dsh-db-tool
Manifest validChat-operated multi-database admin plugin for DeepSeek Harness: query and manage MySQL, PostgreSQL, GaussDB, MongoDB, Redis, Oracle, DM and SQLite from the conversation with project-scoped ro/rw grant
dsh-db-tool
English | 简体中文
DSH 社区插件:在聊天中安全操作数据库,配套侧边栏管理台与 db-admin skill。架构与交互模式对齐 dsh-ssh-tunnel。
功能
- 8 种数据库:MySQL、PostgreSQL、GaussDB、SQLite、Redis、MongoDB、Oracle、达梦(DM)
- DatabaseManager 单工具多 action:
list_connections / query / execute / schema / preview / run_script(run_script在 node:vm 沙箱中执行,60s 超时,仅注入受限db.{query,execute}句柄) - 分级权限:连接级只读(ro)/读写(rw)+ 项目级授权(
grants.json:projectPathKey → 连接 → 模式);未授权项目一律拒绝 - 危险操作确认:DDL / FLUSHALL / dropDatabase 等先返回
NEEDS_CONFIRMATION,对话内(模型经 ask)或 SQL 控制台(弹窗)确认后携一次性challengeId(绑定语句 SHA256、5 分钟过期)重试 - 审计:全部执行落
audit.jsonl(语句、危险级、是否确认、结果) - 侧边栏 4 面板(dsh-better-sidebar,zh/en):连接管理、项目授权、数据浏览、SQL 控制台
- db-admin skill:随插件分发,覆盖 8 库方言速查、安全规范、确认流程
数据布局
$DSH_HOME/db-tool/(0700):
| 文件 | 内容 |
|---|---|
connections.json | 连接定义(urlSafe 中密码脱敏为 ***) |
secrets.json | 0600,密码/URL 凭据,永不返回给模型 |
grants.json | 项目授权(归一化路径 → connId → ro/rw) |
audit.jsonl | 追加式审计日志 |
安装
8 种数据库驱动全部随 npm 包分发(SQLite 优先用 Node 内置 node:sqlite,可选 better-sqlite3;GaussDB 驱动为华为云官方 npm 包 gaussdb-node),无需任何构建步骤。GaussDB 认证支持 sha256 与 md5,md5-sha256 混合与 SM3 暂不支持。
唯一的一次性交互来自 oracledb:其 install 脚本会被 pnpm 默认拦截并使首次安装报告失败——在 DSH 插件安装界面点 "Allow these scripts and retry" 即可完成安装(该脚本仅做 Node 版本检查与横幅打印,批准无风险;批准持久化到 profile,后续升级不再提示)。
# npm(推荐)
dsh plugin --profile web add dsh-db-tool
# GitHub 源码
dsh plugin --profile web add "dsh-db-tool@github:mengqi1436/dsh-db-tool"
# 本地开发
dsh plugin --profile web add "link:E:\path\to\dsh-db-tool"
桌面端安装
DSH 桌面端 0.2.0-rc.2+ 捆绑了 dsh 命令,全程无需另装 Node 或 pnpm:
-
首次使用:打开桌面端菜单栏,点 "Manage dsh command"(管理 dsh 命令),安装捆绑的 CLI——该操作把
dsh命令注册到系统 PATH。 -
安装插件(必须钉精确版本:
@latest会因 release-age 校验回落到旧版):dsh plugin --profile desktop add dsh-db-tool@1.4.0 --registry=https://registry.npmjs.org/已有 npm 镜像源偏好的用户,可把
--registry替换为自己的镜像地址。 -
重启桌面端生效。
mongodb 驱动已 bundle 进发布包(vendor/mongodb-driver.cjs),依赖树不含 mongodb/punycode——桌面端宿主打包在 app.asar 内、无法应用宿主补丁,本插件免补丁可直接安装加载。
测试
npm test # 离线 mock 全量(含 e2e-mock 全链路与对抗用例)
npx tsc --noEmit
npx stryker run # 变异测试(范围 lib/guard + lib/manager + lib/store,报告 reports/mutation/)
真机冒烟(设了才跑):DBT_TEST_MYSQL_URL / DBT_TEST_PG_URL / DBT_TEST_REDIS_URL / DBT_TEST_DM_CONNECT / DBT_TEST_MONGO_URL / DBT_TEST_ORACLE_CONNECT。GaussDB 与 Oracle/Mongo 官方要求均按官方文档实现,未真机验证处以代码内标注为准。
目录结构
lib/ host 插件(store / adapters×8 / guard / manager / http / index)
client/ 侧边栏单文件产物(client.js,即源码)
skills/ db-admin skill
scripts/ 构建与工具脚本(mongodb 驱动 bundle、DSH 宿主热修复 patch:dsh 等)
patches/ DSH 宿主 dsh-app-boot 热修复补丁(patch:dsh 按宿主版本选用)
docs/ 预留(当前为空)
tests/ vitest(离线 mock + DBT_TEST_* 门控真机)
vendor/ mongodb-driver.cjs bundle(gitignore,发布经 files 白名单收录)
许可证
MIT
Comments
Loading…
Similar plugins
Database connections and SQL for DeepSeek Harness: register data sources, browse and comment schemas, run AST-checked SQL with a per-source read-only toggle, and render bar, line and pie charts, from
★ 0
dsh plugin --profile web add @tomowang/dsh-data-agentby JohnXu22786
Safe, audited SQLite/PostgreSQL/MySQL access for dsh agents: schema introspection, enforced read-only queries, a write approval gate, and a durable JSONL SQL audit trail.
★ 1
↓ 107/wk
MIT
TypeScript
Sep 29, 2026
dsh plugin --profile web add dsh-db-connectorby 1321928757
MySQL connector plugin for DeepSeek Harness: configure connections in settings, switch per session from the composer, and expose mysql_query/mysql_tables/mysql_execute tools to every agent preset.
★ 7
↓ 17/wk
MIT
JavaScript
Sep 6, 2026
dsh plugin --profile web add dsh-mysqlby STARDUSTLC666
DeepSeek Harness 工程师级数据库插件:sql_list/query/exec/schema/stats/health 六工具,SQLite/MySQL/PostgreSQL 三引擎、词法级只读保护、写审批门、行数钳制、CSV/JSON 查询输出。· Databases for DeepSeek Harness agents. 已验证兼容 DeepSeek Harness v0.1.
★ 8
↓ 350/wk
MIT
JavaScript
Oct 3, 2026
dsh plugin --profile web add dsh-sqlA DeepSeek Harness plugin that interviews the user about a project, generates a project timeline / Gantt chart, and exports it as Word or Excel.
★ 0
dsh plugin --profile web add dsh-plugin-project-managementby shengsheng90
Native local Taskboard plugin for DeepSeek Harness. SQLite-backed projects, Agent claim/review, and a native Web UI — no iframe, no second chat runtime.
★ 330
↓ 380/wk
Apache-2.0
TypeScript
Sep 30, 2026
dsh plugin --profile web add @shengsheng/dsh-taskboard