siweina/dsh-novel-writer
C2给中文网文作者的本地写作工作台(18 个工具):动笔前取齐上一章承接口/大纲/人物卡/待回收伏笔/用语规范,写完按六维文笔基线对照原著波动带自检,并排出带原句行号的改稿待办;跨章查伏笔埋设跨度、人物连续缺席与大纲偏离。24MB 中文模型随包本地推理,零 token、正文不出本机;同一套能力也可作 MCP 服务器。Local novel-writing workbench for DSH: 18 t
★ 10+ · siweina/dsh-novel-writer source on GitHub · this plugin in the registry
siweina/dsh-novel-writer is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, command execution in build output only.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| can rewrite the system prompt | prompt_surface | systemPrompt |
| command execution in build output only | exec_bundled | ×1 in build output only, e.g. lib/core.js:14 |
Services it injects
locale slots systemPrompt tools
Outbound domains
api.github.com
Environment variables it reads
DSH_HOME DSH_NOVEL_WRITER_STATE DEBUG DSH_NOVEL_WRITER_ROOT
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.