npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-channel-telegram

v0.5.0

Published

Telegram, QQ Official Bot, and experimental WeChat iLink Host plugin for DeepSeek Harness

Readme

dsh-channel-telegram

Cordis Host composition plugin for Telegram, QQ, and experimental WeChat iLink channels. Version 0.5.0 requires DSH 0.1.2-rc.1 or newer.

Full configuration guides and sanitized DSH Web screenshots: English | 简体中文

Install

The 0.5.0 release contains Telegram, QQ, the experimental WeChat transport, and DSH 0.1.2 compatibility. Publish npm packages in dependency order: @wsxcant/[email protected], @wsxcant/[email protected], @wsxcant/[email protected], then [email protected], before installing this package from the registry:

dsh plugin --profile web add [email protected]

For source-checkout verification, link the profile dependency to this package and rebuild the workspace. The DSH plugin manager installs a published package and adds its bundled composition patch to the profile. Restart the active DSH Web Host, then configure Telegram, QQ, and experimental WeChat under Settings > Plugins.

Example composition row:

- name: dsh-channel-telegram
  config:
    allowedUserIds: []
    hostName: Local DSH
    turnTimeoutMs: 600000
    progressEditIntervalMs: 1000
    diagnosticLogging: false
    qqAppId: ""
    qqAllowedOpenIds: []
    qqProgressIntervalMs: 3000
    qqOpenIdLookupEnabled: false
    wechatAllowedUserIds: []
    wechatIdentityLookupEnabled: false

Web settings

Open DSH Settings and select Plugins. The Telegram card manages:

  • Bot Token, stored only by DSH Credentials under the fixed reference TELEGRAM_BOT_TOKEN. The browser can read configured/source/writable status, but the stored value is never returned or rendered.
  • Allowed Telegram user IDs, stored in the Host telegram settings namespace. IDs must be unique positive safe integers.
  • Current host name, stored in the same namespace. It is trimmed, limited to 64 characters, and shown in the Telegram Computers menu. The computer ID remains local.

The composition values are defaults for host name and user IDs. Saved Web settings override those defaults and survive profile reload. Credential and settings updates serialize a Telegram runtime restart. With no Bot Token or no allowed user ID, Telegram remains available for configuration but does not poll.

QQ C2C

The QQ card manages a QQ Official Bot API v2 C2C channel. It stores AppID, allowed QQ user OpenIDs, and stage-message interval in the Host qq namespace. AppID is limited to 64 characters; OpenIDs are trimmed, deduplicated, and limited to 128 characters; the stage interval is an integer from 1000 to 60000 ms. The AppSecret is write-only DSH Credentials under QQ_BOT_APP_SECRET; its stored value is never returned to the browser. The QQ runtime does not start until AppID, AppSecret, and at least one allowed OpenID are present. A normal QQ number is not a user OpenID. To bootstrap the allowlist, temporarily enable Allow /openid identity lookup, send /openid in C2C, save the returned value as an allowed OpenID, and disable the lookup again. While enabled, only /openid replies before authorization; it never invokes DSH.

QQ v1 is C2C only. It obtains and refreshes access tokens server-side, uses the official Gateway with the C2C message and interaction intents, resumes processed event sequences after reconnect, and de-duplicates messages and button callbacks. Menus prefer native QQ keyboards and fall back to numbered text when the API rejects a keyboard. The C2C_MESSAGE_CREATE OpenID must appear in the allowlist before any DSH action is performed. QQ C2C input uses msg_type: 6. Unlike Telegram, QQ does not continuously edit one progress message: current-stage progress is sent as separate text messages throttled by qqProgressIntervalMs, and the final result is sent as another message. QQ emits only the turn process node; tool names, tool results, and repeated Working... notices are omitted. This is an expected Telegram/QQ transport difference.

Experimental WeChat iLink

The WeChat card supports QR login, scanned/verification/online/expired/error states, logout, allowlisted iLink user IDs, and a default-off /userid bootstrap command. Its DSH-native transport adapts Tencent @tencent-weixin/[email protected] QR login, iLink API, monitor, session guard, config cache, lifecycle notifications, and cursor handling; it does not embed the OpenClaw plugin runtime. Credentials, cursor, context tokens, and typing state are serialized under the fixed write-only DSH credential ref DSH_CHANNEL_TELEGRAM_WECHAT_ILINK. The browser receives only a Host-generated QR image and public account/status metadata; raw QR URLs, verification codes, and tokens are not written to ordinary settings.

The private-chat channel reuses the shared DSH control plane and archived-session filtering. It sends typing status, one turn-start process node, and the final answer. Group chat and button menus are outside V1. Telegram and WeChat accept one inbound image or TXT/CSV/JSON/Markdown text file per message; DSH persists images and injects text-file contents, while PDFs, archives, office files, and other binary files are rejected because the current DSH content model has no generic file block. QQ media events remain outside the current scope. Real desktop testing verified QR confirmation, Online, persistent restart recovery, and long-poll startup. Tencent/openclaw-weixin issue #244 remains relevant for accounts that stay online while returning empty msgs.

Never place either bot secret in composition configuration, repository files, logs, or normal settings. Telegram uses TELEGRAM_BOT_TOKEN; QQ uses QQ_BOT_APP_SECRET. Only one running plugin instance may own the configured bot credentials.

Use /start or /menu in Telegram, or send /start or /menu in QQ C2C, to select the computer, project, and session. Telegram and QQ prefer inline buttons; QQ retains a numbered-text fallback. Shared menus use Chinese labels. /new opens the available Agent preset menu and creates the session only after a preset is selected.

Telegram and QQ runtimes restart independently when their settings or credential changes are saved, and both stop their subscriptions and transports on dispose.

Once a session is selected, the bot relays that session's running turns even when they were started from the DSH GUI or another client. Switching computer, project, or session immediately removes the previous subscription. A Telegram message still uses exact message/turn correlation for its direct progress, while the selected-session relay is suppressed for that originating chat to avoid a duplicate. Other chats selecting the same session continue to receive it.

The Telegram bot edits one progress message at the configured interval and finalizes it with the turn result. QQ uses the separate stage-message behavior described above. Only visible assistant text and tool names/status are forwarded; reasoning, tool arguments, tool result bodies, and internal error details are not forwarded.

Set diagnosticLogging to true only while troubleshooting inbound delivery. It sends one readiness notice to each allowlisted user and logs update kind plus numeric routing metadata, but never message text, callback data, credentials, project ids, or session ids.