Provides a collection of skills for DeepSeek Harness, likely enhancing agent capabilities.
- Language
- JavaScript
- License
- NOASSERTION
- Branch
- main
Install
$ dsh plugin --profile web add dsh-skillsRun the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial
Install via your agent
Install the DeepSeek Harness plugin CocoSgt/dsh-skills for me: review the repository at https://github.com/CocoSgt/dsh-skills first, then run the install command and verify the plugin loads successfully.
Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.
一句话定位
第三方技能中枢插件:把 Claude Code 的 ~/.claude/skills、项目目录、.skill 包等散落各处的技能,统一汇入 dsh 的全局技能库 ~/.dsh/skills,入库即在输入框 / 斜杠菜单中可用,并在设置页新增"技能"导航页。
核心能力
- 把任意来源目录里的技能(Claude Code 项目目录、
~/.claude/skills、~/.codex/skills等)一键入库到全局库,技能在/斜杠菜单里即时可见 - 提供两种入库身份:引用(符号链接,编辑即编辑来源,推荐)和副本(整树拷贝,与来源独立演化)
- 在设置页新增"技能"导航页,含两个页签:"全局技能"管理已有技能,"发现"扫描配置的来源目录供批量引用
- 支持上传
.skill包(zip 格式,整树解压入库)、粘贴文本新建技能、从空白新建技能 - 内置 SKILL.md 编辑器,支持读取/保存/导出/删除,导出为
.skill包时引用身份会被解引用为真实文件 - 多语言界面(zh/en),文案随设置语言切换自动重渲染
技术实现
- 语言: TypeScript(编译产物为宿主端
lib/index.mjsESM + 浏览器端lib/client.js) - 关键依赖: @deepseek-ai/cordis(宿主插件框架)、@deepseek-ai/dsh-typert-protocol(typert RPC 协议)、react(设置页组件)
- 架构模式: 宿主端用 Cordis 网关服务(
SkillHubGateway继承TypertRemoteService)暴露三个 RPC(getState/runCommand/browseDirs),浏览器端注册到官方settings.section槽位(order 25);通过cordis.patch.yml注入 bundle idskill-hub - 入口文件: 宿主
src/index.ts(导出SkillHubGateway)、浏览器src/client/index.ts(注册面板到设置页)
适用场景
同时使用 dsh 和其他 AI 编码工具(Claude Code、Codex 等)的开发者,希望把各处的技能(散落在 ~/.claude/skills、项目目录、.skill 包里的)集中到一个全局库管理,避免每个项目或工具各自维护一份。维护私有技能库的开发者也适合用此插件做"单一真相源",引用技能更新一处全局生效。
前置依赖与兼容性
| 依赖 | 最低版本 | 说明 |
|---|---|---|
| DSH(web profile) | >= 0.1.0-rc.6 | devDependencies 锁定 @deepseek-ai/dsh-client-runtime ^0.1.0-rc.6;仅 web profile 可见 |
| Cordis | ^4.0.1 | 宿主框架,peerDependencies 声明 |
| Node | 未声明 | 源码使用 node:fs/promises / node:zlib,无 native 模块 |
| 平台 | 跨平台 | Windows 上文件级符号链接无特权时退化为复制(目录用 junction) |
| 原生模块 | 无 | 全部使用 Node 内置模块 |
安装方式
dsh plugin --profile web add github:CocoSgt/dsh-skills
安装后重启 dsh web,设置页会出现"技能"导航页。卸载:dsh plugin --profile web remove dsh-skills。
配置项
本插件无需额外配置文件。所有运行时配置都在设置页 → 技能面板里完成:
| 配置 | 类型 | 说明 | 默认值 |
|---|---|---|---|
DSH_HOME 环境变量 | string | 覆盖全局主目录路径(影响 ~/.dsh/skills 位置) | ~/.dsh |
| 来源目录列表 | string[] | 扫描时使用的来源目录(支持 ~ 前缀),仅此目录内的技能可被引用/复制入库 | ['~/.claude/skills'] |
| 全局库路径 | string | 入库技能的真实存储位置(DSH 官方 skill-filesystem 扫描根) | $DSH_HOME/skills |
| 技能回收站路径 | string | 删除副本技能时移入此处,可手工找回 | $DSH_HOME/skill-trash |
新建/上传技能、删除、编辑、导出均通过面板操作,无独立配置文件。
常见问题
Q: 引用和副本有什么区别?我该选哪个?
A: 引用是把来源做成符号链接,全局库只有一份文件,编辑引用即编辑来源,零同步开销;副本是把整树拷贝到全局库,与来源独立演化。本插件推荐默认用引用,适合长期维护的来源;临时来源(如 .skill 包、要删的仓库)或想脱钩改全局版的场景用副本。
Q: 入库的技能在哪儿生效,新会话能立即用吗?
A: 全局库位于 ~/.dsh/skills(DSH_HOME 可覆盖),是 dsh 官方 skill-filesystem provider 的默认扫描根,对所有会话生效。新建会话立即可用 / 菜单;已打开的会话需要刷新页面才能看到新入库的技能。
Q: 编辑引用技能会不会改坏来源?
A: 会,而且这是预期行为:保存直接写入来源文件,编辑器顶部有黄字提示。如果你只想改全局版、不想动来源,应选"复制"方式入库。
Q: Windows 上文件符号链接失败会怎样?
A: 文件级引用在没有创建符号链接的权限时,会自动退化为复制,并在状态行明确告知"此平台无法创建文件符号链接,「X」已改为复制入库"。目录引用在 Windows 上使用 junction,不受此影响。
Q: 怎么卸载,会同时删掉我的技能吗?
A: 运行 dsh plugin --profile web remove dsh-skills 卸载插件本体即可。插件不会删除 ~/.dsh/skills 里的技能文件,已入库的技能仍会作为"本地创建"继续存在。
Q: 项目目录里的技能为什么这个插件管不到?
A: 项目目录(.dsh/skills、.agents/skills,rank 100/200)由 harness 直接扫描,不经过本插件;同名时项目技能优先。本插件管理的是全局库(rank 400,对所有会话生效),定位不同。
Q: 上传的 .skill 文件大小有限制吗?
A: 有。上传 base64 长度上限 64MB(约 48MB 二进制),超过即拒收。解压时单条目上限 64MB、全部条目累计上限 256MB,是为了防止恶意 zip 炸弹。
上手难度
入门 — 安装后即可在设置页找到"技能"页签,无需额外配置文件,默认来源目录 ~/.claude/skills 直接生效。
已知问题与限制
- 副本与来源的漂移检测/拉取/推回是二期功能;当前副本仅在状态文件记录来源路径,不判定是否同步(schema 已为后续漂移检测预留字段)
- Windows 上文件级符号链接无特权时自动退化为复制,目录级引用使用 junction;行为有差异但均如实提示
- 引用技能的库内链接名固定于入库时刻;来源 frontmatter 的
name改名后,技能显示名会跟着来源走,但库内链接名不会自动更新(仅目录名与技能名不一致,无副作用) - "全部引用"(批量导入)串行执行,失败逐条收集后汇总展示,不刷屏
- 极少数底层失败的宿主报错(如 zip 损坏细节)以
{message}参数透传,英文界面下仍可能显示中文片段 - 来源路径读取受白名单限制,必须位于配置的来源目录或全局库内,避免任意路径读取
- 来源扫描有性能护栏:每个目录最多 60 个子目录计数、单目录最多 150 个文件名计数,超出后剩余条目按 0 计
简体中文 | English
npm package: dsh-skills · GitHub repository:
CocoSgt/dsh-skills
Third-party skill hub for DeepSeek Harness (dsh): aggregate skills scattered
everywhere into one global library. Claude Code's ~/.claude/skills, project
directories, .skill packages — everything lands in ~/.dsh/skills (the
official skill-filesystem's default scan root, watched live), and once
imported appears in the "/" slash menu of the input box. Adds a "Skills" page
to the settings dialog.
Two import identities
| Link (recommended) | Copy | |
|---|---|---|
| Implementation | skills/<name> is a symlink to the source | full tree copy |
| Sync | No sync problem: one file on both sides, editing edits the source | evolves independently (state records the source for reference) |
| Source deleted | panel marks it "broken link", one-click removal (source untouched) | unaffected |
| Fits | long-lived sources you maintain | throwaway sources (.skill packages, repos you'll delete), or a global version you can change freely |
The harness's skill scanner, fs provider, and watcher all follow symlinks
natively (skill-filesystem's nodeEntryKind handles them explicitly), so
links need no patches and work across every loading form (including SDK/ACP,
where plugins cannot be installed).
Aligned with how the harness actually works
- There is no "install": a skill takes effect the moment it sits in a scan
root. This page manages the global library (
~/.dsh/skills, rank 400, all sessions); skills in project directories (.dsh/skills,.agents/skills, rank 100/200) are scanned by the harness directly and never pass through this page — that is exactly why they are "always invocable", and why project skills win on name collisions. - A skill is a file tree, not one MD: the editor edits
SKILL.mdonly and tells you how many resource files exist; manage resources via "Open directory". Export packages the whole tree as .skill (links are dereferenced: real files are packed). - Editing a link = editing the source: the editor header says so; saving writes straight to the source file.
Tabs
- Global skills: the top action row has "+ New skill" (inline expander,
no scrolling) and "Upload .skill" (imports as soon as a file is picked, no
intermediate confirmation); a filter box appears with many skills. Each
card: identity badges (
Link → source/Copy/Created locally/Broken link), resource count, non-default invocation policy; descriptions clamp to 3 lines by default (click to expand); primary action "Edit SKILL.md", with export / open directory / copy name in the ⋯ menu and an inline two-step delete confirmation (links only remove the link). - Discover: scan directories managed inline as chips at the top (each chip shows its skill count or "missing", ✕ removes immediately, + adds in place — there is no separate "Sources" tab); each scanned item offers "Link" (primary) / "Copy", and "Link all" goes through a single batch RPC; a filter box appears with many results.
Architecture
- Host half (
lib/index.mjs):SkillHubGatewayextendsTypertRemoteServiceand exposes three RPCs:skillHub/getState,skillHub/runCommand, andskillHub/browseDirs(the last one powers the source picker's directory browser). The runCommand payload is a command union carried verbatim over src-json. The earlier 3180–3189 port-probing sidecar HTTP service is gone. Because SRC discovery is blind in the third-party dual-copy scenario, a weak manifest is also registered into the host typert registry. - Browser half (
lib/client.js): $mount identity-codec descriptors →ctx.remote.skillHub; the panel registers into thesettings.sectionslot; "Open directory" goes through the officialhost.openPath. - i18n: all visible copy renders through the official locale service.
zh/en dictionaries live in
src/client/locales.ts; the slot registration declareslocale: NS, so the framework injects a reactivetseat into the component props. Host runCommand results carry a stablecode(e.g.import.linked,err.read.notFound) plus optionalparamsand an explicitlevel: 'error'; the client translates by code and falls back to the Chinesemessagefield, and colors the status line bylevelinstead of guessing from message text.
The state file ~/.dsh/skills/.skill-manager.json records the source
configuration and each skill's {mode, source, addedAt} (schema reserved for
future drift detection). Its filename is deliberately kept from the old
skill-manager so existing installations keep their state.
Install
Install from npm:
dsh plugin --profile web add dsh-skills
The three dsh plugins can be added together in one command:
dsh plugin --profile web add dsh-skills dsh-attachments dsh-inspector
GitHub fallback:
dsh plugin --profile web add github:CocoSgt/dsh-skills
Note: a self-built profile's
~/.dsh/profiles/<name>/package.jsonmust list@deepseek-ai/dsh-baseand@deepseek-ai/dsh-web-appindsh.profile.bundles, otherwise startup hangs silently.
Restart dsh web afterwards. Uninstall:
dsh plugin --profile web remove dsh-skills.
Companion plugins
The other two plugins from the same suite:
- dsh-attachments
(npm) — bring any file
into the conversation as cards above the composer; the model reads images
by path via
read_image, so even non-vision models are never blocked. - dsh-inspector (npm) — an "Instruction Files" panel showing the exact AGENTS.md/CLAUDE.md instruction chain in effect for the session, in real load order, with in-place editing and skill-root status.
Known limitations
- Drift detection/pull/push between copies and their sources is phase two; for now copies only record the source.
- Directory links use junctions on Windows; file-level links fall back to a copy without privilege, and say so honestly.
- A linked skill's in-library link name is fixed at import time; if the source's frontmatter name changes later, the skill name follows the source but the link name does not (harmless — only the directory name and the skill name diverge).
- "Link all" runs serially; failures are collected and summarized (first failure shown) without flooding the status line.
- Host-side messages for a few low-level failures (e.g. corrupt zip details)
ride inside a
{message}param and remain Chinese in the English UI.
Development
pnpm install
pnpm run check # tsc --noEmit
pnpm run build # tsdown (host ESM + browser bundle)
Note: host method parameter names ARE the RPC wire field names (Gateway SRC mode); the build must never minify or rewrite parameter names.
Tags
This package and its repository carry the dsh-plugin, dsh, deepseek-harness
and related keywords/topics. DeepSeek Harness ships no official plugin
marketplace and no official discovery tag — once a third-party plugin is
published, nothing links it back to the ecosystem and users have no way to
find it. These community tags are the only practical discovery channel
(npm: keywords:dsh-plugin; GitHub: topic:dsh-plugin). Unofficial, but
essential — that is why they are here.
License
MIT
Read the usage guide →
Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.
Listing badge
[](https://deepseek-plugin.org/plugins/CocoSgt/dsh-skills)Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.