{"_id":"@dsh-so/dsh-plugin-advisor","_rev":"3-0720588704c01427593d32b1efe00b8c","name":"@dsh-so/dsh-plugin-advisor","dist-tags":{"latest":"0.2.1"},"versions":{"0.2.0":{"name":"@dsh-so/dsh-plugin-advisor","version":"0.2.0","license":"Apache-2.0","_id":"@dsh-so/dsh-plugin-advisor@0.2.0","maintainers":[{"name":"ihuajiu","email":"smith.chou.2023@gmail.com"}],"homepage":"https://github.com/dsh-so/dsh-plugin-advisor#readme","bugs":{"url":"https://github.com/dsh-so/dsh-plugin-advisor/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"b1a5de557375b235bd4a9489565dc46668dd9091","tarball":"https://registry.npmjs.org/@dsh-so/dsh-plugin-advisor/-/dsh-plugin-advisor-0.2.0.tgz","fileCount":10,"integrity":"sha512-mWB7qAxlwjkV06fgt0mdJmgrrpJlQjPIcATu5Z9Qm46mfxs5DU4H++b74mZhwLCZeBfl1UMsyiGj7TICxSGpsQ==","signatures":[{"sig":"MEUCIQCiggQ+rKnJzcFLydGzW6V/FOmF20BE+M3wBIIdQwyvdQIgFt2fUlFORSB4+TMcM+y7sdy5RaZfBe+3mWTgYyGY0lw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":75697},"main":"lib/index.js","type":"module","types":"lib/index.d.ts","gitHead":"154d6c5fd6d188e19c5045e2e13ee0bbb95a26b4","scripts":{"test":"node --test","build":"tsc -p tsconfig.json","verify":"npm test && npm run verify:install","prepublishOnly":"tsc -p tsconfig.json","verify:install":"node scripts/verify-install.mjs"},"_npmUser":{"name":"ihuajiu","email":"smith.chou.2023@gmail.com"},"repository":{"url":"git+https://github.com/dsh-so/dsh-plugin-advisor.git","type":"git"},"_npmVersion":"11.9.0","description":"Find DeepSeek Harness plugins from the dsh.so registry — like find-skill, but for dsh plugins.","directories":{},"_nodeVersion":"24.14.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^20.19.43","@deepseek-ai/dsh-tools":"0.1.0-rc.6","@deepseek-ai/schemastery":"^3.18.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"0.1.0-rc.6","@deepseek-ai/schemastery":"^3.18.1"},"_npmOperationalInternal":{"tmp":"tmp/dsh-plugin-advisor_0.2.0_1788784168072_0.345124297874025","host":"s3://npm-registry-packages-npm-production"},"deprecated":"renamed to @dsh-so/dsh-plugin-finder"},"0.2.1":{"name":"@dsh-so/dsh-plugin-advisor","version":"0.2.1","license":"Apache-2.0","_id":"@dsh-so/dsh-plugin-advisor@0.2.1","maintainers":[{"name":"ihuajiu","email":"smith.chou.2023@gmail.com"}],"homepage":"https://github.com/dsh-so/dsh-plugin-advisor#readme","bugs":{"url":"https://github.com/dsh-so/dsh-plugin-advisor/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"2faafcbcc10e975ee72687ca5abd182827957f12","tarball":"https://registry.npmjs.org/@dsh-so/dsh-plugin-advisor/-/dsh-plugin-advisor-0.2.1.tgz","fileCount":10,"integrity":"sha512-LDinjnPK3VMmL9m2nIOr2Fa6Wka7MmGmy34mNsI0x1/Vn6mhw8c49faFuXb/Xa1aaQ/Ruxm5bSU7PPl1PcesGw==","signatures":[{"sig":"MEUCIQDqX9FYjvFlE4ERnMJmAzg00jzJSsZ8Ni5PRFG3ACimpQIgJ6yx5FzH9N/4qFRbcSdEONMAsWRGiKH/Tw/91CMBTM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIA5KkQFWgOoKi02vkTxvja9ZsxRTNVc9DqAt0wOw+aVYAiEA8q+YfLafNvXMVeU7+LN7MuN3JI5Lzh18Ls0QHGJq9RI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76109},"main":"lib/index.js","type":"module","types":"lib/index.d.ts","gitHead":"11dd220c0af132bae42ff8ac30dfd168c9f37726","scripts":{"test":"node --test","build":"tsc -p tsconfig.json","verify":"npm test && npm run verify:install","prepublishOnly":"tsc -p tsconfig.json","verify:install":"node scripts/verify-install.mjs"},"_npmUser":{"name":"ihuajiu","email":"smith.chou.2023@gmail.com"},"repository":{"url":"git+https://github.com/dsh-so/dsh-plugin-advisor.git","type":"git"},"_npmVersion":"11.9.0","description":"Find DeepSeek Harness plugins from the dsh.so registry — like find-skill, but for dsh plugins.","directories":{},"_nodeVersion":"24.14.0","_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^20.19.43","@deepseek-ai/dsh-tools":"0.1.0-rc.6","@deepseek-ai/schemastery":"^3.18.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"0.1.0-rc.6","@deepseek-ai/schemastery":"^3.18.1"},"_npmOperationalInternal":{"tmp":"tmp/dsh-plugin-advisor_0.2.1_1788785364946_0.5712699106354551","host":"s3://npm-registry-packages-npm-production"},"deprecated":"renamed to @dsh-so/dsh-plugin-finder"}},"time":{"created":"2026-09-07T12:29:27.955Z","modified":"2026-09-20T18:05:23.257Z","0.2.0":"2026-09-07T12:29:28.207Z","0.2.1":"2026-09-07T12:49:25.038Z"},"bugs":{"url":"https://github.com/dsh-so/dsh-plugin-advisor/issues"},"license":"Apache-2.0","homepage":"https://github.com/dsh-so/dsh-plugin-advisor#readme","repository":{"url":"git+https://github.com/dsh-so/dsh-plugin-advisor.git","type":"git"},"description":"Find DeepSeek Harness plugins from the dsh.so registry — like find-skill, but for dsh plugins.","maintainers":[{"name":"ihuajiu","email":"smith.chou.2023@gmail.com"}],"readme":"# dsh-plugin-advisor\r\n\r\n在 dsh.so 插件市场中检索 DeepSeek Harness 插件——类似 *find-skill*,但面向 dsh 插件。\r\n\r\n本插件在会话中注册一个 **`plugin_advisor`** 工具:用一句自然语言描述需求,它从 dsh.so 插件市场索引中检索最匹配的插件,返回插件名、GitHub star 数、标签、简介、**验证级别(L1–L5)**、**安全状态与风险等级**、**安装命令**和详情链接。\r\n\r\n<p align=\"center\">\r\n  <a href=\"https://www.dsh.so\" rel=\"dofollow\">\r\n    <img src=\"https://raw.githubusercontent.com/dsh-so/dsh-plugin-advisor/main/assets/dsh-so-logo.svg\" alt=\"dsh.so 标志\" width=\"72\">\r\n  </a>\r\n  <br>\r\n  <strong>Powered by <a href=\"https://www.dsh.so\" rel=\"dofollow\">dsh.so</a></strong>\r\n  <br>\r\n  <em>DeepSeek Harness 插件市场——发现、对比并安装插件</em>\r\n</p>\r\n\r\n**English**: [README.md](https://github.com/dsh-so/dsh-plugin-advisor/blob/main/README.md)\r\n\r\n## 目录\r\n\r\n1. [安装](#1-安装)\r\n2. [安装时的 peer 依赖警告(重要)](#2-安装时的-peer-依赖警告重要)\r\n3. [使用方法](#3-使用方法)\r\n4. [返回结果格式](#4-返回结果格式)\r\n5. [查询技巧](#5-查询技巧)\r\n6. [配置](#6-配置)\r\n7. [数据来源与匹配规则](#7-数据来源与匹配规则)\r\n8. [常见问题 FAQ](#8-常见问题-faq)\r\n9. [开发与发布](#9-开发与发布)\r\n\r\n---\r\n\r\n## 1. 安装\r\n\r\n从 dsh.so 插件市场安装(推荐):\r\n\r\n```sh\r\ndsh plugin --profile web add @dsh-so/dsh-plugin-advisor\r\n```\r\n\r\n其他 profile 同理,替换名字即可:\r\n\r\n```sh\r\ndsh plugin --profile tui add @dsh-so/dsh-plugin-advisor\r\ndsh plugin --profile headless add @dsh-so/dsh-plugin-advisor\r\n```\r\n\r\n从本地源码目录安装(开发调试时):\r\n\r\n```sh\r\ndsh plugin --profile web add E:\\AgentsWs\\dsh-so-projects\\dsh-plugins\\dsh-plugin-advisor\r\n```\r\n\r\n> ⚠️ **版本提示**:若你装的是 **0.1.0**,请先升级——0.1.0 把 `@deepseek-ai/dsh-tools` 装成了普通依赖,会与宿主副本冲突导致 agent 循环崩溃(`Cannot read properties of undefined (reading 'prepare')`)。**0.1.1 已修复**,重新安装:\r\n>\r\n> ```sh\r\n> dsh plugin --profile web add @dsh-so/dsh-plugin-advisor@^0.1.1\r\n> ```\r\n\r\n安装完成后,**重启 web profile** 才能生效:\r\n\r\n```sh\r\ndsh web\r\n```\r\n\r\n重启后,会话里就会出现 `plugin_advisor` 工具,直接对助手说需求即可触发(见[使用方法](#3-使用方法))。\r\n\r\n### 升级\r\n\r\n```sh\r\ndsh plugin --profile web add @dsh-so/dsh-plugin-advisor@latest\r\ndsh web    # 重启以加载新 bundle\r\n```\r\n\r\n### 卸载\r\n\r\n```sh\r\ndsh plugin --profile web remove @dsh-so/dsh-plugin-advisor\r\ndsh web    # 重启以卸载 bundle\r\n```\r\n\r\n> ⚠️ 卸载务必用**包名**,绝不把本地路径传给 `remove`/`del`,否则会删掉源码目录的文件。\r\n\r\n---\r\n\r\n## 2. 安装时的 peer 依赖警告(重要)\r\n\r\n执行安装命令时,你大概率会看到这样一段 pnpm 输出:\r\n\r\n```\r\nWARN  Issues with peer dependencies found\r\n└─┬ @dsh-so/dsh-plugin-advisor 0.1.1\r\n  ├── ✕ missing peer @deepseek-ai/cordis@^4.0.1\r\n  ├── ✕ missing peer @deepseek-ai/dsh-tools@0.1.0-rc.6\r\n  └── ✕ missing peer @deepseek-ai/schemastery@^3.18.1\r\n```\r\n\r\n**这是正常的\"误报\",不需要做任何处理,插件可以正常使用。**\r\n\r\n### 为什么会出现\r\n\r\n- `dsh plugin add` 的机制是在 profile 目录下执行 `pnpm add`;pnpm 校验 peer 依赖时,**只看 web profile 自己声明的依赖**(目前只有 `@dsh-so/dsh-plugin-advisor` 一个)。\r\n- 而这 3 个 `@deepseek-ai/*` 包由 **DSH 宿主(harness)统一管理**,实际安装在上一级目录 `~/.dsh/profiles/node_modules`。\r\n- 运行时,Node 的模块解析会**逐级向上查找**,所以插件能正常 `import` 到宿主提供的这些包。\r\n\r\n### 如何确认没问题\r\n\r\n只需确认宿主侧的实际版本满足插件要求。当前环境实测:\r\n\r\n| 插件要求 | 宿主实际版本 | 结果 |\r\n|---|---|---|\r\n| `@deepseek-ai/cordis@^4.0.1` | 4.0.1 | ✅ |\r\n| `@deepseek-ai/dsh-tools@0.1.0-rc.6` | 0.1.0-rc.6 | ✅ |\r\n| `@deepseek-ai/schemastery@^3.18.1` | 3.18.1 | ✅ |\r\n\r\n### dsh 适配版本 / Compatibility with dsh\r\n\r\n- **目标依赖线**:`@deepseek-ai/dsh-tools@0.1.0-rc.6` · `@deepseek-ai/cordis@^4.0.1` · `@deepseek-ai/schemastery@^3.18.1`(即 dsh rc.6 系列)。\r\n- **实测环境**:dsh 10.28.1(web profile)。\r\n- **状态**:作者声明(Declared),未经独立验证——遵循 dsh.so 兼容性矩阵语义。\r\n- **升级 dsh 后自查**:重启 profile,确认 `plugin_advisor` 存在;若大版本升级跨了依赖线,先执行 `dsh plugin --profile web update @dsh-so/dsh-plugin-advisor` 再试。\r\n\r\n> 事实上,DSH 生态里**任何**正确声明了 peer 依赖的第三方插件,装进 profile 时都会出现类似的警告(harness 自己的 `@deepseek-ai/dsh-tool-cordis` 也是这么声明 `@deepseek-ai/cordis` 的)。这是 pnpm 的\"信息缺失\"提示,不是错误。\r\n\r\n### 不建议的\"修复\"方式\r\n\r\n1. **不要把插件的 `peerDependencies` 改成 `dependencies`** —— 那会让每个插件自带一份宿主核心包的副本,遮蔽宿主的单例,反而会触发 `ctx.tools` 崩溃(即上面 0.1.0 的 bug)。\r\n2. **不建议把 3 个 peer 显式装进 profile** —— 版本会被钉死在 profile 里,未来宿主升级核心包时,插件仍加载旧版,产生 API 错位的隐蔽问题。\r\n\r\n如果只是想让 CI 日志干净,可以显式安装(会换来一次性的 `declares no dsh.bundle` 提示):\r\n\r\n```sh\r\ndsh plugin --profile web add @deepseek-ai/cordis@4.0.1 @deepseek-ai/dsh-tools@0.1.0-rc.6 @deepseek-ai/schemastery@3.18.1\r\n```\r\n\r\n日常使用:**直接忽略警告即可**。\r\n\r\n---\r\n\r\n## 3. 使用方法\r\n\r\n`plugin_advisor` 是**模型工具**,不需要手动输入命令——直接对助手说需求,它会自动调用。示例(中英文均可):\r\n\r\n- \"帮我找支持 OCR / 截图转文字的 dsh 插件\"\r\n- \"有没有终端 TUI 插件?\"\r\n- \"我想做 RAG 记忆,有什么插件\"\r\n- \"Find me a plugin for price tracking\"\r\n- \"有没有能识别图片内容的插件?\"\r\n\r\n### 完整对话示例\r\n\r\n**中文 — OCR / 截图**\r\n\r\n- **你:** *帮我找支持 OCR / 截图转文字的 dsh 插件*\r\n- **助手:** *自动调用 `plugin_advisor`,参数 `{\"query\": \"vision OCR screenshots\", \"limit\": 3}`,返回按相关度排序的结果——见[返回结果格式](#4-返回结果格式)*\r\n- **你:** *第一个怎么装?*\r\n- **助手:** *执行 `dsh plugin --profile web add dsh-vision-router`,然后重启 `dsh web`。*\r\n\r\n**English — terminal TUI**\r\n\r\n- **You:** *I need a terminal TUI plugin*\r\n- **Agent:** *calls `plugin_advisor` with query `\"terminal TUI\"`* → returns `dsh-tianshu-tui`, `dsh-whale-tui`, `dsh-tui`\r\n- **You:** *Install the first one*\r\n- **Agent:** *Run `dsh plugin --profile web add dsh-tianshu-tui`, then restart `dsh web`.*\r\n\r\n### 能力缺口自动搜索与安装确认\r\n\r\n当你的需求**已安装的插件都无法满足**时，agent 会自动调用 `plugin_advisor` 搜索缺失的能力。结果默认通过质量门槛——**L5（实测）验证等级** 且 **安全审计通过**（warning 级发现可接受，排除 high/critical 风险）。随后工具会高亮最匹配的一个插件、给出安装命令，并**先向用户确认再安装**——未经同意不会安装任何插件。\r\n\r\n### 工具参数\r\n\r\n| 参数 | 必填 | 类型 | 说明 |\r\n|---|---|---|---|\r\n| `query` | ✅ | string | 需求描述,如 `\"vision OCR screenshots\"`、`\"memory rag\"`。中英文均可,英文命中率更高 |\r\n| `limit` | ❌ | number | 返回条数,默认取插件配置 `maxResults`(默认 5),范围 1–10 |\r\n\r\n---\r\n\r\n## 4. 返回结果格式\r\n\r\n每条结果包含:排名、插件名、star 数、标签、**验证级别(L1–L5)**与**安全状态/风险**徽标、简介、安装命令、详情链接。以下为**真实示例**(取自 dsh.so 实时索引,排名与 star 数会随时间变化)。\r\n\r\n**`plugin_advisor(\"vision OCR screenshots\", limit=3)`**\r\n\r\n```\r\n1. dsh-vision-router — 46★ [developer, vision] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   Eyes for text-only DeepSeek Harness agents: built-in free vision chain (no key) + pixel-level vision tools (Q&A, grounding, crop, pixel diff, colors, OCR, SVG trace, cutout, screenshots)……\r\n   Install: dsh plugin --profile web add dsh-vision-router\r\n   https://www.dsh.so/plugins/dsh-vision-router/\r\n\r\n2. agent-vision-toolkit — 819★ [developer, vision, automation, ai, ui] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   为纯文本模型\"看图\"设计更好的视觉工具箱和技能,支持多图理解,图片问答,\r\n   前端UI还原、GUI 自动化等……\r\n   Install: dsh plugin --profile web add agent-vision-toolkit\r\n   https://www.dsh.so/plugins/agent-vision-toolkit/\r\n\r\n3. dsh-vision-toolkit — 317★ [vision, browser, automation, ui] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   让纯文本模型更好地做视觉任务的DeepSeek Harness插件:带意图的图片问答、长截图 OCR、UI 还原等……\r\n   Install: dsh plugin --profile web add dsh-vision-toolkit\r\n   https://www.dsh.so/plugins/dsh-vision-toolkit/\r\n```\r\n\r\n**`plugin_advisor(\"terminal TUI\", limit=3)`**\r\n\r\n```\r\n1. dsh-tianshu-tui — 132★ [terminal, ui] · ✔ 基础验证通过 · 🔒 安全通过:低风险\r\n   dsh-tianshu-tui — DeepSeek Harness terminal UI\r\n   Install: dsh plugin --profile web add dsh-tianshu-tui\r\n   https://www.dsh.so/plugins/dsh-tianshu-tui/\r\n\r\n2. dsh-whale-tui — 0★ [developer, terminal, ui] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   grok-build style terminal UI for DeepSeek Harness: a Rust/ratatui TUI shipped as a dsh plugin bundle\r\n   Install: dsh plugin --profile web add dsh-whale-tui\r\n   https://www.dsh.so/plugins/dsh-whale-tui/\r\n\r\n3. dsh-tui — 4★ [developer, terminal, ai, ui] · ✔ 已收录(未功能测试) · 🔒 安全通过:低风险\r\n   Claude Code-style terminal UI for DeepSeek Harness agents, as an out-of-tree dsh plugin bundle\r\n   Install: dsh plugin --profile web add dsh-tui\r\n   https://www.dsh.so/plugins/dsh-tui-4/\r\n```\r\n\r\n**`plugin_advisor(\"memory rag\", limit=3)`**\r\n\r\n```\r\n1. dsh-memory — 2★ [terminal, knowledge, storage] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   Cited memory over DSH's lossless session log — distilled, human-auditable facts with citations……; memory_read/memory_expand tools, recall index, and a dsh-memory CLI.\r\n   Install: dsh plugin --profile web add dsh-memory-2\r\n   https://www.dsh.so/plugins/dsh-memory-2/\r\n\r\n2. dsh-memory — 1★ [knowledge, storage] · ✔ 基础验证通过 · ⚠️ 安全提示:中风险\r\n   Durable cross-session SQLite memory for DeepSeek Harness\r\n   Install: dsh plugin --profile web add dsh-memory\r\n   https://www.dsh.so/plugins/dsh-memory/\r\n\r\n3. mindspace-dsh-session-memory — 1★ [knowledge, storage] · ✔ 基础验证通过 · 🔒 安全通过:低风险\r\n   Editable, session-isolated personalization memory for DeepSeek Harness\r\n   Install: dsh plugin --profile web add mindspace-dsh-session-memory\r\n   https://www.dsh.so/plugins/mindspace-dsh-session-memory/\r\n```\r\n\r\n> 💡 查询意图很重要:`\"price tracking\"` 匹配到的是**费用/余额追踪**类插件(`dsh-balance`、`deepseek-harness-wallet`),而不是比价爬虫——匹配结果反映的是索引里实际存在的描述。\r\n\r\n无匹配时返回提示:\r\n\r\n```\r\nNo plugins in the dsh.so registry matched that query. Suggest broader terms (e.g. \"image\", \"terminal\", \"memory\").\r\n```\r\n\r\n每条结果(匹配或无匹配)末尾都会附带 **Powered by dsh.so** 推广信息和版权行(`dsh-plugin-advisor v0.2.1 · © 2026 zhoushimin · Apache-2.0`)。可通过 `attribution: false` 关闭。\r\n\r\n---\r\n\r\n## 5. 查询技巧\r\n\r\n- **中文查询已优化**：内置中英概念词典（记忆→memory、账单→billing 等）与 CJK 二元组匹配，中文长句也能准确命中；英文短词仍最优。\r\n- **把需求说具体**:`\"terminal TUI\"` 比 `\"好看的界面\"` 结果更准。\r\n- **可以用标签词**:如 `vision`、`browser`、`automation`、`ui`,标签命中权重更高。\r\n- **空 query 会按 star 数返回 Top N**(模型一般不会这么用,但行为如此)。\r\n- **匹配是关键词打分,不是 AI 语义**:名称命中 +3、标签命中 +2、简介命中 +1,同分按 star 数排序。措辞差异大时,换个说法再试。\r\n\r\n---\r\n\r\n## 6. 配置\r\n\r\n在宿主 composition 或 agent preset 的 `cordis.yml` 中配置(默认值即可,通常无需修改):\r\n\r\n```yaml\r\n- insert:\r\n    - id: dsh-plugin-finder\r\n      name: @dsh-so/dsh-plugin-advisor\r\n      config:\r\n        indexUrl: https://www.dsh.so/plugins-index.json   # 索引地址,自建/测试时覆盖\r\n        maxResults: 5                                      # 默认返回条数\r\n        cacheTtlMs: 600000                                 # 索引缓存 10 分钟\r\n        timeoutMs: 15000                                   # 抓取超时(毫秒)\r\n```\r\n\r\n| 配置项 | 默认值 | 说明 |\r\n|---|---|---|\r\n| `indexUrl` | `https://www.dsh.so/plugins-index.json` | dsh.so 机器可读插件索引地址 |\r\n| `maxResults` | `5` | 未传 `limit` 时的默认返回条数 |\r\n| `cacheTtlMs` | `600000`(10 分钟) | 索引缓存时长,避免每次调用都重新抓取 |\r\n| `timeoutMs` | `15000` | 抓取索引的超时时间(毫秒) |\r\n| `attribution` | `true` | 在每次结果末尾追加 \"Powered by dsh.so\" 推广与版权信息 |\r\n| `minVerificationLevel` | `5` | Minimum verification level (L1–L5) a result must have; `0` disables the filter / 结果最低验证等级，0 表示不过滤 |\r\n| `requireLowRisk` | `true` | Only audited plugins; warning-level findings are kept, high/critical risk excluded / 仅保留已审计插件，warning 可接受，排除 high/critical |\r\n\r\n---\r\n\r\n## 7. 数据来源与匹配规则\r\n\r\n- **数据源**:`https://www.dsh.so/plugins-index.json` —— dsh.so 全部插件的机器可读索引(id、name、description、stars、topics、install、url、verification 验证级别、security 安全状态与风险)。\r\n- **匹配**:query 分词后对每个 token 打分——名称包含 +3、标签包含 +2、简介包含 +1;按总分排序,同分按 star 数排序,取前 `limit` 条。\r\n- **缓存**:索引在 `cacheTtlMs` 内复用,不重复请求。\r\n\r\n---\r\n\r\n## 8. 常见问题 FAQ\r\n\r\n**Q: 装完插件,会话里没有 `plugin_advisor` 工具?**\r\nA: 检查两步:① `dsh plugin --profile web list` 确认已安装;② 安装后需要**重启** `dsh web` 才能加载新 bundle。\r\n\r\n**Q: 安装时的一堆 `missing peer` 警告要不要管?**\r\nA: 不用管,是误报,见[第 2 节](#2-安装时的-peer-依赖警告重要)。\r\n\r\n**Q: 查询没结果?**\r\nA: 换更宽的英文词,如 `\"image\"`、`\"terminal\"`、`\"memory\"`;或去掉过具体的限定词。\r\n\r\n**Q: 插件升级了,怎么更新?**\r\nA: `dsh plugin --profile web add @dsh-so/dsh-plugin-advisor@latest`,然后重启。\r\n\r\n**Q: 怎么卸载?**\r\nA: `dsh plugin --profile web remove @dsh-so/dsh-plugin-advisor`,然后重启。\r\n\r\n**Q: PowerShell 报错 \"The splatting operator '@' cannot be used...\"?**\r\nA: 只发生在 **scoped 包**(`@scope/name`)上——PowerShell 把行首 `@` 当展开运算符,需要加引号:`dsh plugin --profile web add '@scope/name'`。本插件是**无前缀包**,不需要引号。\r\n\r\n**Q: 启动报 `ERR_MODULE_NOT_FOUND: Cannot find package '@dsh-so/dsh-plugin-advisor'`?**\r\nA: 有残留的安装条目(或 bundle patch 的 `name`)仍引用旧的无 scope 包名。先按包名移除再重装:`dsh plugin --profile web remove @dsh-so/dsh-plugin-advisor`,然后重新 `add`。\r\n\r\n**Q: npmjs.com 页面显示的版本比注册表旧?**\r\nA: 网页有缓存,注册表才是权威。终端验证:`npm view @dsh-so/dsh-plugin-advisor version --prefer-online`;网页硬刷新(Ctrl+F5)或稍等几分钟。\r\n\r\n**Q: 怎么查看当前安装的版本?**\r\nA: `dsh plugin --profile web list` 看 profile 的依赖;`npm view @dsh-so/dsh-plugin-advisor version` 看 npm 上的最新版。\r\n\r\n---\r\n\r\n## 9. 开发与发布\r\n\r\n```sh\r\npnpm install     # 或 npm install(peer 依赖由宿主提供,仅 devDependencies 用于本地构建/测试)\r\npnpm build       # tsc -> lib/\r\npnpm test        # node --test(匹配逻辑单测)\r\n```\r\n\r\n- 插件 bundle 声明在 `cordis.patch.yml`,`package.json` 的 `dsh.bundle.patch` 指向它。\r\n- 发布 npm 包需包含 `lib/`、`cordis.patch.yml`、`README.md`、`README.zh.md`(见 package.json `files` 字段)。\r\n\r\n---\r\n\r\n## License\r\n\r\nApache-2.0 · Copyright (c) 2026 zhoushimin\r\n","readmeFilename":"README.zh.md"}