证据快照复核于 2026-09-16GitHub 数据核对日期: 2026-08-21
证据已验证Plugin Bundle自动化与智能体deepseek-harness Profile

DSH Skills Anywhere

将本地安装和 Git 来源的 Agent Skills 共享给 DeepSeek Harness 与 MCP 客户端。

快速了解

它能做什么

将本地安装和 Git 来源的 Agent Skills 共享给 DeepSeek Harness 与 MCP 客户端。

本站提供的是中文说明,不代表该项目或 Plugin 自身提供中文界面;语言支持请以上游文档为准。

使用场景
自动化与智能体智能体Plugin 管理工作流自动化
适配技术
deepseek-harnessMCP
兼容性

deepseek-harness Profile
DeepSeek Harness 0.1.5-rc.1 and 0.1.5-rc.2; Node.js ^22.19.0 or >=24.0.0

可信度与状态

证据已验证
核对日期 2026/9/13 UTC 14:02

有代码证据的贡献

它为 DSH 增加什么

Skills Anywhere 技能提供器

将发现的智能体目录、插件市场和已配置 Git 源中的技能加入 DeepSeek Harness 技能目录,并为目录额度之外的技能提供搜索和加载工具。

机制证据
MCP 技能服务器

通过 list_skills、find_skills、open_skill 和 skill:// 资源向 MCP 客户端提供同一技能池。

机制证据
Skills Anywhere 设置卡片

在支持的 DSH Web 配置中,可查看已发现的技能并调整目录可见性和额度。

机制证据

选择前先看

这个 DeepSeek Harness 插件包新增实时技能提供器,可从其他编码智能体、Claude Code 插件市场和可选 Git 源发现技能,无需复制文件。它还可作为 MCP 服务器运行,让兼容客户端搜索和打开同一批技能。

适合谁

同时使用 DeepSeek Harness、Codex、Claude Code、Cursor 或其他 MCP 客户端技能的用户。

常见任务

  • 把其他智能体已安装的技能暴露到 DSH 技能目录中。
  • 添加经过审查的 Git 技能仓库,并在本地锁定文件中记录解析后的版本。
  • 在限制进入模型目录的技能数量时,仍让大量技能可被搜索。
  • 在浏览器、CLI 或 CI 中检查本地 SKILL.md 的解析结果。

权限与数据

读取本地技能文件;可选 Git 源会在本地克隆和刷新。

权限
  • 读取已配置的智能体技能目录和 Claude Code 插件市场目录。
  • 为已配置的 Git 源运行 Git。
  • 从 Git 源安装时,如缺少已编译文件,可能运行包的 prepare 构建。
数据处理
  • 在技能原位置读取文件,并在 DSH 主目录下缓存已配置的 Git 源。
  • 浏览器技能检查器声明提交的文件保留在浏览器中。
外部服务
  • 已配置技能源所使用的可选 Git 托管服务。
凭据
  • 未声明凭据要求;私有 Git 源可能需要你现有的 Git 访问权限。

局限

  • 其 SKILL.md 检查器是解析检查,不是安全审计,也不保证兼容所有客户端。
  • 证据仅覆盖所声明的 DSH 发布候选版本。
  • 没有 DSH 工具运行时的配置中,可选工具行会保持待处理状态。

DSHub 已核对

  • 固定来源具有已验证的 DSH 插件包补丁。
  • 清单声明兼容 DSH 0.1.5-rc.1 和 0.1.5-rc.2。
  • 该包使用 MIT 许可证。

DSHub 未核对

  • 本记录未执行安装、构建、运行行为或 MCP 客户端操作。
  • 未审计 npm 包内容。

固定版本安装

安装 DSH Skills Anywhere

这个Plugin Bundle没有 DSH Plugin 安装操作,请根据源码文档使用真实交付方式。

访问源码项目

维护者原文

项目 README

查看 commit 79d10a7 对应的 README
维护者编写的上游内容原文于 2026/9/13README.md 获取,正文和仓库相对媒体固定到 commit 79d10a7bf6da,内容哈希为 87aad1ac32b7。以下是未经 DSHub 翻译的上游原文,语言可能与当前页面不同;第三方托管的 badge 可能独立更新。

dsh-skills-anywhere

Your skills, anywhere. Install an Agent Skill once, use it in every agent: a live skill provider for DeepSeek Harness (dsh) and an MCP server for Claude Code, Cursor, Codex and friends.

English | 中文

Try the interactive Hugging Face playground — explore an example workspace, resolve name clashes, and search beyond the catalog budget. No installation or model API needed. How it works.

Bring your own SKILL.md. Compare the provider's strict and lenient parsing locally: inspect repairs, invocation settings and a downloadable check report. Your file stays in the browser. The same checks are available in the command line and CI, with file hashes and actionable exit codes. This is a parser check, not a security audit or a guarantee of compatibility with every client.

<a href="https://huggingface.co/spaces/glayguo/dsh-skills-anywhere"><img src="docs/skill-check.png" width="880" alt="Actual local SKILL.md check: strict mode rejects an invalid name, while lenient mode explains the name and description repairs."></a>

CI npm dsh plugin OpenSSF Scorecard License: MIT

Agent Skills are portable by design: a folder with a SKILL.md. Every agent still looks only in its own folder, so a skill you install for Claude Code is invisible to Codex, Cursor and DeepSeek Harness, and the ones you wrote for them are invisible back. dsh-skills-anywhere reads all of those folders where they live and serves them everywhere: as a live skill provider inside dsh, and as an MCP server for Claude Code, Cursor, Codex and any other MCP client.

<p align="center"><img src="docs/demo.gif" alt="dsh-skills-anywhere list finds skills from Claude Code, Codex, Cursor, Gemini CLI, Goose, Windsurf and Kiro, then adds anthropics/skills from GitHub" width="880"></p>

Inside dsh, it registers one extra provider on the built-in ctx.skills registry, so the model's normal skill tool and /name invocation simply see more skills:

  • Every other agent's skill directories. 60+ agents out of the box: Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, Windsurf, Kiro, Goose, OpenCode, Roo, Cline, Qwen Code, Trae and more. Project-level and user-level.
  • Claude Code plugin marketplaces. The skills nested inside ~/.claude/plugins/marketplaces/*/plugins/*/skills/*, including the official Anthropic marketplace.
  • Any git repository full of skills. Point at anthropics/skills, a sub-directory, a branch, a tag, or a commit. It is shallow-cloned into a local cache, refreshed in the background, and pinned in a lock file.
  • Zero copies, zero symlinks. Files are read where they live and re-read on every load. Edit a skill in Cursor and dsh sees the change. Nothing to import, nothing to keep in sync.

Hundreds of skills would bloat every model request, so the provider keeps a catalog budget: at most 50 skills enter the model's session catalog by default, and the rest stay one find_skills call away through two small tools the plugin adds, with /name invocation untouched.

The same pool is available outside dsh too: dsh-skills-anywhere mcp serves it to any MCP client (Claude Code, Cursor, Codex, Windsurf…) as find_skills / open_skill tools and skill:// resources, so one install of a skill reaches every agent you use.

It also deduplicates symlinked and byte-identical installs (the skills CLI links one canonical copy into several agents), repairs common frontmatter drift instead of silently dropping a skill, and renames colliding names (discord/configure vs telegram/configure) so every skill stays reachable. A small CLI shows you exactly what dsh will see and why.

Quick start

# 1. Install into the dsh profile you use (web is the default UI profile)
dsh plugin --profile web add dsh-skills-anywhere

# 2. See what the model will get, without booting dsh
npx dsh-skills-anywhere list

# 3. Add a whole repository of skills
npx dsh-skills-anywhere add anthropics/skills

Published on npm with build provenance; every GitHub release also carries the same tarball.

Start dsh as usual. The skill catalog now includes everything above; load a skill with the skill tool or /skill-name exactly as before.

On a machine with only Claude Code installed, list already finds the 31 skills inside the official plugin marketplace, none of which dsh sees on its own:

$ npx dsh-skills-anywhere list
NAME                 FROM                                                    PATH
discord-access       claude plugin discord @ claude-plugins-official         ~/.claude/plugins/marketplaces/.../discord/skills/access/SKILL.md
frontend-design      claude plugin frontend-design @ claude-plugins-official ~/.claude/plugins/marketplaces/.../frontend-design/skills/frontend-design/SKILL.md
skill-creator        claude plugin skill-creator @ claude-plugins-official   ~/.claude/plugins/marketplaces/.../skill-creator/skills/skill-creator/SKILL.md
...
31 skills, 6 renamed — run `dsh-skills-anywhere doctor` for details
<details> <summary>Install from a git checkout or a release tarball instead of npm</summary>

Every GitHub release carries a prebuilt tarball, and both dsh plugin add and npx accept its URL directly (https://github.com/noteflowai/dsh-skills-anywhere/releases/download/v0.6.0/dsh-skills-anywhere-0.6.0.tgz). If you want an unreleased commit:

dsh plugin --profile web add github:noteflowai/dsh-skills-anywhere

A git install ships sources, so pnpm has to run this package's prepare build. pnpm 10+ refuses until you allow it: the first add fails and prints the exact key to allow. Copy that key (it includes the commit) into the profile's pnpm-workspace.yaml and run the add again.

# $DSH_HOME/profiles/web/pnpm-workspace.yaml
allowBuilds:
  'dsh-skills-anywhere@https://codeload.github.com/noteflowai/dsh-skills-anywhere/tar.gz/<sha>': true

Pin a commit (github:noteflowai/dsh-skills-anywhere#<sha>) if you want the install to be reproducible.

</details><details> <summary>Requirements</summary>
  • DeepSeek Harness 0.1.5-rc.1 or newer (the suite runs against 0.1.5-rc.1 and 0.1.5-rc.2), any profile that mounts @deepseek-ai/dsh-skill (the shipped web, acp, headless and sdk profiles all do)
  • Node.js 22.19+ or 24+
  • git on PATH for git sources (everything else works without it)
</details>

What gets discovered

Where Example dsh source label Default rank
Another agent's project skills <project>/.claude/skills/* anywhere-project 250
Another agent's user skills ~/.codex/skills/*, ~/.cursor/skills/* anywhere-user 550
Claude Code plugin marketplaces and the installed-plugin cache ~/.claude/plugins/marketplaces/*/plugins/*/skills/* anywhere-claude-plugins 580
Git sources anthropics/skills, vercel-labs/agent-skills/skills anywhere-source 700

Lower rank wins a duplicate name inside the dsh registry. The built-in dsh roots keep their ranks (.dsh/skills 100, .agents/skills 200, ~/.dsh/skills 400, ~/.agents/skills 500), so a skill you wrote for dsh always beats the same name found elsewhere. .agents/skills and .dsh/skills are deliberately not re-scanned here.

Run npx dsh-skills-anywhere agents for the full agent table and which directories exist on your machine.

Skill format

Any directory with a SKILL.md following the Agent Skills specification, plus dsh's flat <name>.md form. name, description, license, compatibility, allowed-tools, metadata, and dsh's disable-model-invocation / user-invocable are all understood. Unknown frontmatter (Claude Code's argument-hint, context, ...) is preserved under metadata.frontmatter. scripts/, references/ and assets/ are exposed through the skill's resource directory like any dsh skill.

In the default lenient mode a missing name falls back to the directory, an invalid name is normalised to kebab-case, and a missing description is derived from the first paragraph. Each repair is recorded and shown by doctor. Set lenient: false to match the strict behaviour of the built-in provider.

Git sources

npx dsh-skills-anywhere add anthropics/skills                      # default branch
npx dsh-skills-anywhere add anthropics/skills@v1.0.0               # tag or branch
npx dsh-skills-anywhere add vercel-labs/agent-skills/skills        # sub-directory
npx dsh-skills-anywhere add https://github.com/o/r/tree/main/dir   # GitHub tree URL
npx dsh-skills-anywhere add git@gitlab.com:group/skills.git        # any git URL
npx dsh-skills-anywhere add ./local/skills-repo --project          # local repo, project-scoped
npx dsh-skills-anywhere add o/r --ref 3f2a9c1 --rank 300           # pin a commit, set precedence

Sources come from three places, merged in this order: the plugin config.sources, the user file ~/.dsh/skills-anywhere/sources.json, and the project file <project>/.dsh/skills-anywhere.json (commit it to share skills with your team). The CLI edits the last two.

Each repository is shallow-cloned once into ~/.dsh/skills-anywhere/cache/<host>/<owner>/<repo> (<repo>@<ref> when a branch, tag or commit is set, so several refs of one repository never share a checkout) and refreshed when dsh starts, every syncIntervalMs (6 hours by default), and whenever a sources file changes. The resolved commit of every source is written to ~/.dsh/skills-anywhere/lock.json. Discovery only ever reads the cache, so a failed refresh means yesterday's skills, never an empty catalog. The catalog is invalidated as soon as a refresh brings changes; dsh never waits on the network.

Catalog budget and the find_skills / open_skill tools

dsh publishes every model-invocable skill's name and description into the session, on every request. With marketplaces and a few git sources that is hundreds of lines of context. The provider therefore ranks its skills and marks only the first catalog.limit (default 50) as model-invocable; the remainder is published with model invocation off, which keeps it out of the catalog but still loadable by you with /name.

Two tools, registered by the dsh-skills-anywhere/tools row, make the hidden part reachable for the model:

  • find_skills(query, limit?) searches every skill by keyword (name, description, whenToUse, origin), catalog or not, and says which matches are listed.
  • open_skill(name) loads any skill by exact name, including ones the budget hid. Skills whose own frontmatter says disable-model-invocation: true are still refused, exactly as the built-in skill tool does.
- id: skills-anywhere
  config:
    catalog:
      limit: 30                       # 0 = unlimited (old behaviour)
      pin: [frontend-design]          # always listed
      hide: [example-skill]           # never listed, still searchable and /name-invocable
- id: skills-anywhere-tools
  config:
    findLimit: 10

Author-disabled skills never count against the budget. Which skills stay listed follows the precedence order below, so project-level skills win over user-level, which win over marketplaces and git sources. The tools row needs the tool runtime (ctx.tools); in a profile without one it stays pending and the provider works alone.

CLI

Check before committing. Run npx -y dsh-skills-anywhere@0.6.0 check skills/example/SKILL.md --fail-on-repair. The same parser used in the playground now has batch file checks, JSON reports with file hashes, and CI exit codes. Checks read only the named files. Commands, CI example and scope.

dsh-skills-anywhere list [--all] [--json]     Skills the provider publishes (--all shows hidden duplicates)
dsh-skills-anywhere agents [--json]           Supported agents and which directories exist here
dsh-skills-anywhere sources [--json]          Configured git sources and their synced commits
dsh-skills-anywhere add <source> [--ref] [--path] [--rank] [--project]
dsh-skills-anywhere remove <source> [--project]
dsh-skills-anywhere sync [--force] [--json]   Clone or refresh every source now
dsh-skills-anywhere doctor [--json]           Repaired, skipped, renamed and duplicate skills, with reasons
dsh-skills-anywhere check <files...> [--json] Explicit local files; strict parser gate by default
dsh-skills-anywhere mcp                       Serve the same skills to any MCP client over stdio

All commands accept --cwd <dir>. For check, it resolves the named files; other commands use it to pick the project. check --lenient accepts provider repairs; --fail-on-repair rejects any reported repair in the selected mode. The CLI uses the same parsing code as the plugin and never needs dsh running.

Use as an MCP server

Skills are not a dsh-only idea, and neither is this provider. dsh-skills-anywhere mcp starts a Model Context Protocol server over stdio that exposes the identical pool (agent directories, Claude Code marketplaces, git sources, same dedupe and rename rules) to any MCP client:

Tool What it does
list_skills Browse every model-invocable skill with its description and origin (limit, offset)
find_skills Keyword search across names, descriptions and origins
open_skill Load one skill's instructions plus the directory its scripts and references live in

Skills are also exposed as skill://<name> resources (with completion), for clients that let you @-mention resources. Skills whose frontmatter sets disable-model-invocation: true are never listed or opened. The server needs no dsh installation at all.

Claude Code (as a plugin; this repo doubles as a plugin marketplace)

claude plugin marketplace add noteflowai/dsh-skills-anywhere
claude plugin install dsh-skills-anywhere@noteflowai

Or register the bare server instead: claude mcp add skills-anywhere -- npx -y dsh-skills-anywhere mcp. Either way, restart Claude Code once so it connects.

Cursor (.cursor/mcp.json or ~/.cursor/mcp.json)

{ "mcpServers": { "skills-anywhere": { "command": "npx", "args": ["-y", "dsh-skills-anywhere", "mcp"] } } }

Codex (~/.codex/config.toml)

[mcp_servers.skills-anywhere]
command = "npx"
args = ["-y", "dsh-skills-anywhere", "mcp"]

The server is also listed in the official MCP registry as io.github.noteflowai/dsh-skills-anywhere, so registry-aware clients can install it by name. The repository is also an Agent Plugin (plugin.json + mcp.json at the root), so Cursor and other open-plugin clients can install it from the repository URL. Add --cwd <dir> when the client does not start the server inside the project you are working on. Git sources sync in the background on start, exactly as in dsh. Programmatic use: import { createSkillsAnywhereServer } from 'dsh-skills-anywhere/mcp' returns the McpServer and the provider so you can attach your own transport.

Browse and toggle skills in the dsh web UI

In dsh web, open Settings → Plugins → Plugin configuration. The Skills Anywhere card lists every skill the provider found, grouped by where it lives (agent directories, Claude Code plugins, git sources), with its catalog state — listed for the model, not listed (kept out by the budget or by you) or author disabled — and the name it was renamed to when it collided. Each row offers Pin (always listed), Hide (out of the model catalog, still /name- and find_skills-reachable) and Exclude (dropped from the provider); the catalog budget is editable in place, and a filter box searches names, descriptions and origins.

<p align="center"><img src="docs/web-card.png" alt="The Skills Anywhere card in dsh web settings: skills grouped by origin with listed / not listed / author disabled states, renames, and Pin, Hide, Exclude actions" width="720"></p>

Edits are written to the profile's dsh settings document as the skills-anywhere namespace, layered over catalog and excludeSkills from cordis.patch.yml, and the model catalog follows immediately: no restart, no file editing. The card only appears in profiles that mount dsh's settings service and web server (the shipped web profile does); everywhere else the provider behaves exactly as composed.

Configuration

Override the row in your profile's cordis.patch.yml. A patch replaces the whole config block, so restate every key you care about:

- id: skills-anywhere
  config:
    agents: true
    excludeAgents: [openclaw]
    claudePlugins: true
    sources:
      - anthropics/skills
      - { repo: vercel-labs/agent-skills, path: skills, ref: main, rank: 650 }
    excludeSkills: [example-skill]
Field Default Meaning
providerName skills-anywhere Provider name on ctx.skills
agents true Scan other agents' skill directories
excludeAgents [] Agent ids to skip (see agents command)
extraProjectDirs [] Additional project-relative skill directories
extraUserDirs [] Additional absolute or ~/ skill directories
claudePlugins true Scan Claude Code plugin marketplaces and cache
sources [] Git sources: strings or { repo, ref?, path?, rank? }
sourcesFiles true Also read the user and project sources.json files
cacheDir ~/.dsh/skills-anywhere/cache Where sources are checked out
sync true Clone and refresh git sources at all
syncOnStart true Refresh when the plugin starts and on first use of a project
syncIntervalMs 21600000 Background refresh interval; 0 disables
syncTimeoutMs 120000 Per-git-command timeout
maxDepth 5 Directory depth walked inside sources and marketplaces
dedupe true Collapse symlinked and byte-identical duplicates
lenient true Repair recoverable frontmatter instead of skipping
watch true Watch local roots and refresh the catalog on change
excludeSkills [] Skill names to hide (raw frontmatter name or the published name shown by list); editable at runtime from the web card
ranks { project: 250, user: 550, claudePlugins: 580, sources: 700 } Precedence per group
catalog.limit 50 Skills from this provider listed in the model catalog; 0 = unlimited
catalog.pin [] Names always listed
catalog.hide [] Names never listed (still /name-invocable and searchable)
dshHome, home $DSH_HOME / ~ Path roots, mainly for tests

The dsh-skills-anywhere/tools row accepts findLimit (default 10), findMaxLimit (50), and find / open booleans to register only one tool.

How precedence and duplicates work

  1. Roots are scanned in rank order. Within one rank, the agent table order, then path.
  2. Entries pointing at the same file (symlinks) collapse to the first. Entries with the same name and byte-identical body collapse to the first. Both appear in doctor as hidden duplicates.
  3. Entries that still share a name but differ are all kept. If one of them is yours (an agent directory) it keeps the bare name and the others are prefixed with their plugin, repository, or agent (telegram-configure). If every member comes from a marketplace or a git source, all of them are prefixed, so you get discord-access and telegram-access rather than a meaningless bare access. doctor lists the renames.
  4. The dsh registry then merges this provider's candidates with the built-in ones by rank.

Security notes

  • The plugin reads skill files. It never writes to your agent directories.
  • Git sources run git on your machine at plugin start and on the refresh interval. Pin a commit for anything you do not fully trust, and review lock.json.
  • A skill is instructions the model will follow. Adding a source is a trust decision, exactly like installing a plugin.
  • Skills are read with Node's filesystem API, not through dsh's sandboxed ctx.fs; the built-in provider does the same for its bundled root.

Development

pnpm install
pnpm run check        # typecheck + lint + tests + build
pnpm pack             # tarball for `dsh plugin --profile <name> add ./dsh-skills-anywhere-*.tgz`

Tests run against the real @deepseek-ai/dsh-skill registry and real git repositories in temp directories.

Contributing

Issues and pull requests are welcome. Adding an agent is a one-line change in src/agents.ts. See CONTRIBUTING.md.

License

MIT © Note Flow AI

有意识地管理

安装与管理

前置条件与目标 Profile

目标 deepseek-harness Profile

交付方式 Git Bundle — noteflowai/dsh-skills-anywhere#79d10a7bf6da219bf2b67ca7ea444530acd5ea07

验证、更新与移除

显示生命周期命令
验证
dsh plugin --profile deepseek-harness list

兼容性与访问范围

Compatible with declared DSH 0.1.5 release candidates DeepSeek Harness 0.1.5-rc.1 and 0.1.5-rc.2; Node.js ^22.19.0 or >=24.0.0

检查兼容性证据

风险事实

filesystem-access

Reads local skill directories and skill files outside the DSH sandbox.

证据
network-and-process

Configured Git sources run Git locally during refresh and are cached on disk.

证据
lifecycle-script

A Git-source installation can run the package prepare build when compiled files are unavailable.

证据
证据与编辑审查Manifest、Bundle patch、分发与新鲜度

不可变证据

审查状态与源码活动

AI 已审查

添加任何 Git 技能源前请先审查:技能会成为模型遵循的指令,且配置的源会在刷新时运行 Git。

AI 审查于 2026/9/13 UTC 14:03GitHub 事实核对日期: 2026/9/13 UTC 14:03

自当前证据基线以来,没有记录到重要源码变化。

下一步

按 Plugin 安装流程操作

订阅重要变化: DSH Skills Anywhere