npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-remote-shell

v0.1.0

Published

DSH plugin bundling the remote-shell skill: secure SSH/SFTP/Telnet/WinRM remote operations with an encrypted credential vault.

Readme

dsh-remote-shell

DSH(DeepSeek Harness)插件,打包 remote-shell 技能:安全的 SSH / SFTP / Telnet / WinRM 远程操作,内置加密凭证库(Fernet + PBKDF2-HMAC-SHA256)。

English version: README.md。

安装

从 npm 注册表(发布后):

dsh plugin --profile web add dsh-remote-shell

从本地检出(开发 / 测试):

dsh plugin --profile web add /path/to/dsh-remote-shell

安装后重启 dsh web 使插件生效。技能会以 remote-shell 出现在技能目录中(provider dsh-remote-shell,source bundled)。

功能

打包的技能提供:

  • 远程命令执行(SSH / WinRM / Telnet):单条命令、批量执行、脚本执行、远程系统信息、健康检查。
  • SFTP 文件传输:上传、下载、目录遍历。
  • 加密凭证库:登录/执行脚本不接受明文密码(无 -p 参数),强制从加密凭证库取用;使用 credctl 录入、查询、修改、删除凭证。
  • 安全拦截:修改类命令默认被拦截,需用户确认后以 --auto-confirm 执行。

工作原理

本插件是一个 Cordis 插件,注入单个技能提供方。加载时扫描打包的 skills/ 目录中的 SKILL.md 文件,解析每个文件的 YAML frontmatter,并以 rank 600、source bundled 注册到宿主技能注册表。提供方是不可变的:不做文件监听或轮询;缺失或格式错误的技能会优雅降级(跳过,绝不抛错)。

行尾策略

打包的技能文件从源技能逐字节复制,而源技能使用混合行尾。.gitattributes 将每个文件钉住到其源行尾,使任何 core.autocrlf 设置下的检出都能精确复现源字节。SKILL.md 钉为 LF,因为提供方的 frontmatter 检测要求精确的 --- 行——CRLF 检出会使提供方完全跳过该技能。

开发

运行单元测试(Node.js 内置测试运行器,无需额外工具):

node --test

依赖

技能脚本为 Python 3,需要 paramiko(SSH/SFTP)、pywinrm(WinRM)等第三方库,首次使用时按技能 SKILL.md 中的指引安装。

安全声明

安装本插件即会在本机运行第三方代码。凭证库主密码由用户自行管理,插件不存储、不传输该密码。

许可

MIT — 见 LICENSE。