Quality & security scorecard for the DSH plugin ecosystem: sync the dsh-plugin topic catalog, audit any plugin (0-100, A-D, security veto), rankings, search, and historical score curves with a workspace-persisted catalog.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:863683348/dsh-plugin-scorecard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
DSH 插件体检评分卡:质量与安全审计、榜单与搜索。Quality & security scorecard, rankings and search for the dsh-plugin ecosystem.
一个 Cordis 插件,把「哪些插件值得装、哪个有风险」变成可执行的评分与报告:
- plugin_sync_catalog 同步 GitHub
dsh-plugintopic 目录(star 排序,可配上限) - plugin_audit <名称> 对单个插件出体检报告:0-100 分、A/B/C/D 等级、信号明细、证据链;高危安装脚本一票否决(🚨 封顶 30 分)
- plugin_top 榜单(按评分 / star / 最近更新)
- plugin_search <关键词> 语义搜索目录
- plugin_history <名称> 历史评分曲线(时间/分数/等级、趋势方向)
- plugin_export 导出目录与评分开放数据 JSON(默认
.dsh/scorecard-export.json)
Compatibility
Tool schemas are validated against the @deepseek-ai/dsh-tools value-schema DSL at plugin load (checked against dsh-tools 0.1.0-rc.6 and 0.1.1-rc.2). Earlier releases used JSON-Schema required at the root of output.schema and closed nested objects without declared properties, which made the host abort the whole profile boot with unsupported JSON schema: schema.required is not supported by the value schema DSL and could reject the tool's own results. Current releases fix both; if an affected version left your DSH unable to start, remove the plugin from the profile (or upgrade) — no data is lost.
评分模型
| 维度 | 满分 | 说明 |
|---|---|---|
| 维护活跃度 | 30 | 最近 push、star 量、是否归档 |
| 文档质量 | 25 | README、描述、许可证、标签 |
| npm 可装性 | 15 | npm 包存在性、更新度、周下载 |
| 安全 | 30 | 安装脚本高危模式(curl |
等级:A ≥80 · B ≥60 · C ≥40 · D <40。命中高危模式 → 封顶 30 分 + 🚨 不推荐。
安装
dsh plugin add dsh-plugin-scorecard
或编辑 profile 的组合:cordis.patch.yml 已内置 insert 条目(id: dsh-plugin-scorecard)。
配置(可选)
| 字段 | 默认 | 说明 |
|---|---|---|
| githubToken | "" | GitHub Token,提升 API 限额(无 Token 时 60 次/小时) |
| securityScan | true | 是否扫描安装脚本 |
| cacheTtlMs | 900000 | 目录缓存 TTL(含工作区文件缓存) |
| catalogFile | .dsh/scorecard-catalog.json |
目录持久化文件(会话工作区内) |
| historyFile | .dsh/scorecard-history.json |
评分历史文件(会话工作区内) |
| historyMaxEntries | 100 | 历史快照条数上限 |
| exportFile | .dsh/scorecard-export.json |
开放数据导出文件(会话工作区内) |
| maxCatalogSize | 200 | 每次同步的仓库数上限 |
开发
node --check lib/index.js
node test/scorer.test.mjs # 主模块方式(沙箱里勿用 node --test)
node test/format.test.mjs
路线图
- v0.2 ✅:目录持久化(JSON 缓存)+ 历史评分曲线(plugin_history)
- v0.3 ✅:目录增量同步(新增/更新/未变/移出)+ 开放数据导出(plugin_export)
- v0.3:Web 设置页榜单(ui-settings-plugins 扩展点)+ 开放数据导出 JSON
- v0.4:企业审计报告导出 / 私有化
License
MIT
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8296
Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.
dsh-market/dsh-market★ 5354
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
kingOfSoySauce/dsh-skin-market★ 181
Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.
bradeGithub/DSH-Plugins-Marketplace★ 169
GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.
awesome-dsh-plugin/dsh-find-plugin★ 166
Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.
Sanqi-normal/dsh-webui-market-plugin★ 104
In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.