DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Plugin Manager — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-plugin-manager

Plugin Manager

用于 DeepSeek Harness (DSH) 和 Cordis 的 Web 插件管理器:检查、启用、禁用、分组和管理运行时插件

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-plugin-manager@0.1.0
README兼容性版本

兼容性与来源证明

Plugin Manager 以 dsh-plugin-manager 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.1.0stable
2026/8/13

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
2.3 MB
文件数
27
Surface
web
许可证
MIT
发布源
npm
GitHub
★ 1
周下载
279
安全扫描
✓ v0.1.0 扫描通过
最近提交
2026/9/20
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

DeepSeek Harness Plugin Manager

简体中文

DeepSeek Harness Plugin Manager is a Web-based plugin manager for DeepSeek Harness (DSH) and its Cordis plugin runtime. It lets operators inspect, search, enable, disable, group, and batch-manage runtime plugins from the Harness Plugins settings page.

This is a community project, not an official DeepSeek Harness package.

Features

  • Inspect the current Cordis Loader entries and lifecycle state.
  • Enable or disable one plugin without deleting its npm package.
  • Expand official Harness workspace groups, toggle all mutable entries in a group, or manage individual Loader entries by their configured names.
  • Persist desired state in the active profile's cordis.patch.yml so it survives restart.
  • Protect the manager itself and the Web management surface from accidental shutdown.
  • Use Harness's existing trusted-host transport policy; the plugin does not open another server.
  • English and Simplified Chinese Web UI.

Install

Install the package into the web profile:

dsh plugin --profile web add dsh-plugin-manager
dsh --profile web

Open Settings -> Plugins -> Plugin list. The manager replaces Harness's read-only list while keeping runtime status visible and adding category grouping, search, and enable/disable controls. Removing the package later uses:

dsh plugin --profile web remove dsh-plugin-manager

For a local checkout or tarball:

pnpm install
pnpm run build
pnpm pack
dsh plugin --profile web add ./dsh-plugin-manager-0.1.0.tgz

Git installs run the prepare build and require explicit build-script authorization under pnpm 10 and newer. Published npm packages and tarballs already contain lib/ and do not need install-time build permission.

Behavior and safety

"Disable" means persisting disabled: true and asking Cordis to stop the configured plugin; it does not uninstall the dependency. Ordinary leaf plugins are switched in the running process when their lifecycle permits it. If the desired state is saved but does not settle before the timeout, the UI reports that a profile restart is required instead of treating the saved change as a failure. The manager writes only its own marked patch rows and leaves user-authored rows untouched. If a local entry id is ambiguous, the operation fails instead of changing the wrong plugin.

By default, the manager protects its own entry and Loader ancestors, the root Include and profile HMR services, plus the API gateway, Web server, client runtime, settings shell, client module loader, connection, locale, and Host runner. These entries keep profile changes and the management page alive and cannot safely be disabled from that page. Add deployment-specific ids through the Cordis row config:

- id: dsh-plugin-manager
  name: dsh-plugin-manager
  config:
    protectedEntries: [my-auth-provider]
    settleTimeoutMs: 8000

The Web API follows the same trusted-host decision as the Harness connection. Anyone allowed to use the trusted Web control plane can invoke plugin enablement, so do not expose the Harness Web server to untrusted networks.

Categories and entry names

Official and third-party packages share one open functional grouping rule. A package can declare dsh.pluginManager.group in package.json; packages that declare the same group id appear together regardless of publisher. Without a declaration, repository.directory in the form packages/<group>/<package> supplies a best-effort fallback for any repository. Missing or invalid metadata falls back to Ungrouped. Group ids use lowercase letters, digits, dots, underscores, and hyphens. A future rich dsh-plugin.json manifest and detail view are intentionally outside this release.

{
  "dsh": {
    "pluginManager": {
      "group": "llm"
    }
  }
}

Groups are collapsed by default and directly list Loader entries by their configured ids, such as include, timer, and tool-web; imported module specifiers are intentionally hidden. A group toggle changes every mutable entry and skips protected infrastructure. Green means fully enabled, while yellow means the group is partially enabled.

Development

pnpm install
pnpm run typecheck
pnpm test
pnpm run build
pnpm run pack:check

Publishing

Pushing a vX.Y.Z tag runs .github/workflows/publish.yml. The workflow verifies that the tag matches package.json, runs the test, typecheck, and build gates, and publishes through npm Trusted Publishing with GitHub OIDC. It does not use a long-lived NPM_TOKEN.

Before using the workflow, configure the npm package's Trusted Publisher with GitHub owner hrhgit, repository deepseek-harness-plugin-manager, workflow filename publish.yml, no environment, and npm publish as the allowed action. npm exposes this setting only on an existing package, so the initial 0.1.0 release must first be published with a granular access token that has permission for this package and Bypass two-factor authentication enabled. Configure Trusted Publishing immediately afterward and revoke the bootstrap token.

For each later release, update and commit the version, then push the commit and its tag:

npm version patch
git push origin main --follow-tags

The package has one Host entry, one browser entry, generated Typert Remote artifacts, and one dsh.bundle patch. It targets the pre-release 0.1.x Harness APIs; review release notes before upgrading peer dependencies.

Roadmap

  • Install, remove, and update npm plugin packages.
  • Display true dsh.bundle provenance and compatibility metadata.
  • Discover community plugins from npm, GitHub, or a dedicated index.
  • Import and export curated plugin sets.

Discoverability

Recommended GitHub topics: deepseek-harness, dsh, cordis, plugin-manager, plugin-management, web-ui, deepseek, typescript.

Search phrases that accurately describe this project include DeepSeek Harness plugin manager, DSH plugin management Web UI, Cordis plugin enable and disable, and DeepSeek Harness plugin bundle manager.

License

MIT