dsh-qualityforge
DeepSeek Harness bundle: systematic, audit-ready QA orchestration for finished projects — exhaustive test-method catalog, evidence-backed execution, and a per-item checkable report with P0–P3 severity for negotiating fix scope with the Harness. 适合需要对已完成项目进行系统化QA测试与工程缺陷扫描的开发者。
インストール
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:lpeixin/dsh-qualityforgeドキュメント
README 全文を読む ↗Usage
1. Recon — qf_scan
{ "projectPath": "/path/to/project", "force": true }
Produces a project profile: stack and package manager, project type, languages, runnable commands
(each with its source, e.g. package.json#scripts.test), test frameworks, CI/container/IaC/security
tooling, documentation completeness, and confirmed engineering gaps (a missing lockfile, suspected
hardcoded credentials, and so on). Secret findings record location and kind only — never the value.
2. Plan — qf_plan
{ "depth": "standard", "categories": ["sec-input", "api-semantics"], "includeAll": false }
| depth | items | use |
|---|---|---|
smoke | 331 | pre-release blocker list |
standard | 984 | normal delivery audit (default) |
deep | 1295 | deep audit of an important release |
exhaustive | 1363 | first full audit, compliance evidence |
Every item gets a stable id (QF-001), a priority (P0–P3), a severity, a judgement mode
(auto / agent analysis / human confirmation) and an explicit pass criterion. Re-running is safe:
existing items keep their status and history; only reset=true rebuilds from scratch.
3. Run and probe — qf_exec / qf_probe
{ "presets": ["build", "typecheck", "lint", "test", "coverage", "audit", "secrets"] }
{ "urls": ["http://127.0.0.1:3000/health"], "expectStatus": 200, "itemId": "QF-512" }
qf_exec spawns only the preset commands discovered by recon (no shell, no arbitrary command strings);
install is opt-in because it mutates the working tree. qf_probe is restricted to loopback http(s),
GET/HEAD, with a truncated body.
4. Record conclusions — qf_record
{
"items": [
{
"id": "QF-142",
"status": "fail",
"actual": "`ORDER BY ${sort}` is interpolated into SQL at src/api/orders.ts:88",
"recommendation": "Map sort fields through an allowlist; return 400 otherwise",
"files": ["src/api/orders.ts:88"],
"repro": ["GET /api/orders?sort=id;DROP TABLE users--"],
"evidence": ["SQL log shows the interpolated statement"],
"cwe": ["CWE-89"],
"effort": "S"
}
]
}
Judgement discipline: fail (with reproduction) / pass (with evidence) / blocked (environment or
dependency missing — do not record as fail) / na (does not apply, with a reason) / wontfix
(risk accepted).
5. Report — qf_report
{ "reportPath": ".qualityforge/QUALITYFORGE-REPORT.md", "waveScope": "defects" }
Sections: how to use the report · verdict summary · priority & severity distribution · fix waves · problem list with one checkbox per defect · full checklist · skipped items · command evidence · project profile · re-test and sign-off table.
6. Negotiate fix scope — qf_update / qf_fixplan
Developers tick - [x] in the report (or `WONTFIX` / `DEFER` / `NA`); the Harness runs
qf_update sync=true to read the ticks back. Ticking a defect sets it to fixed, pending re-test — only
a re-test makes it verified.
Then pick a scope:
| scope | meaning |
|---|---|
all | everything still open |
p0 / p0-p1 | blockers only / the minimum shippable fix set |
defects (default) | every failing or blocked item |
pending | only items not judged yet |
ids + excludeIds | explicit include/exclude |
Output is a fix handoff sheet — per item: expectation, observation, location, suggestion — plus the constraints (touch only what is in scope, every fix must be verifiable, write ticks back when done).