
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-trade-assistant
Advanced tools
DeepSeek Harness(dsh)外贸场景工具插件:询盘回复 与 多语言产品文案。
Everything is a plugin —— 这是给 dsh 生态补上「外贸」空白的插件。规则驱动、零模型依赖、无外部 API 调用、不烧 token,装上就能用。
trade_inquiry_reply 询盘回复助手粘贴客户询盘原文,自动完成:
product_copy_multilang 多语言产品文案输入产品名称与卖点,输出 13 种语言(中、英、西、法、德、阿、俄、葡、日、韩、越、泰、印尼)的文案骨架:
# 方式一:npm 包
dsh plugin --profile web add dsh-trade-assistant
# 方式二:GitHub 仓库(无构建步骤,纯 JS 直装)
dsh plugin --profile web add github:你的用户名/dsh-trade-assistant
验证是否加载:
dsh --profile web --dump-config | grep trade-assistant
在 dsh Web UI 会话中:
用 trade_inquiry_reply 处理这封询盘:
"Dear Sir, we are an import company in Nigeria and need 500 pcs of your
solar panel 550W, please quote best price with delivery to Lagos port.
Payment by T/T."
用 product_copy_multilang 给我们的矿机产品写西语和阿拉伯语文案:
产品:BTC 矿机 S21,卖点:能效比 15J/TH;支持 220V 家用电压;质保 12 个月
两个工具均为规则引擎:内置外贸行业知识(询盘类型特征、关键字段正则、13 语言本地化素材库),执行时不发起任何 LLM 调用,输出结构化骨架供主模型撰写最终文本。因此:
dsh 生态 2026-08 起爆发式增长,但插件集中在开发工具、UI 主题、模型适配,外贸场景(询盘、多语言文案)几乎是空白。中国外贸从业者使用 dsh 时缺少开箱即用的行业工具,本插件即为此设计。欢迎提交 Issue/PR 补充更多语言与场景(如信用证审核、货代询价、展会跟进)。
# 本地调试
pnpm dsh web --patch ./cordis.yml # 或 dsh --patch ./cordis.yml
# 单元测试(Node 直接跑,无需 dsh)
node --test test/
MIT
FAQs
外贸询盘回复与多语言产品文案工具(DeepSeek Harness 插件)— 询盘解析、回复结构、本地化文案,零模型依赖
We found that dsh-trade-assistant demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.