편집자 노트

xiaoheizi1212/dsh-computer-use

Model-agnostic Computer Use for DeepSeek Harness: isolated browser, Windows native helper, third-party vision perception, and a Chrome Cookie Bridge.

이것은 DeepSeek Harness(DSH) 플러그인입니다. 이 사이트는 GitHub README, 설치 정보, 유지보수 상태, 공개 보안 시그널을 모아 보여줍니다.

업스트림에서 중국어 README를 제공하지 않아 저장소 원본 내용을 표시합니다.

dsh-computer-use

Model-agnostic Computer Use capability for DeepSeek Harness: an isolated browser, a Windows native helper, provider-neutral observation, a Chrome Cookie Bridge for importing your logged-in sessions, and a text planner (DeepSeek) plus a third-party vision model for perception.

Platform & License

  • License: MIT — open source, free to use, modify, and redistribute.
  • Platform: the windows provider's native helper is Windows-only; the playwright browser provider and everything else are cross-platform.
  • macOS: not currently developed — the author has no macOS environment. Developers are welcome to contribute a macOS version.

Credits

1st version — created using DeepSeek-V4-Pro-0813 with DeepSeek Harness.

Token usage: 223,443,625 tokens · 99% cache hit rate.

What it provides

  • A capability seam ctx.computerUse (start / listTargets / observe / act / stop).
  • Six model-facing tools: computer_observe, computer_act, computer_stop, computer_take_over, computer_resume, computer_perceive.
  • Three providers behind one seam: fake (deterministic tests), playwright (isolated Chromium), windows (native helper).
  • A perception layer: accessibility mode (no image) and analyze mode (screenshot → third-party vision model → structured result).
  • Risk-classified, fail-closed approval + domain allowlist + a full computer/* replayable session log.

Required plugins (harness dependencies)

PackageWhy
@deepseek-ai/dsh-llm-pi-aiHosts the third-party vision route (declares input:['text','image'])
@deepseek-ai/dsh-llmThe image content block and createUserMessage
@deepseek-ai/dsh-attachment (+ -local)Persists screenshots as content-addressed refs
@deepseek-ai/dsh-credentials (+ -local)Resolves the vision API key per request
@deepseek-ai/dsh-user-approvalOne-shot fail-closed action approval
@deepseek-ai/dsh-tools / -session / -system-promptTool registry, session log, guidance

@deepseek-ai/dsh-llm-deepseek is text-only and cannot be the vision model — it is the planner.

Configuration

All options live on the dsh-computer-use/plugin row (config:), for example in your profile's cordis.patch.yml:

- id: computer-use
  name: dsh-computer-use/plugin
  config:
    provider: playwright
    visionProvider: xiaomi
    visionModel: mimo-v2.5

You can also flip the whole capability on/off live from the DeepSeek Harness GUI — the plugin registers a computer-use settings section (Settings → computer-use), so enabled, provider, and the browser/import options above are editable without editing YAML.

Core

OptionDefaultMeaning
enabledtrueMaster toggle — false turns the whole capability off
providerfakeBackend: fake (tests) | playwright (browser) | windows (desktop)
toolstrueRegister the model-facing tools
confirmActionstrueOne-shot confirmation before risky computer_act calls
visionProvider / visionModelllm-pi-ai route + model used by computer_perceive analyze
visionMaxTokens2000Vision output token cap
allowedDomains[]Hostnames the browser may act inside (empty = no restriction)
windowsHelperCommand''Native helper executable (defaults to the bundled lib/native/win32-x64/dsh-computer-use-helper.exe)

Browser (Playwright) session

OptionDefaultMeaning
browserHeadlesstrueHeadless (default) or a visible window. false = 正常模式(弹窗)
browserWindowStatenormalVisible-window state: normal | maximized | minimized(先 launch、后应用状态)
reuseBrowserProfilefalseUse a persistent (dedicated) browser profile instead of an isolated context
browserUserDataDirPersistent profile's "User Data" ROOT dir (non-default; e.g. ~/.dsh/browser-profiles/main)
browserProfileNameDefaultProfile directory name inside browserUserDataDir
importCookiesfalseImport cookies so the isolated browser shares the user's logins
importPasswordsfalseImport saved passwords for autofill
importHistoryfalseImport browsing history as injected context
cookiesFilePlaywright storage-state JSON ({ "cookies": [...] }) loaded when importCookies
passwordManagerCsvPassword-manager CSV export (name,url,username,password) when importPasswords

Windows (desktop) provider

OptionDefaultMeaning
windowsWindowStatenormalTarget-window state: normal | maximized | minimized(minimized = 先激活后最小化)

Scripting: import cookies / passwords / history

The browser starts isolated (no cookies, no profile) by default. To give it your logged-in state:

A. Cookie Bridge (recommended — works with Chrome 127+ App-Bound Encryption)

Chrome 127+ encrypts cookies with App-Bound Encryption, so a separate process cannot read your existing profile's cookies. The Cookie Bridge sidesteps this by running inside Chrome: a small extension reads cookies via chrome.cookies (plaintext — Chrome decrypts them itself) and POSTs them to a local receiver.

# 1. Install the companion extension ONCE (see github.com/xiaoheizi1212/dsh-cookie-bridge):
#    chrome://extensions → Developer mode → "Load unpacked" → the extension folder.
# 2. Start the receiver:
pnpm exec tsx scripts/import-cookies-server.ts
# 3. Either click the extension icon and pick a domain, or drive it from the agent:
pnpm exec tsx scripts/request-cookies.ts all x.com,xiaohongshu.com

Then point the plugin at the saved cookies.json:

- id: computer-use
  config:
    provider: playwright
    importCookies: true
    cookiesFile: "C:/path/to/dsh-computer-use/cookies.json"

Cookie values only travel from Chrome to 127.0.0.1 (never to a remote host), and only the cookies for the domains you pick are exported. Multiple exports merge (deduped by domain|path|name).

B. Dedicated browser profile (log in once manually)

Use a plugin-owned, non-default profile. Chrome refuses remote debugging on its real User Data dir, and copying a profile does not carry App-Bound cookies, so the supported path is a fresh dedicated profile where you log in once:

- id: computer-use
  config:
    provider: playwright
    reuseBrowserProfile: true
    browserUserDataDir: "C:/Users/you/.dsh/browser-profiles/main"
    browserProfileName: "Default"
    browserHeadless: false   # visible window so you can log in

⚠️ Reusing your existing Chrome profile is NOT supported: Chrome 127+ App-Bound Encryption + the "no remote debugging on the default data dir" restriction are designed to block it.

Passwords / history (reserved)

  • PasswordsimportPasswords: true expects a passwordManagerCsv export (name,url,username,password); reserved switch, wire your own autofill bridge first.
  • HistoryimportHistory: true is a reserved switch; inject the top visited origins as model context in your own adapter.

Every import weakens isolation. Import only what the task needs, and never enable import while the allowedDomains list is empty.

Vision model

Recommended default: qwen2.5-vl-72b-instruct over an OpenAI-compatible gateway (self-hosted vLLM, DashScope, OpenRouter). Alternatives: gpt-4o-mini, glm-4v-flash, llava-v1.6-34b, internvl2-76b, mimo-v2.5.

Configure the vision route in your profile's settings.yaml (or the base llm-pi-ai section):

llm-pi-ai:
  providers:
    vision:
      apiKeyEnv: VISION_API_KEY
      api: openai-completions
      baseURL: https://your-vision-endpoint/v1
      defaultInput: [text, image]
      models:
        - id: qwen2.5-vl-72b-instruct
          contextWindow: 131072
          input: [text, image]

pi-ai does not verify modality declarations: a model declared image-capable but that is not will fail mid-turn after the message is durable. Verify the chosen model actually accepts images before committing it.

Install & load

dsh plugin --profile web add dsh-computer-use
npx playwright install chromium   # once, for the playwright provider

The bundle's cordis.patch.yml mounts ctx.computerUse (package root) and the tool/provider plugin (dsh-computer-use/plugin, provider fake). Override provider in your profile patch to select playwright or windows.

Providers

  • fake — deterministic in-memory provider for contract tests and keyless demos.
  • playwright — isolated Chromium: observe (screenshot → ctx.attachments + accessibility tree with short-lived element ids) and act (click-element / click-coordinate / type-text / press-key / scroll / drag / set-value / activate-target). Headless by default; headed + window-state via browserHeadless / browserWindowState.
  • windows — a thin adapter over the native-helper protocol (src/native/*); the self-contained helper (dsh-computer-use-helper.exe, UI Automation + Windows.Graphics.Capture + SendInput) is built by pnpm build. Target window state via windowsWindowState.

Policy

  • Actions are risk-classified deterministically by type, never by page content: scroll / activate-targetread (no confirmation); type-text / set-value / draglocal; click-* / press-keyexternal (one-shot confirmation). destructive / financial / auth are domain/policy determinations deferred to the Harness permission extension.
  • allowedDomains restricts the Playwright provider to acting only inside the listed hostnames; an out-of-allowlist target fails with TARGET_NOT_ALLOWED.
  • Prompt-injection boundary: the classifier and the allowlist never read page text, accessibility names, or screenshot content, so untrusted page content cannot grant permission.

Development

pnpm install
pnpm build      # tsdown bundles src into lib/ + dotnet publish the native helper into lib/native/win32-x64
pnpm test       # keyless contract tests (fake/framing/transport/windows/perception) + Playwright (needs Chromium)
pnpm typecheck

Source uses explicit .ts import specifiers (harness convention); tsdown rewrites them to .js.

Documentation

  • Protocol — the versioned native-helper wire protocol (framing, handshake, methods, screenshot channel).
  • Security — threat model and safety invariants.
  • Provider authoring — how to add a provider to the ctx.computerUse seam.

License

MIT

REPOSITORY SIGNALS

보안 및 설치 증거

이 점수는 공개 저장소 메타데이터와 이 사이트에 등록된 설치 증거에만 기반하며, 코드 보안 감사와 다릅니다.

출처 추적 가능

공개 플러그인 카탈로그에서 왔으며, 공개 GitHub 저장소로 연결됩니다.

라이선스

저장소가 MIT 라이선스를 선언했습니다.

유지보수 활동

최근 180일 내 코드 업데이트가 있습니다.

설치 증거

재현 가능한 정확한 설치 메타데이터가 아직 등록되지 않았습니다. 저장소 설명에 따라 직접 확인하세요.

설치 라이프사이클 스크립트

검사한 패키지 메타데이터에 설치 라이프사이클 스크립트가 선언되지 않았습니다.