Skip to main content

dsh-plugin-marketplace

20Stars3Forks1Issues1Watchers

Verified plugin marketplace and autonomous registry for DeepSeek Harness

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
JavaScript
License
MIT
Branch
main
dsh-plugin

Install

cmdweb profile
$ dsh plugin --profile web add dsh-plugin-marketplace

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin YELEBAI/dsh-plugin-marketplace for me: review the repository at https://github.com/YELEBAI/dsh-plugin-marketplace first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

一句话定位

DSH 官方插件市场 + 中心 Registry:在「设置 → 插件市场」中浏览、搜索、分类排序、一键或引导安装 GitHub 上的 DSH 插件,并提供已安装插件的批量更新、启停、卸载、冲突诊断和 DSH 安全重启能力。

核心能力

  • 浏览中心 Registry 中的插件,支持搜索、分类筛选、按 Star 排序和最近 7 天增长趋势
  • 按 Registry 验证过的精确 GitHub commit 或精确 npm 版本一键安装
  • 把官方 dsh plugin --profile ... add github:... 命令粘贴后解析、锁定 commit 并安全安装
  • 为需要构建或生命周期脚本的插件创建绑定 Registry 证据的引导安装 Agent
  • 已安装插件批量更新(每批最多 50 个)、启用/停用、卸载,状态变更通过 FIFO 队列串行写入
  • 静态检测重复 Bundle ID 和常见 Cordis 服务注册形式,在安装、更新、启用前阻止新引入的冲突
  • 把后续插件安装位置切到自定义目录,并把市场专属 Agent 工作区绑定到指定路径
  • 直接读取本仓库最新版本并把安装源固定到精确 commit 的市场自更新
  • 内置 install-dsh-plugin Skill,强制 Agent 安装/更新会话先加载安全工作流再执行任何写操作

技术实现

  • 语言: TypeScript(双面:Host 服务 + Web Client)
  • 关键依赖: @deepseek-ai/cordis ^4.0.1、@deepseek-ai/dsh-app-boot ^0.1.0-rc.5、@deepseek-ai/dsh-typert-protocol ^0.1.0-rc.5、zod ^4.4.3
  • 架构模式: Cordis Typert Remote 双面插件;cordis.patch.yml 注册名为 plugin-marketplace 的 Host/Client bundle,./client 导出注册 Settings 中的「插件市场」标签;所有远端方法返回 MarketplaceResult<T> 联合,业务错误用带 code 的结构化错误对象表达
  • 入口文件: src/host/index.ts(Host 端 MarketplaceService,包内 main 指向 lib/index.js)、src/client/index.ts(Client 端 apply(ctx),包内 ./client 指向 lib/client.js)
  • 安装引擎: 复用 Profile 绑定的 pnpm store,全部任务通过 pnpm add/remove/install --ignore-scripts 执行;自定义目录安装会先在 staging 目录下载、冲突检查、再复制到目标并通过 file: 依赖关联回 Profile

适用场景

当你需要管理 DSH 第三方插件而不想在命令行手敲 dsh plugin add github:... 时使用这个插件;它把「找插件」「挑可信版本」「跟其他插件冲突了怎么办」「装了不想要了怎么卸」「DSH 需要重启了」这几件事全部搬到 Web 设置面板里完成,并对每个动作给出结构化的安全校验和回滚保障。

前置依赖与兼容性

依赖最低版本说明
DSH 宿主^0.1.0-rc.5(peerDependencies:@deepseek-ai/dsh-app-boot、@deepseek-ai/dsh-typert-protocol)插件通过 Typert Remote 协议与 Client 端通信,并通过 dsh-app-boot 读写 Profile manifest
DSH ClientWeb(dsh.client.platform: web)设置面板需要 @deepseek-ai/dsh-client-ui-settings 和 @deepseek-ai/dsh-client-locale 提供的 settings 标签和本地化支持
pnpm由 DSH 宿主提供所有安装、卸载、链接操作通过 pnpm 子进程执行,要求 pnpm 在 PATH 中
平台跨平台源码中通过 process.platform === 'win32' 处理 Windows junction,其余逻辑平台无关
Node.js未声明package.json 未提供 engines 字段
原生模块无仅依赖 zod,无任何 node-gyp/binding.gyp 依赖

安装方式

dsh plugin --profile web add github:YELEBAI/dsh-plugin-marketplace

配置项

配置类型说明默认值
registryUrlURL 字符串中心 Registry 的 plugins.json 地址,留空则使用内置默认 URL 或环境变量 DSH_PLUGIN_REGISTRY_URL未设置(使用默认)
registryCacheMinutes整数 (1–1440)远程 Registry 内容的内存缓存时长(分钟),过期后才重新请求;刷新失败会先回退到上一次有效结果,再回退到包内快照15
registryRequestTimeoutMs整数 (1000–60000)拉取远程 Registry 时的单次请求超时(毫秒)10000
installDir字符串可选的插件实体安装目录,覆盖默认的 Profile 内 node_modules;通过「管理与诊断」面板选择,无需手填未设置(使用 Profile 默认位置)

这些字段对应 Loader 配置里的对象(即宿主注入插件时传入的配置),由 Zod Schema 校验;普通用户通常不需要手写,只在「管理与诊断」面板里选择目录即可。

常见问题

Q: 装完插件在哪里打开?

A: 启动 dsh --profile web 后进入「设置 → 插件」页面,会看到「插件市场」标签。该标签下分三个子页面:插件市场(搜索/安装)、已安装插件(管理)、管理与诊断(手动安装、目录、冲突)。

Q: 安装一个不认识的插件安全吗?

A: Registry 中已经过结构、commit 锁定和 bundle 校验的插件支持一键安装;无法静态通过校验的会交给引导 Agent,由 DSH 原生审批层逐项请求生命周期脚本等确认;仍未通过或当前 Profile 不兼容时只展示作者说明,不会执行命令。

Q: 可以换 Registry 源吗?

A: 可以。通过环境变量 DSH_PLUGIN_REGISTRY_URL 覆盖默认 URL,或在插件 Loader 配置中写入 registryUrl,远程内容会按 ETag/TTL 缓存并支持回退到包内快照。

Q: 安装位置必须放在默认目录吗?

A: 不必。在「管理与诊断 → 插件安装位置」可选择自定义目录,DSH 会用原生目录选择器创建 file: 依赖并把运行入口链接回 Profile 的 node_modules;切换目录只影响后续新安装。

Q: 卸载会影响其他插件吗?

A: 单个卸载只移除对应依赖和 bundle 层;批量卸载每批最多 50 个并按 FIFO 队列串行写入 Profile manifest,单项失败不会阻断其他任务。重启 DSH 后变更生效。

Q: 插件市场如何自我更新?

A: 在已安装插件页面操作市场自身的「更新」时,市场会直接读取仓库当前版本,将安装源固定到解析后的精确 commit,并提示重启 DSH 生效。

上手难度

入门 — 这是 DSH 官方推荐的「装插件」入口,绝大多数用户只需要在 Web 设置面板里点几下,不需要手动写命令或改配置。

已知问题与限制

  • 静态冲突诊断可能误报:当某个插件把其它插件的代码 inline 进自己的入口时,诊断器会将其中的 Cordis 服务声明误认为重复所有者;安装、更新或启用前仅阻止本次新引入的冲突,已有冲突不会被阻断。
  • 恶意代码启发式扫描与 Agent Loop 运行时探测目前为实验项目,与稳定 Registry 完全隔离;其结果不会把已经通过静态安装检查的插件从一键安装降级为引导安装。
  • Registry 分类器在升级时会复用未受影响的缓存以避免耗尽 API 配额,但 GitHub Search 单次最多返回 1000 条结果,扫描器会拆分请求并在配额重置后继续,初始化扫描可能需要较长时间。

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/YELEBAI/dsh-plugin-marketplace)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory