精选
为什么选中它
待人工精选——以下事实来自源码仓库。
它能做什么
Chat with, monitor, and approve your DSH agents from WeChat — an iLink gateway + conversation node bundle for DeepSeek Harness
适合谁
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
风险提示
- 未发现明显风险信号;安装前仍建议查看源码。
Chat with, monitor, and approve your DSH agents from WeChat — an iLink gateway + conversation node bundle for DeepSeek Harness
待人工精选——以下事实来自源码仓库。
Chat with, monitor, and approve your DSH agents from WeChat — an iLink gateway + conversation node bundle for DeepSeek Harness
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
dsh plugin --profile web add github:Jesse-njx/dsh-chatnode-wechat 作者没有声明支持的平台。
ilinkai.weixin.qq.com) — the same mechanism hermes-agent and OpenClaw use. Text messages go both ways, session targeting works with /sessions /use /new /stop /status, permission requests are answered with /yes / /no right in the chat, and progress is reported as digest-style messages instead of a tool-call firehose. 你 (WeChat) ⇄ iLink ⇄ wechat-gateway ⇄ wechat-conversation-node ⇄ DSH agent session The bundle ships two separable Cordis plugins: | Plugin | Role | | --- | --- | | wechat-gateway (WechatGateway) | iLink service (ctx.wechat): QR login, authenticated long-poll, reconnect/backoff, send retry + rate-limit circuit, typing indicator, encrypted CDN media download. | | wechat-conversation-node | WeChat ⇄ DSH bridge: allowlist gate, session targeting, commands, digest outbound (chunked + throttled), approvals. | ## ⚠️ Read this first - One poller per account. iLink allows exactly ONE authenticated poller per bot token. If you also run hermes-agent or OpenClaw on the same WeChat account, one of them gets HTTP 403s and drops messages. Use a dedicated WeChat account for the agent, and never run two instances of this bundle against the same token. - Unofficial gateway. This rides the same unofficial mechanism as hermes/openclaw; Tencent could restrict the account. Again: use a dedicated account you are willing to lose. - Unofficial protocol. iLink details are reconstructed from hermes-agent source, not Tencent docs. Recorded transcripts live in test/fixtures/inbound.ndjson so CI never needs a live account. ## Install sh git clone https://github.com/Jesse-njx/dsh-chatnode-wechat.git cd dsh-chatnode-wechat pnpm install && pnpm build dsh plugin --profile <your-profile> add . Credentials are stored through the dsh credentials service — never in the patch file. Pair your WeChat account once: sh pnpm login # prints a QR URL; scan it with WeChat and confirm This writes WEIXIN_ACCOUNT_ID / WEIXIN_BOT_TOKEN / WEIXIN_BASE_URL to $DSH_HOME/.credentials.yaml (via dsh-credentials-local). The bundle resolves them at boot and starts polling automatically. ## Configuration yaml # profile patch (cordis.patch.yml) plugins: dsh-chatnode-wechat: allowFrom: ["<your-wechat-id>"] # hard allowlist, REQUIRED, no default digestIntervalSec: 300 # heartbeat summary while a turn runs approvalTimeoutSec: 600 # approval prompt timeout → default deny maxMessageChars: 2000 # WeChat bubble cap (protocol limit) sendChunkDelayMs: 1500 # throttle between outbound bubbles # cwd: /path/to/workspace # working dir for `/new` sessions # agentPreset: <preset-name> # agent preset for `/new` sessions # agentProvider / agentModel: ... # model route for `/new` agents allowFrom is mandatory with no permissive default: an agent that accepts instructions from any WeChat contact is a prompt-injection front door. Messages from non-allowlisted senders are logged and ignored — they are never fed to the model. ## Usage Send text to the bot. Everything is zero-config once one session exists — the most recent session is the default target. | Command | What it does | | --- | --- | | (plain text) | routes to the active agent (agent.followup) | | /sessions | numbered session list (most recent first) | | /use N | switch the active session | | /new <prompt> | create a fresh agent+session and start | | /stop | cancel the active turn | | /status | agent status + session summary | | /yes /no (or 1/2 while one request is pending) | answer a permission request | | /help | command list | Outbound is digest-style, never a mirror of every tool call: - ⏳ 收到,开始处理… when a turn starts, - a one-line 🔄 仍在处理中… heartbeat every digestIntervalSec, - the assistant's actual text (chunked to maxMessageChars, throttled), - ❌ 出错… / ⏹ 已停止 / ⚠️ 输出截断 on turn end, - 🔐 #N 需要你的确认 permission prompts, answered in-chat. ## Approvals WeChat personal accounts have no buttons. When a DSH permission request fires, the bridge renders it as a numbered text prompt and waits: 🔐 #1 需要你的确认 工具: bash 原因: run a destructive command 回复 /yes 同意,/no 拒绝(仅一条待确认时也可回复 1/2) 10 分钟内未回复将自动拒绝。 /yes (or 1 while exactly one request is pending) grants allowed-once; /no (2) rejects; a timeout falls back to DSH's default deny. The bridge only answers requests for the agent currently driven by the WeChat user — anything else is delegated down the answerer chain. ## Development sh pnpm install pnpm -r build pnpm --filter @dsh-cowork/chatnode-wechat test # 35 tests, no WeChat account - test/fake-ilink-server.ts implements the iLink endpoints (getupdates long-poll, sendmessage, sendtyping, getconfig, QR login, encrypted CDN) and replays test/fixtures/inbound.ndjson; the full inbound→session→outbound loop runs in CI. - pnpm smoke is the manual live-account script (set WEIXIN_ALLOW_FROM). - Pin the dsh-base family (@deepseek-ai/* at 0.1.0-rc.6 in this repo) — DSH is a developer preview and upstream breaks are expected. ## Risks | Risk | Mitigation | | --- | --- | | iLink exclusive lock — two pollers on one token → 403 + dropped messages | Dedicated account; loud fatal error + polling stop on 403; documented coexistence warning | | Account restriction — unofficial gateway | Dedicated account; stated plainly in this README | | DSH v0.1 churn | Pinned @deepseek-ai/* deps; CI against the pinned versions | | Protocol opacity | Protocol ported from hermes-agent; fixtures recorded so refactors need no live account | ## Roadmap - v0.1 (this package): QR login, text both directions, session targeting, commands, approvals, digests, allowlist. - v0.2: images/files both directions (inbound media download already shipped in the gateway), outbound voice replies. - v0.3: group chats (risk-heavy), multi-account, a hermesclaw-style shared-poller proxy so the bundle can coexist with hermes/openclaw. - Later: WeCom / DingTalk / Feishu bundles sharing the node/ layer. ## License MIT — see LICENSE.不看 Star,人工一条条挑的。
把 DSH 的 settings.yaml 做成可视化看板:所有已注册的 settings namespace——包括官方界面从未覆盖的第三方插件配置——都渲染成可编辑表单。项目还早,但方向很对:告别手改 YAML。
给 DSH 的 DIY 轨迹可视化:把 agent 的计划与执行画成图,不用翻原始日志也能看清它在干嘛。项目还早,但补上了「一眼看懂 agent 在做什么」这个真实缺口。
从 Claude Code / Codex 把活派给 DSH:在宿主内拉起带分级预设的 DSH agent 会话,看原生子代理进度,还能借它的多模态桥给纯文本的 DSH 补上视觉和生图。编排型插件,把 DSH 变成其他编码 agent 的后端。