the old probe denied and the new one confirms is yibie/awesome-jev (2,124★).

  • The ten days since the 09-25 measurement moved the merged count by 27, and 21 of them are one repository. Six of the rest landed one apiece in six repositories that were not part of this set at all before — ruvnet/ruflo, walkinglabs/learn-harness-engineering, koishijs/koishi-plugin-booru, 2768651338/dsh-plugin-manager, losebird/dsh-plugin-market and omdsh-dev/dsh-annotation — which is what puts the largest row in the table, ruflo at 73,842★, in a set it was not part of on 09-25. The 21 are laya, where all 45 of this account's merged pull requests landed inside a nine-day run and the maintainer merges in batches rather than one at a time: seven at 19:29:05 on 09-27 with #556 a second before them, and eight at 17:40:36 on 09-29.

  • Three of the previous round's own claims did not survive the re-read. The account is second among laya's merged-PR authors, not third: 45 sits between aashish254's 126 and Bruce-Yii's 27, so "third, behind 126 and 27" was arithmetically impossible. The repository is not empty of pending work — #924 and #925 went up on 10-04, and #924 merged at 17:50:19Z the same day, leaving #925 as the only open proposal there. And of the two closures only #370 was this account's own; #416 was closed by the maintainer in favour of another contributor's #461. Outside PerryLink/* the open proposals number 95 across 57 repositories, and the wider deepseek-ai org now carries 16 open proposals from this account against its systems repositories, with FlashMLA #224 still the only one merged in that org.

2026-10-04 round

  • The page said 36 external repositories carried my work; the same probe, run under the same rule, now returns 43 — and laya has no open pull requests at all. Every external repository this account ever opened a pull request against (106 of them) was probed again with /contributors: 43 carry a commit attributed to this account, 20 of them above a thousand stars, and the merged count outside PerryLink/* is 348, up from 321. Five of the thousand-star rows are new since the last measurement — ruvnet/ruflo (73,833★), walkinglabs/learn-harness-engineering (18,892★), dsh-market/dsh-market (5,490★), punkpeye/fastmcp (3,272★) and Anil-matcha/awesome-vibecoded-saas (1,036★) — while yibie/awesome-jev moved the other way, from "merged but uncredited" to a contributor row (2,120★). The correction matters more than the growth: the page had been listing 14 pull requests as still open at laya, and reading the repository's own pull-request connection shows 47 opened, 45 merged, 2 closed unmerged, 0 open — those fourteen merged on 09-27 and 09-29, in two batches of eight, and the section below now says so.

  • The npm figures were re-derived name by name instead of carried forward, and the page had been overstating them. The old line read 56 names, 917 versions, 49 active, 42 with provenance; probing the registry directly — the search index alone is not enough, since it returns 47 names and silently omits the deprecated ones — gives 52 names, 909 versions, 46 whose latest is not deprecated, and 44 carrying a provenance attestation on that version. Over the trailing 30 days the account served 158,593 downloads in the npm window 09-04..10-03, against 134,856 in 08-23..09-21. The six scoped @perrylink/* names and the six deliberate deprecations both re-derived unchanged.

  • The one thing in the family that moved every single day of the window was the verification artifact. dsh-plugin-doctor committed ten times between 09-25 and 10-04, each one chore: refresh verified badges rewriting data/verified.json (+122/-122) against the live GitHub API — a dated, machine-generated record of which repos still pass the zero-dependency R+K static gate on their current default-branch HEAD. Everything else in the window is 29 releases published on 09-25 itself, the repackaging pass that followed the 0.1.7-rc.2 move the previous round reported, and no repository outside the doctor has been pushed since.

🚀 Flagship picks (start here)

The six most-starred family plugins (★ measured 2026-10-04); every other family repo is listed in full further down, and the research four-piece set is under Research.

Plugin What it gives you Install
dsh-auto-review Second-model auto-review on the approval chain, fail-closed by default (228★) dsh plugin --profile web add dsh-auto-review
dsh-research-report Verifiable research reports: content-addressed evidence ledger, manifest seal hash, byte-level citation checks, drift detection, disproof ledger (214★) dsh plugin --profile web add dsh-research-report
dsh-industry-research Industry/company research: chain-map SVG with bottleneck detection, timeline, company cards, adversarial review (207★) dsh plugin --profile web add dsh-industry-research
dsh-memento Approval-gated cross-session memory (ctx.memory + SQLite) (138★) dsh plugin --profile web add dsh-memento
dsh-permission-rules Claude Code-style declarative allow/deny/ask rules plus a process-level network policy (117★) dsh plugin --profile web add dsh-permission-rules
dsh-mcp-panel MCP management console: /mcp + Settings tab + trial calls (74★) dsh plugin --profile web add dsh-mcp-panel

One-command starter pack: dsh-kit — installs the core family in one command.

📦 The full family — 42 plugins + 5 support repos

Counting note: "42 plugins" counts every repo that declares dsh.bundle.patch, re-derived one repo at a time on 2026-10-04 by reading each repo's own package.json at its default branch. Measured against the 47 PerryLink-owned repositories this page names: 42 declare the contract and 5 do not — the support trio dsh-catalog, dsh-kit and dsh-plugin-certification (the certification registry, whose MCP server publishes from dsh-cert-mcp instead), plus jevcore (no dsh.bundle; only its jevcore-dsh workspace member is a plugin) and laya-mcp (an MCP sidecar, not a plugin). The third-party pan17/dsh-wechat carries a plugin row but is not one of them: 47 + 1 = the 48 repos this page names. A naive scan of the account finds two more than the heading claims — the retired dsh-plugin-upgrade corridor legs dsh-plugin-upgrade-015 and dsh-plugin-upgrade-016, both archived, both still carrying the manifest, and neither an active plugin: 42 active + 2 retired = the 44 such a scan returns. The heading and the badge keep the active figure.

🔒 Security (4)

Plugin One-liner npm
dsh-defend Injection/jailbreak/secret detection + destructive-delete gate npm
dsh-permission-rules Declarative allow/deny/ask rules + a local HTTP/CONNECT network policy npm
dsh-mask PII masking/sanitization npm
dsh-skill-pack-security Security-audit skill pack + supply-chain gate npm

🔁 Workflows (8)

Plugin One-liner npm
dsh-background-agents Durable background child agents with a Web UI sidebar, messaging and interrupt npm
dsh-team-rooms Cross-session team rooms: shared message bus, task board, approval-gated handoffs and a timeline that survive restarts npm
dsh-checkpoint-rewind Snapshots, forks, one-shot restore npm
dsh-github GitHub PR/issue integration + Action, writes approval-gated npm
dsh-claude-move Migrate Claude Code/Codex/OpenCode/Hermes into DSH npm
dsh-click Desktop control tools (Windows/macOS) npm
dsh-session-sync Git-backed session synchronization npm
dsh-test-drive Install→smoke→uninstall test driver for plugins npm

✨ Experience & UX (4)

Plugin One-liner npm
dsh-composer-history Terminal-style input history for the web composer npm
dsh-output-styles Runtime-switchable model output styles npm
dsh-session-pin Pin sessions in the Web sidebar npm
dsh-memento Approval-gated cross-session memory protocol npm

🧪 Evaluation (3)

Plugin One-liner npm
dsh-auto-review Second-model auto-review on the approval chain npm
dsh-doublecheck Engineering-discipline guard: grill, gates, adversary review npm
dsh-score Plugin quality scoring across git/gh/npm npm

📊 Observability & cost (4)

Plugin One-liner npm
dsh-autotier Automatic strong/cheap model-tier routing with deterministic risk guards npm
dsh-budget Token/cost metering, budget caps, carbon estimate, latency benchmarks npm
dsh-observe OTel/Langfuse telemetry export npm
dsh-fast Performance diagnostics npm

🎨 Content & knowledge (5)

Plugin One-liner npm
dsh-draw Image-generation routing npm
dsh-translate Translation + JSON repair npm
dsh-talk Speech recognition and voice I/O npm
dsh-library Local knowledge-base RAG npm
dsh-local-ai Ollama LLM provider and routing npm

🛠️ Developer experience (6)

Plugin One-liner npm
dsh-lsp-actions LSP diagnostics/formatting/completion/actions npm
dsh-mcp-panel MCP management console npm
dsh-plugin-guide Plugin-dev knowledge base + CLI toolchain + release-engineering guide npm
dsh-plugin-upgrade Plugin-author upgrade skill: one package, one corridor index that detects the caller's peer band and routes to the matching closed card (0.1.3-alpha.1 → 0.1.5-rc.1, 0.1.5-rc.2 → 0.1.6-alpha.2), plus a zero-dependency seam scanner (bundle skill + npx CLI) npm
jevcore TypeSafe Jev as typed decisions instead of prose (noul/choice/score with calibrated probabilities): offline by default, every transmission named before it happens, disabled gates register nothing (the DSH adapter jevcore-dsh, plus jevcore core and jevcore-mcp for non-DSH MCP hosts) npm
dsh-laya Laya typed decisions (noul/choice/score) as a first-class Cordis service (ctx.laya) plus laya_ask/laya_plan tools; a client of a laya-mcp serve sidecar, so it installs and downloads nothing, and reports whether state stays on this machine as a fact rather than a policy npm

Support repos: dsh-plugin-kit (review-rule meta package) · dsh-catalog (DSH Desktop Market catalog source) · dsh-cert-mcp (certification MCP server) · dsh-kit (one-command installer) · dsh-plugin-doctor (plugin health checker). Five of these repos and plugins publish under a @perrylink/ npm name rather than their repo name — the support repos @perrylink/dsh-plugin-kit and @perrylink/dsh-plugin-doctor, and the plugins @perrylink/dsh-github, @perrylink/dsh-ticktick and @perrylink/dsh-skill-pack-security-provider — and a sixth name, @perrylink/dsh-cert-mcp, is the deprecated scoped predecessor of dsh-cert-mcp; the perrylink account therefore holds 52 npm names while the family has 42 plugin repos (measured 2026-10-04).

📱 Messaging & bridges (3)

Plugin One-liner npm
dsh-wechat WeChat ↔ DSH bridge (Tencent iLink bot): text/image/file/voice, approvals in chat — developed with pan17, who now hosts the repo and publishes the npm package npm
dsh-ticktick TickTick/Dida365 task bridge: session-header panel + 11 tools npm
dsh-reach Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console npm

🔬 Research (4)

Plugin One-liner npm
dsh-data-quality Data profiling/cleaning/verification npm
dsh-fund-research Mutual-fund research, sealed traceable snapshots npm
dsh-industry-research Industry/company research domain pack npm
dsh-research-report Verifiable research-report engine npm

🔧 Upstream & community contributions

Every repo below is external to PerryLink/*; every number is measured, merged work only, and open proposals are deliberately not listed. The third column names the project's owner — the account alone does not say whether that is a company, a standards body or one person.

★ 1,000+ — named individually, as the rule requires, each carrying the party that owns the project. Twenty external repos above a thousand stars carry merged work (★ measured 2026-10-05), three more than the round before — and none of the three is a row that merely drifted over the line: ruvnet/ruflo and walkinglabs/learn-harness-engineering entered with merges landed in the ten days since, and punkpeye/fastmcp has carried its merge since 2026-09-24 and was missing from the earlier seventeen. Six of those rows belong to a company or a well-known project organization — Reactive Resume, DeepSeek, cordiverse, Tencent, and the ACP project that Zed and JetBrains jointly govern, which accounts for two of the twenty; the other fourteen are catalog repos, small community orgs and one-person projects, and the column says so rather than letting the account name imply a company:

Repository ★ 项目归属方
ruflo 73,842 ruvnet (rUv / Reuven Cohen) — individual maintainer; a 73.8k★ agent harness on a personal account, not a company repo, and the largest row in this table
reactive-resume 43,755 reactive-resume org — independent open-source project (rxresu.me)
laya 30,650 NandhaKishorM — individual maintainer; the repo was created 2026-09-18
learn-harness-engineering 18,986 walkinglabs community org — the harness-engineering tutorial site
awesome-dsh-plugin 17,758 awesome-dsh-plugin org — community catalog, no company behind it
FlashMLA 13,034 DeepSeek — the official deepseek-ai org
Cordis 8,999 cordiverse org; its maintainer Shigma is now at DeepSeek, and Cordis is the kernel DeepSeek Harness vendors as @deepseek-ai/cordis
dsh-web 8,364 zhu1090093659 — individual maintainer
ouroboros 6,179 Q00 — individual maintainer (@zep-us)
dsh-market 5,508 dsh-market org — the community plugin market behind dshmarket.com, not a DeepSeek repo
teamai-cli 5,121 腾讯 Tencent — the official Tencent org, opensource.tencent.com
agent-client-protocol 4,371 agentclientprotocol org — governed jointly by Zed Industries and JetBrains
fastmcp 3,272 punkpeye (Frank Fiegel) — individual maintainer at Glama; the TypeScript MCP framework
deepseek-harness-desktop 3,012 dsh-tauri community org — self-described non-official and non-commercial, not a DeepSeek repo
claude-agent-acp 2,610 agentclientprotocol org — the same jointly-governed org as the row above, a separate repository
awesome-jev 2,124 yibie — individual maintainer, community catalog for Jev; the row the 09-25 round both printed and denied, kept now on the commit the history probe finds
dsh-plugin-radar 1,464 AdamPlatin123 — individual maintainer, catalog is a generated artifact
Agents-Anywhere 1,413 anywhere-labs community org — 3 public repos, created 2026-05, dshdesktop.cn; not a company
awesome-deepseek-harness 1,137 0xsline — individual maintainer, community catalog
awesome-vibecoded-saas 1,037 Anil Chandra Naidu Matcha — individual maintainer, community catalog

Cordis is the upstream plugin-core framework that powers DeepSeek Harness — vendored into that repo and renamed @deepseek-ai/cordis; FlashMLA #224 is the only merged pull request in the whole deepseek-ai org.

The rest of the contributor set is the community catalog layer rather than upstream projects: 23 further repositories, DSH plugin directories and small community projects (dsh-handbook and imsai-sh's list, which alone took 41 merges, among them) — the catalogs ingest the family and carry no company owner, so they are named here only in aggregate. 43 external repositories carry at least one merged pull request of ours together with a commit attributed to this account, and 317 merges were counted inside them — re-derived 2026-10-05 from this account's own merged pull requests, so 317 is exact rather than a floor over a probed subset. Two further repositories took 33 more of our merged pull requests without crediting a commit to this account on their default branches — SihanTeng's list, 32 of them, which is the case the rule at the top of this section was written about, and dsh-better-sidebar, one, which merged 2026-10-04 and carries no commit of ours on main — so neither sizes the contributor set. 317 + 33 = the 350 merged pull requests this account has outside PerryLink/*, concentrated in 45 repositories; a further 95 are open across 57 repositories and are deliberately not counted here, 34 of them inside the 45 that have already merged something.

The ten days since the last round moved the merged count by 29 (2026-09-25 → 2026-10-05, the window this round re-measured), and 22 of those 29 are laya alone — the last of them #924, which merged 2026-10-04T17:50:19Z and is the most recent merge this account has anywhere. Six more landed one apiece in six repositories that were not part of this set at all before — ruflo, learn-harness-engineering, koishi-plugin-booru, dsh-plugin-manager, dsh-plugin-market and dsh-annotation — which is what puts the largest row in the table, ruflo at 73,842★, in a set it was not part of ten days ago. The twenty-ninth is dsh-better-sidebar, merged 2026-10-04T17:26:07Z, and it is the one merge in the window that credits this account no commit — which is why it is named in the paragraph above instead of being counted with the other 28. Three proposals opened in that window are still open.

laya — NandhaKishorM/laya — 46 merged pull requests of the 49 this account has opened there, and second among merged-PR authors there: behind aashish254 (126) and ahead of Bruce-Yii (27), with the maintainer NandhaKishorM holding one merged PR of his own because he commits to main directly rather than through pull requests — none of the three leaders is a collaborator, so all three are outside contributors. 45 of the 46 merged inside a nine-day run (2026-09-21 → 2026-09-29), and the maintainer merges in batches rather than one at a time, which is why fifteen of them share two timestamps: seven at 19:29:05 on 09-27 with #556 a second before them, and eight at 17:40:36 on 09-29; the 46th, #924, came five days later on 2026-10-04. Nine areas rather than one:

  • Multilingual routing and evaluation — a caller-supplied language hint (#211), a reproducible per-language harness (#210), a re-run of the 51-language sweep in both temperature regimes (#222), the multilingual columns refreshed from that re-run (#389), letters counted for the scripts no range claims (#169), and a Router that no longer picks a checkpoint from a language code naming no language (#368).
  • HTTP serving and containers — inference moved off the event loop (#230), the Compose laya-serve service (#234), the inference failure the client is not allowed to see now reaching the operator's log (#375), a request with no state no longer answered about the literal text null (#427), and a lone surrogate in the body returning 400 instead of 500 (#454).
  • Email disclaimers and names — the request kept when a disclaimer footer shares its paragraph (#94), "confidential" no longer read as a disclaimer (#227), a From: line opening ordinary prose no longer deleting the request (#371), and a name class that excluded lowercase in every script (#503).
  • Correctness across the call surface — three assertions that could not fail (#231), the load-time and budget errors no suite reached (#237), an ECE that binned differently from its siblings (#232), non-ASCII characters kept in non-string instructions (#228), a README link pointing at a heading that does not exist (#236), a choice label with no description that came back as a non-string (#380), a nested choice label reported as a named caller error instead of a bare TypeError (#425), a score legend that echoed the caller's own type instead of level text (#420), hooks_installed removing a hook it did not install (#424), a null choice label that made the answer undecodable (#508), a short temperature list that now fails at load rather than at the first decode (#502), #249, where a noul criteria dict that cannot be read raises instead of silently falling back to defaults — the line the project's 0.3.11 release note calls "stricter noul criteria" — and #299, two parity cells in the benchmark table that did not match the JSON they cite.
  • The test and CI surface — the Windows lane (#212) and #376, six pytest suites that every lane invoked in a way that exited 0 without running a single test, including the only coverage of the HTTP surface.
  • Prediction hooks and batched routing — process-wide default hooks never reaching predict_batch (#379), predict_batch dropping each request's lang, so per-language temperatures never applied (#381), and lang_temperatures crashing on the inputs it exists to reject (#428).
  • The TypeScript front end — the From: header rules the Python side already had, ported rather than re-derived (#422); the Azerbaijani schwa counted as a non-English letter (#423); and a score legend that echoed the caller's own types, unlike the Python backends (#556).
  • CLI, packaging and serving edges — --preset sending the request under a key no question set names (#426); the onnx extra missing its onnxscript dependency (#504); the packaging test scanning .venv for broken links (#500); and two over-budget messages that each named a knob which makes the problem worse rather than the one that fixes it (#455, #501).
  • Documentation — #378, which stopped the README presenting a confidence threshold as permission to act on its own, and the pages the project's docs-structure issue asked contributors to write: the fine-tuning guide (#505), the Questions and answers guide (#418), and the reference entry for answer_confidence, which no page documented (#419).

The nine area headings above are this account's own grouping of its 45 merges, not the project's taxonomy; the merge counts are the repository's own.

One is open there and deliberately not counted above — #925, a stale low_confidence left behind on a re-gate. It was two until 2026-10-04T17:50:19Z, when #924, a load that crashes because transformers tries to import TensorFlow, merged and moved into the 46 counted above. Both went up 2026-10-04, after the fourteen this page had listed as pending were all resolved — thirteen merged between 09-25 and 09-29, and #416 closed instead, with the guide it carried landing as #418. That leaves two closures unmerged in total, and the reason is on the record for each: #370, closed by this account as a duplicate of #362, which opened the same fix four minutes earlier, and #416, the Routing guide, closed by the maintainer in favour of another contributor's #461 so the project would not carry two routing pages.

Security — published advisory GHSA-j922-p6h6-p255 for dsh-permission-rules (medium, patched in 0.6.16).

Official harness repo — it does not accept external pull requests, so that line runs through issues, Discussions (the Show Your Plugins! post #6104) and the plugin ecosystem instead — while the wider deepseek-ai org is open to fixes, and the account now proposes them at the systems layer rather than only in its catalogs: of the 20 pull requests it has opened across that org, FlashMLA #224 remains the only one merged, and 16 are open, 14 of them code fixes carrying a reproduction across ten repositories — DeepEP three, FlashMLA and deepseek-recipe two each, and one apiece in DeepGEMM, 3FS, TileKernels, DeepSeek-MoE, DeepSeek-Prover-V1.5, DeepJIT and DeepSelect — the other two are catalog additions.

🌍 Where the plugins live

  • GitHub (this profile), Gitee and npm — source, CI and releases here; 46 family repos mirrored to Gitee by a daily job (default branch + all tags), plus this profile repo; the perrylink account holds 52 npm names and 909 versions, 46 of them with a non-deprecated latest and 44 carrying a provenance attestation on that version (measured 2026-10-04 against each name's own packument — the registry search endpoint is not authoritative here, since it returns only 47 names and omits the deprecated ones)
  • npm downloads — 158,593 over the trailing 30 days (npm window 09-04..10-03, summed per name from the downloads point endpoint; dshfind independently tracks 21.5k+ across the 7 family plugins it currently has a download figure for — dshfind reports rounded tiers, so that is a floor rather than a total
  • DSH Desktop Market — add the catalog source https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json under Market → Sources to browse the family in-app; MCP Registry — three servers, all published from their release workflows over GitHub OIDC: dsh-cert-mcp, jevcore-mcp and laya-mcp
  • GitHub Actions — dsh-github and dsh-test-drive also ship composite actions, so they install as uses: PerryLink/dsh-test-drive@vX

Published to a dozen-plus third-party DSH directories and curated lists — awesome-dsh-plugin, DSH Directory, Awesome DeepSeek Harness, walkinglabs' list, Zhiyuan-Fan's list, the AdamPlatin123 radar, dsh-suite, dshfind.com, deepseek1024.com and Glama among them — and scored on OpenSSF Scorecard; the GitHub dsh-plugin topic is what most of them ingest from.

中文介绍

在 DeepSeek Harness 上构建插件生态:42 个开源插件,来自一个 48 仓的家族(其中 47 个由 PerryLink 自己维护)—— 安全、工作流、研究、消息桥接、开发者体验,外加 DSH Desktop Market 目录、插件认证注册表与 dsh-plugin-doctor 这个 CI 检查器。42 个插件全部带 CI 与 Gitee 镜像,五语文档由每个仓自己的 CI 闸门守着一致(段落数、安装命令、配置键),并声明 dsh.bundle 契约;近 30 天 npm 下载 158,593(窗口 09-04..10-03)。perrylink 这个 npm 账号下共有 52 个名称、909 个版本:其中 46 个 latest 版本未弃用(40 个非 scoped + 6 个 @perrylink/ scoped)、6 个已弃用(dsh-plugin-upgrade 折进 2.0.0 后退役的一条走廊腿、作者撤回的 dsh-personal-directive、改名前的 scoped @perrylink/dsh-cert-mcp,以及三个已归档的 layacore 名字)、44 个当前 latest 版本带 provenance 证明(均按 2026-10-04 实测,逐个读各自 packument —— 注意 npm 的 search 接口在这里不作数,它只返回 47 个名称并漏掉已弃用的那几个)。我也向上游 Cordis(DeepSeek Harness 所基于的插件内核框架)与 deepseek-ai 项目贡献:该组织下 20 条 PR 里,已合并的仍是 FlashMLA 修复(#224,唯一一条),另有 16 条开放,其中 14 条是带复现的系统层修复(DeepEP 3 条、FlashMLA 与 deepseek-recipe 各 2 条,以及 DeepGEMM、3FS、TileKernels、DeepSeek-MoE、DeepSeek-Prover-V1.5、DeepJIT、DeepSelect 各 1 条);家族之外共 43 个外部仓带着本账号已合并的 PR 与一条归属提交,其中 20 个在千星以上,已合并 PR 合计 348 条(均按 2026-10-05 实测)。

这一家子所依赖的那项研究,现在是一篇有 DOI 的论文 —— 而且它测的很大一部分,正是这份主页上的两个项目:laya-mcp 与 jevcore。《当判定层的自报字段说谎时:三类判断层的成本、延迟与失效边界实测》在一套相同条目上实测三类判定层(Laya、TypeSafe Jev、DeepSeek-V4.1-Flash),四条主张三条成立、一条被自己的数据否定;判定器的接入层自报字段不可信(截断标志报「通过」却静默丢输入、概率字段把结论反号、两个判定词在真实输入下不可达),失效集中在一处 —— 答案被明确陈述时近乎完美(0.9909,n=220),必须注意到「缺席」时塌缩(0.3091,n=220);异种判定器在三个区制上都没有增量覆盖。引其一即可,不要当两篇引(英文原文 · 中文译本 · 制品);两者有出入以英文为准。

2026-10-05 轮:这一轮换掉了探针本身 —— 两个便宜的探针都会漏判,而且都往对本页有利的方向漏。/contributors 是上限 100 条的派生列表,对 yibie/awesome-jev 不返回条目,而那条默认分支上确实有本账号的一条提交(09-25 那轮把这条假阴性写成了「拿了合并却没给提交署名」,同时又把它印成了表格行,等于自相矛盾);/commits?author=<login> 对 pan17/dsh-wechat 返回空数组,而那条默认分支上有本账号的三条提交。现在改用规则本身指定的 defaultBranchRef.target.history(按 author:{id} 过滤),读的是真实历史:43 个外部仓带本账号的提交、其中 316 条合并、另有 1 个仓拿了 32 条却一条提交都不署名、千星以上 20 行;旧探针否掉而新探针确认的那一个,就是 yibie/awesome-jev(2,124★)。距 09-25 那次实测的十天里,家族外多了 27 条合并,其中 21 条在同一个仓;另外 6 条各落在一个此前根本不在名单里的仓(ruvnet/ruflo、walkinglabs/learn-harness-engineering、koishijs/koishi-plugin-booru、2768651338/dsh-plugin-manager、losebird/dsh-plugin-market、omdsh-dev/dsh-annotation),千星表里最大的一行 ruflo(73,842★)就是这一轮进来的。上一轮自己有三处说法经不起复核:laya 的排名是第二而不是第三(45 夹在 aashish254 的 126 与 Bruce-Yii 的 27 之间,「第三、前面是 126 和 27」本身算不通);那里也不是「没有任何在途的东西」—— #924、#925 于 10-04 新开;两次关闭里只有 #370 是本账号自己关的,#416 由维护者关闭、改用另一位贡献者的 #461。家族之外的开放提案是 97 条、分布在 58 个仓,而 deepseek-ai 组织下现在有 16 条本账号针对其系统仓的开放提案,那边已合并的仍只有 FlashMLA #224。

**2026-10-04 轮:这一轮是重新测量,不是发布 —— 三处旧数字被自己的探针推翻。**其一,主页写「36 个外部仓带我的提交」,同一套规则重跑(106 个外部仓逐个查 /contributors)返回 43 个,千星以上从 17 涨到 20 个,家族之外的已合并 PR 从 321 涨到 348;更要紧的是纠错:主页把 14 条 laya 的 PR 列为「仍开放」,而读仓库自己的 pull request 连接是「开过 47 条、合并 45 条、自行关闭 2 条、当前开放 0 条」—— 那 14 条在 09-27 与 09-29 两批各 8 条合掉了。其二,npm 数字逐名重测后是 52 个名称、909 个版本、46 个 latest 未弃用、44 个带 provenance,而不是旧版写的 56 / 917 / 49 / 42。其三,窗口里唯一每天都有动作的是 dsh-plugin-doctor:09-25 到 10-04 共 10 次提交,每次都是 chore: refresh verified badges 重写 data/verified.json(+122/-122)。

laya(NandhaKishorM/laya)是这个账号投入最深的外部项目:提了 49 条 PR,其中 45 条已合并,合并数在该仓排第二 —— 前面是 aashish254 的 126 条,后面是 Bruce-Yii 的 27 条;维护者 NandhaKishorM 自己只有 1 条已合并 PR,因为他直接向 main 提交而不走 PR。这三位领头的都不是该仓的 collaborator,所以都算外部贡献者。45 条全部合在 2026-09-21 至 09-29 这九天里,而维护者是成批合并而不是逐条合,所以有 15 条共享两个时间戳:09-27 的 19:29:05 一次合了 7 条(#556 早一秒),09-29 的 17:40:36 一次合了 8 条。方向不是一个,而是九个:#211、#210、#222、#389、#169、#368(多语言路由与评测);#230、#234、#375、#427、#454(HTTP 服务与容器);#94、#227、#371、#503(邮件免责声明与姓名类);#231、#237、#232、#228、#236、#380、#425、#420、#424、#508、#502、#249、#299(调用面正确性);#212、#376(测试与 CI 面);#379、#381、#428(prediction hooks 与批量路由);#422、#423、#556(TypeScript 前端);#426、#504、#500、#455、#501(CLI、打包与服务边界);#378、#505、#418、#419(文档)—— 包括项目的第一条 Windows CI 车道(#212),Linux 的 16 个 suite 里 15 个现在在 windows-latest 上跑。另有 #924、#925 两条仍开放(2026-10-04 提的,一条是 transformers 试图导入 TensorFlow 导致加载崩溃,一条是重新过闸时残留的 low_confidence),按上面的口径不计入;此前主页列为「仍开放」的那 14 条已全部了结:13 条在 09-25 至 09-29 之间合并,#416 那条 Routing 指南则由维护者关闭、改用另一位贡献者的 #461,它承载的内容以 #418 落地。因此未合并即关闭的一共 2 条,原因各自有记录:#370 由我自己作为重复关闭(比它早四分钟的 #362 是同一个修复),以及上面那条 #416。

还有一条在别处:一个根本起不来的进程现在能起来了。 claude-agent-acp #1146 让 src/index.ts 里那处没有保护的顶层 await 不再因一次瞬时错误就中断模块求值、在发出任何一条 ACP 消息之前退出。

待业中。十一准备出去玩一圈,所以更新迭代节奏可能短期内仍然提升的有限。当然,问题和缺陷修复不会停,只是发布频率会降低一些,还请大家谅解。

About

Building the DeepSeek Harness plugin ecosystem: 42 open-source plugins in a 46-repo family, 45 PerryLink-owned - security, workflows, research, messaging bridges, developer experience - plus the DSH Desktop Market catalog, a certification registry and the dsh-plugin-doctor CI checker. Cordis + deepseek-ai contributor, plus 24 merged PRs to laya.

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors