a86582751/dsh-nexttavern
C3DeepSeek Harness 长篇角色扮演agent(DSH酒馆插件):SillyTavern 角色卡导入、行动选项卡、分支对话管理、长篇记忆、关键词与语义混合检索、交互式角色卡创作、世界书、多角色 Agent 集群、文风预设、小说与角色卡导出、一键安装。 / Roleplay Agent 、Tavern plugin for DSH (DeepSeek Harness): branch co
★ 100+ · a86582751/dsh-nexttavern source on GitHub · this plugin in the registry
a86582751/dsh-nexttavern is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, eval in build output only, decodes base64 payloads.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.json |
| can rewrite the system prompt | prompt_surface | systemPrompt |
| eval in build output only | eval_bundled | ×2 in build output only, e.g. lib/client.js:7718, development/ui-chat/lib/client.js:6 |
| decodes base64 payloads | base64_decode | ×5 in authored code, e.g. development/mvu-schema-runtime-v2/assets/zod-4.4.3.js:1, development/mvu-schema-runtime/assets/zod-4.4.3.js:1 |
| starts a network server | net_server | ×2 in authored code, e.g. integrations/auth-webserver/test.mjs:13, integrations/auth-webserver/test.mjs:22 |
Services it injects
agentDefaultModel agents attachments configForms connection fileUpload fileUploads fs invariants layout llm locale nexttavernMessageEdits remote sessionController sessionProjections sessionQuery sessions shortcuts sidebarRight slots systemPrompt tools typert uiConversation uiSession uiWorkspace workspaceRegistry workspaces
Hooks it attaches
agent/assistant-stream agent/created agent/disposed agent/error agent/pre-step agent/status connection/reset internal/config internal/dispatch llm/adapters-updated llm/stream loader/volatile-update session/created session/disposed session/event session/flush
Outbound domains
harness.example.com npms.io docs.aws.amazon.com www.exchangerate-api.com api.openai.com team.cloudflareaccess.com
Environment variables it reads
DSH_HOME DSH_ROLEPLAY_USERINFO_PATH DSH_ROLEPLAY_CONVERSATIONS_PATH
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.