npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-cloudq

v0.3.0

Published

CloudQ integration for DeepSeek Harness with secure credential, workspace, and plugin-management surfaces

Readme

dsh-cloudq

English | 简体中文

CloudQ integration for DeepSeek Harness. It adds a CloudQ mode to the Web profile, bundles the cloudq skill, and provides CloudQ usage and architecture views, local credential setup, and plugin management.

Screenshots

CloudQ risk analysis conversation

CloudQ settings and plugin management

Requirements

  • Node.js >=22.19.0
  • DeepSeek Harness 0.1.1-rc.2 or a compatible newer 0.1.x release
  • pnpm available to the dsh plugin command
  • Python 3 available as python3
  • macOS or Linux

Install

dsh plugin --profile web add dsh-cloudq

Restart the Web profile after installation:

dsh --profile web

Open the URL printed by DSH. The conversation input area and sidebar will expose the CloudQ entry. You can also invoke the bundled skill explicitly with /cloudq.

Upgrade and remove

dsh plugin --profile web update dsh-cloudq
dsh plugin --profile web remove dsh-cloudq

Restart the Web profile after changing the installed package set.

Usage

  1. Open Settings → Plugins and expand the CloudQ card.
  2. Enter your Tencent Cloud SecretId and SecretKey (available from the CAM console).
  3. Click 测试连接 to validate the pair, then 保存配置. The card shows AKSK有效 once the credential is active.
  4. Click 进入 CloudQ 模式 in the conversation input area — or type /cloudq — and start asking cloud operations questions, e.g. “帮我看看系统有哪些风险”.

Credentials

The settings card accepts a Tencent Cloud SecretId/SecretKey pair.

  • Credentials are stored locally at ~/.tencent-cloudq/credential.json with owner-only permissions.
  • Secret values are sent to Python helpers through standard input, never command-line arguments.
  • Browser APIs return only credential state and masked identifiers; local credential paths and secret values are not returned.
  • Use the logout action to remove the stored credential.

Follow least-privilege: grant only the permissions required for the CloudQ operations you intend to run. The bundled skill can invoke read and write cloud-management operations; review each action before approving it.

Security model

  • Host APIs accept only loopback, same-origin requests.
  • JSON request bodies are limited to 64 KiB.
  • Python helper output is bounded, and unexpected internal errors are not returned to the browser.
  • Remote values are inserted with DOM text nodes rather than HTML injection.
  • Download links require HTTPS.
  • No credentials, tokens, or local environment files are included in the npm package.

Report security issues through GitHub Issues without including live credentials.

Development

pnpm install
pnpm run lint
pnpm run typecheck
pnpm run test:all
pnpm run build
pnpm run check:client
npm pack --dry-run --registry=https://registry.npmjs.org/

The npm package ships prebuilt Host and Web client artifacts, the bundle patch, the runtime logo, and the bundled skill. Registry installation runs no build scripts.

Repository layout

src/                         Host and Web client source
skills/cloudq/               Bundled CloudQ skill and Python helpers
assets/cloudq.png            Runtime logo served by the Host
scripts/                     Build and release checks
tests/                       Unit, integration, and package-contract tests
cordis.patch.yml             DSH bundle layer

Release

Source is reviewed and versioned in TencentCloud/cloudq-for-dsh. An npm version is published to the official registry only after the repository checks and the package-install smoke test pass.

More documentation

License

MIT. See LICENSE.