DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Plugin Shop — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-plugin-shop

Plugin Shop

DeepSeek Harness 插件商店:从可通过 Git 审计的目录中浏览、安装、启用和更新 dsh 插件。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-plugin-shop@0.8.2
README兼容性版本

兼容性与来源证明

Plugin Shop 以 dsh-plugin-shop 发布,当前版本为 0.8.2。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.8.2stable
2026/9/15
0.8.1stable
2026/9/10
0.8.0stable
2026/9/7
查看其余 60 个版本收起版本
0.8.2-beta.0beta
2026/9/14
0.8.1-beta.2beta
2026/9/10
0.8.1-beta.1beta
2026/9/9
0.8.1-beta.0beta
2026/9/8
0.8.0-beta.4beta
2026/9/7
0.8.0-beta.3beta
2026/9/7
0.8.0-beta.2beta
2026/9/7
0.8.0-beta.1beta
2026/9/6
0.8.0-beta.0beta
2026/9/6
0.7.5-beta.0beta
2026/9/4
0.7.4stable
2026/9/3
0.7.3stable
2026/9/3
0.7.3-beta.2beta
2026/9/3
0.7.3-beta.1beta
2026/9/3
0.7.3-beta.0beta
2026/9/3
0.7.2stable
2026/9/3
0.7.2-beta.1beta
2026/9/3
0.7.2-beta.0beta
2026/9/3
0.7.1

相关插件

正在加载相关插件…

最新版
0.8.2
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
736.9 kB
文件数
44
Surface
web
许可证
Apache-2.0
发布源
npm
GitHub
★ 0
周下载
735
安全扫描
✓ v0.8.2 扫描通过
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
stable
2026/9/2
0.7.1-beta.1beta
2026/9/2
0.7.1-beta.0beta
2026/9/2
0.7.0stable
2026/9/2
0.7.0-beta.0beta
2026/9/2
0.6.0stable
2026/9/2
0.6.0-beta.2beta
2026/9/1
0.6.0-beta.1beta
2026/9/1
0.6.0-beta.0beta
2026/9/1
0.5.4stable
2026/9/1
0.5.4-beta.3beta
2026/9/1
0.5.4-beta.2beta
2026/9/1
0.5.4-beta.1beta
2026/9/1
0.5.4-beta.0beta
2026/9/1
0.5.3stable
2026/9/1
0.5.3-beta.0beta
2026/9/1
0.5.2stable
2026/9/1
0.5.1stable
2026/9/1
0.5.0stable
2026/9/1
0.4.14stable
2026/8/31
0.4.13stable
2026/8/31
0.4.12stable
2026/8/31
0.4.11stable
2026/8/30
0.4.10stable
2026/8/30
0.4.9stable
2026/8/28
0.4.8stable
2026/8/28
0.4.7stable
2026/8/27
0.4.6stable
2026/8/27
0.4.5stable
2026/8/27
0.4.4stable
2026/8/27
0.4.3stable
2026/8/27
0.4.2stable
2026/8/27
0.4.1stable
2026/8/27
0.4.0stable
2026/8/27
0.3.1stable
2026/8/26
0.3.0stable
2026/8/26
0.2.0stable
2026/8/26
0.1.4stable
2026/8/26
0.1.3stable
2026/8/26
0.1.2stable
2026/8/26
0.1.1stable
2026/8/26
0.1.0stable
2026/8/26

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

dsh-plugin-shop

The plugin shop for DeepSeek Harness — browse a catalog of dsh plugins, install one with a single confirmation, and manage what you have, from a tab inside Settings.

English | 中文


📦 Install

Two tracks below. They do the same thing; pick the one that matches who is reading.

🧑 For people

Prerequisites: Node.js. Running the harness itself needs no install — the upstream-documented form is npx -y @deepseek-ai/dsh web. Plugin management goes through dsh plugin, which spawns both the dsh command and pnpm — install them once with npm install -g @deepseek-ai/dsh pnpm and verify with dsh --version and pnpm --version.

# dsh on PATH (global install). The explicit version pin matters: pnpm 11
# holds back very recent releases, so a bare `add dsh-plugin-shop` can hand
# you an older version for a while. Pin the current release — refresh it
# with `npm view dsh-plugin-shop version`.
dsh plugin --profile web add dsh-plugin-shop@0.8.2
# or straight through npx, nothing installed:
npx -y @deepseek-ai/dsh plugin --profile web add dsh-plugin-shop@0.8.2

Replace web with your profile if you use another one. Then restart dsh once — a newly added bundle is not applied to a running process — and open

Settings → Plugins → Plugin shop

You land on a shelf of plugin cards with a search box. The first load reads the catalog over the network and can take a few seconds; a shimmering skeleton stands in until the cards arrive.

🤖 For agents

Non-interactive, no prompts, nothing to confirm. --profile is mandatory — without it dsh plugin exits with error: required option '--profile <name>' not specified.

1. Resolve a profile name. Profiles are directories under $DSH_HOME/profiles ($DSH_HOME defaults to ~/.dsh). node_modules appears there too and is not a profile.

ls -1 "${DSH_HOME:-$HOME/.dsh}/profiles" | grep -v '^node_modules$'

2. Install. Pin the version — the explicit pin bypasses pnpm's release cooldown, and deterministic installs are the point of the agent path.

dsh plugin --profile <profile> add dsh-plugin-shop@0.8.2

3. Verify — do not skip this. A zero exit from step 2 means pnpm resolved the package, not that the profile will load it. Assert on the bundle list:

dsh plugin --profile <profile> list --depth 0

dsh-plugin-shop must appear with a resolved version. If you would rather read the manifest directly, the same fact lives at $DSH_HOME/profiles/<profile>/package.json under dsh.profile.bundles.

4. Restart the profile — dsh --profile <profile>, or dsh web for the web profile. Enabling or disabling an already installed plugin is hot; adding a new bundle is not.

Failure modes

What you seeWhat it meansWhat to do
error: required option '--profile <name>' not specified--profile was omittedPass it; there is no default
A version older than npm's latest gets installedpnpm 11 holds back very recently published versionsPin the version explicitly: dsh plugin --profile <p> add dsh-plugin-shop@<version>
client bundles not found ... lib/client.jsthe copy on disk was built without its browser halfInstall from npm rather than from a source checkout, or run pnpm build in that checkout
dsh: pnpm not found on PATH — install pnpm to manage profile pluginsdsh plugin forwards to pnpm, and pnpm is missingnpm install -g pnpm
no profile directory found above <path>the plugin could not locate its profilePlease report it — this is resolved from ctx.baseUrl and should not fail
The tab is missing after a restartthe bundle is not in the profile's bundlesRe-run step 3; if it is absent, step 2 did not complete

🖼️ Screenshots

The plugin shop shelf inside dsh Settings
Installing an unreviewed plugin requires an explicit acknowledgementThe same shelf in the dark theme
Installing an unreviewed plugin requires an explicit acknowledgementThe same shelf in the dark theme

✨ What it does

Browse & searchThousands of plugins, harvested from the whole public npm registry by the dsh-plugin and deepseek-harness keywords and from GitHub repositories using them as topics — shown with the author's own summary when they declared one, and sorted into seven categories
InstallOne confirmation. An unreviewed plugin requires an explicit acknowledgement first — an installed plugin holds the same privileges as a built-in one
Enable / disableApplies to an installed plugin without a restart. A plugin with a browser half also needs the open page reloaded, and the shop offers the button when it does
Installed stateAn installed plugin shows an Installed label on its card — or an Update button when the catalog has a newer version — plus an Uninstall button; the Installed filter in the category bar shows only installed plugins
Size & authorEach card shows what installing the plugin puts on disk, next to the account that published it — npm's own unpacked figure, so it matches the package's npm page
Leave out what cannot runA plugin whose declared components your installation does not provide is badged incompatible; the filter at the end of the category bar takes those off the shelf. It never hides a plugin whose name is already taken by another install, and never subtracts from the Installed view — those cards are the only place the problem is explained or can be undone
ReloadWhen an uninstall or a toggle is already live on the server and only the open page is stale, the shop offers to reload that page — never automatically, because a reload discards work in flight
RestartWhen the plugin's host half could not be brought up live — and also when it could, but the plugin has a browser half: a plugin that arrives mid-session reaches the page only through a restart, so the shop says so rather than offering a reload that would change nothing. It states the cost first: the page disconnects and in-flight work is interrupted
Self-updateThe shop shows its own version next to the search box, checks npm for a newer release, and updates itself with the pinned version — then the usual restart

🔎 Where the shelf comes from

The catalog is not a list anyone curates by hand. Six steps run every day, and two of them are the reason the shelf is worth reading:

  1. Harvest the whole registry. Every npm package carrying dsh-plugin or deepseek-harness, plus every GitHub repository using them as topics. Nothing is submitted; there is no queue.
  2. Gate every candidate. Most of what is harvested never reaches the shelf; the live badges on the repository README count both sides. A package with no dsh.bundle is a library, not a plugin. No license or no repository means nothing can be audited. Deprecated on npm is out; a repository listing additionally needs no build scripts and no workspace: dependencies, either of which would fail the install on your machine. A name a hair away from a popular one is held until someone clears it. Seventeen recorded reasons, all mechanical, and every rejection carries a line its author can read.
  3. Classify and record. Seven categories, and the peer modules each plugin declares — names only, never version ranges.
  4. Publish. Content-addressed JSON, to npm and GitHub Pages at once.
  5. Fetch here. This package races the origins and verifies the sha256 before trusting a byte.
  6. Check dependencies here too. Your installation resolves each recorded peer name against your profile — the same question dsh's loader asks at mount time. A card whose modules are absent reads Incompatible and names them. That verdict is computed on your machine, because it depends on the harness you are actually running, not the one the build ran on.

The full pipeline diagram lives in the repository README.

One thing this does not do: no listing has been read by a human. verified.yml is empty today, every entry is community-tier, and every install asks you to acknowledge that. Mechanical filtering is not review.

🧩 How it is put together

Two halves ship in this one package, and the split between them is the security boundary:

HalfEntryCan reachCannot reach
Hostdsh-plugin-shopThe network (catalog fetch and sha256 verify), the filesystem (cache), dsh plugin add under a per-profile mutex—
Clientdsh-plugin-shop/clientExactly nine shop/* Remote methodsThe network, the filesystem

Compromising the browser half buys an attacker those nine calls and nothing more.

⚙️ Configuration

The shop reads its catalog from whichever source answers first: the npm package dsh-plugin-shop-catalog (via your configured registry, npmmirror, or npmjs) or https://LivXue.github.io/dsh-plugin-shop/v1/. All of them carry the same bytes; the race exists because the link to one of them can be far slower than the link to another. Setting DSH_SHOP_CATALOG_URL opts out of the race and uses only what you name.

VariableEffect
DSH_SHOP_CATALOG_URLRead the catalog only from this base, instead of racing the default sources

📚 The catalog

Built daily from the public npm registry and published as static JSON:

  • /v1/index.json — the pointer, carrying schemaVersion, builtAt, the entry count and rejected totals (the badges above read them live), and the content hash
  • /v1/plugins.<sha256>.json — the data, content-addressed and safe to cache indefinitely

The pointer is small enough to poll. The shop verifies the data file's sha256 against the pointer before trusting a byte of it.

⚠️ What it does not claim

A listing is not an endorsement.

capabilities is whatever the author wrote about their own package. There is no sandbox in v0, and the interface never renders that field as an enforced permission list. The verified tier means a human read that exact version; a newer publish downgrades it to verified-stale and keeps the review pinned to the version it was actually given — so passing review once cannot buy trust for every future release.

🏷️ For plugin authors

Add a harvest keyword — "keywords": ["dsh-plugin"] or "keywords": ["deepseek-harness"] — to package.json and publish. Or, without npm: add the keyword as a GitHub repo topic and keep a package.json at the root with a name and dsh.bundle — the catalog lists the repo and pins the default-branch commit as its version. The daily build finds you; nothing is submitted to this project. Declare a dsh.catalog section to control your own category, summary and capabilities — or omit it, and the catalog derives a listing from your npm description.

Full reference: docs/schema.md.

📄 License

Apache-2.0 © LivXue