Manage Git-backed DSH plugin markets, installed agent skills and optional Codex hooks from the web settings page.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:Diluka/dsh-agent-plugin-market
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
DSH(DeepSeek Harness)插件市场:将 Git 仓库作为 agent 内容市场。它克隆市场仓库,按当前作用域启用的插件或显式启用的根 skills/ 目录发现技能,并通过 DSH 技能 provider 原地提供这些技能。
- 市场与插件清单:市场清单依次识别
.agents/plugins/marketplace.json、.claude-plugin/marketplace.json、.cursor-plugin/marketplace.json、.github/plugin/marketplace.json和根marketplace.json;插件清单依次识别.codex-plugin/plugin.json、.claude-plugin/plugin.json和根plugin.json。 - 技能生命周期:已安装插件的有效技能默认启用;市场根
skills/中未被插件引用的独立技能默认关闭,并可单独或按市场批量启用。 - 工作区覆盖:设置页可在全局默认和已注册工作区之间切换。工作区为插件、插件技能和独立技能保存稀疏的启用/禁用覆盖;缺少覆盖时继承全局配置。
- 代理工具:通过插件配置的「功能」开关控制
agent_market_info、agent_market_set_plugin和agent_market_set_skill,让代理查看市场状态并只修改工作区覆盖;支持注入简短工具用法提示词。工具关闭时也停止注入提示词,具体配置见 代理市场工具。home 路径会话会被 scoped restriction 隐藏这些工具;若运行时未能隐藏,执行时也会拒绝。 - 原地加载:安装插件只保存安装状态,不复制市场文件。技能的
resourceBase指向克隆后的技能目录,因此技能内的相对资源可用。 - Codex hooks(可选):从 Codex 插件清单发现 hooks 配置;只有已安装的插件才能启用它们。启用需要设置页的双重确认、配置指纹审批和可用的
@deepseek-ai/dsh-hooks-codexbridge。 - 设置页:设置菜单添加「技能与挂钩」区段,提供市场、插件、技能和 hooks 的管理及目录筛选。
安装
当前开发依赖和 CI 验证版本为 DSH 0.2.0-rc.2(当前 npm latest 与 next 发布线)。Host 显式注入 webServer;bundle patch 同时为 connection 提供方补充 webServer,保留其原有 webRuntime 依赖。这同时满足自定义 RPC 通道的调用方依赖及新版 Connection getter 的提供方 shadow 上下文检查,仅修改 Host 的注入列表仍会启动失败。
在 DSH Web 侧边栏「插件」中添加并安装 dsh-agent-plugin-market bundle。安装后在设置页「技能与挂钩」中管理市场。包的 cordis.patch.yml 将 Host 插件加入 web profile,package.json 中的 dsh.client 声明加载浏览器端设置页。
@deepseek-ai/dsh-client-ui-primitives、@deepseek-ai/dsh-home-paths 和 @deepseek-ai/schemastery 是运行时 peer dependencies,由 DSH 运行环境提供。工具与提示词开关保存在 profile entry 的 volatile Config fields 中,通过 DSH Config Forms 即时编辑,并以内联方式显示在插件 bundle 详情页。市场与技能功能不依赖 hooks bridge;bridge 缺失时,设置页显示通过 profile 依赖安装所需包的命令,并禁用 hooks 开关。Host RPC 使用 DSH 0.2.0-rc.2 的 Connection 通道,由运行时统一执行 Host/Origin 校验和浏览器会话 token 认证;通过认证的本机或网络 Web 页面都可管理 Host 上的市场、Git checkout 和 hooks。代理工具只暴露读取和工作区覆盖写入,不执行市场添加、删除、Git 更新、全局安装/卸载或 hooks 授权。
启用 Codex hooks(可选)
官方 DSH CLI 0.2.0-rc.2 已包含 Codex bridge;可用不代表 hooks 已授权,仍需设置页的双重确认。对于不含 bridge 的自定义部署,在运行于目标 profile 的 DSH shell 中执行以下命令,再重启 DSH。bridge 是可选的运行时依赖,不是可从侧边栏「插件」独立安装或加入 profile bundle 列表的 bundle:
pnpm --dir "$DSH_PROFILE_DIR" add @deepseek-ai/dsh-hooks-codex@0.2.0-rc.2 @deepseek-ai/dsh-hook-protocol@0.2.0-rc.2
使用
- 添加市场:输入 SSH 或 HTTPS Git 仓库地址;可选择默认分支、分支、标签或 commit。市场必须提供含
plugins数组的市场清单,或在根skills/目录中提供至少一个有效的独立技能。 - 修改市场引用:已添加市场可随时改为默认分支、指定分支、标签或 commit。保存时会先克隆并校验目标引用,校验通过后替换当前市场 checkout;切回默认分支会删除持久化的
refType/ref。 - 安装插件:市场清单的每项插件由
source指向市场内的插件目录;未声明source时使用仓库根目录。字符串source和{"source":"local","path":"<仓库内路径>"}都可用;./指向仓库根。{"source":"url","url":"..."}仅在 URL 规范化后等于当前市场仓库时被视为仓库根插件,其他 URL 来源会标记为不支持。所有路径都必须解析在市场根目录内。 - 更新市场:Host 启动时会依次对默认分支和分支引用执行
git pull --ff-only;失败只记录错误并继续其他市场。标签和 commit 是固定引用,手动或自动更新都会跳过。更新按钮复用相同逻辑。 - 管理技能:安装插件后,其有效技能默认进入 DSH 技能目录,可逐项关闭。根
skills/中未被插件引用的技能需要先显式启用,支持逐项或整组切换。 - 工作区覆盖:在工作区列表的项目操作菜单中点击「配置插件与技能」打开该工作区的配置弹窗;设置页的「配置作用域」也可切换全局默认或工作区视图。选择工作区后,插件和技能使用三态菜单:继承全局、仅此工作区启用、在此工作区禁用。插件级禁用会屏蔽该插件的所有技能;但对单个技能启用「仅此工作区启用」会独立生效——即使该插件自身继承全局且未安装,该技能仍会在本工作区加载。重置覆盖立即恢复全局值。市场添加、修改引用、更新和移除仍属于全局操作。
- 管理 hooks:已安装且声明 Codex hooks 的插件初始未授权。bridge 可用时,第一次点击开关只显示确认,第二次点击才保存当前配置指纹并尝试挂载。授权状态和已挂载状态分别显示。hooks 和其审批在当前版本仍为全局配置。
- 代理工具:代理可调用
agent_market_info查看市场、插件、技能、hooks、工作区和当前作用域;可调用agent_market_set_plugin写入某个插件的工作区三态覆盖;可调用agent_market_set_skill写入某个技能的工作区三态覆盖。两个写入工具默认使用当前会话cwd匹配到的工作区,也接受workspace_id;home 路径会话不可使用这些工具。参数和返回作用见docs/agent-tools.md。
市场清单查找顺序如下:
.agents/plugins/marketplace.json
.claude-plugin/marketplace.json
.cursor-plugin/marketplace.json
.github/plugin/marketplace.json
marketplace.json
市场与技能格式
一个常见的市场布局如下:
<market-repo>/
├── .agents/plugins/marketplace.json
├── plugins/<plugin-name>/
│ ├── .codex-plugin/plugin.json
│ ├── hooks/
│ │ └── hooks.json
│ └── skills/
│ └── <skill-name>/
│ └── SKILL.md
└── skills/
└── <standalone-skill>/
└── SKILL.md
插件清单的 skills 可以是字符串、字符串数组,或含 paths 的对象;未声明时默认扫描插件的 skills 目录。Awesome Copilot 兼容布局使用 extensions["com.github.awesome-copilot"].skills,其中只接受指向市场根 ./skills 或其子路径的条目。
每个技能源目录只扫描两类直接子项:子目录中的 SKILL.md,以及目录自身的直接 .md 文件。有效技能必须具有 frontmatter,且至少包含:
---
name: my-skill
description: 说明何时应触发该技能。
whenToUse: 可选补充。
---
技能正文(Markdown 指令)。
name 必须匹配 [a-z0-9]+(?:-[a-z0-9]+)*;description 不能为空。可选触发说明接受 whenToUse 或 when_to_use。根 skills/ 中与某个插件技能同一文件、同一真实文件目标或内容相同的技能不会重复作为独立技能列出。
Codex hooks
只有 .codex-plugin/plugin.json 中的 hooks 会形成 Codex hooks 配置。该字段可以省略、写成一个插件根相对 JSON 路径、一个内联 JSON 对象,或由两者组成的数组:
{
"skills": "./skills",
"hooks": [
"./hooks/hooks.json",
{ "hooks": {} }
]
}
省略 hooks 时,插件会尝试读取 ./hooks/hooks.json。文件路径必须以 ./ 开头、位于插件根目录内、没有 ..、反斜杠或空路径段,且不能是符号链接;目标必须是包含 JSON 对象的普通文件。内联对象不经过文件读取。
为每份已批准的 hooks 配置生成 bridge 配置前,插件会为 type: "command" 或未声明 type 的 command 项注入以下环境变量:
PLUGIN_ROOT:插件根目录。PLUGIN_DATA:该市场插件的持久数据目录。CLAUDE_PLUGIN_ROOT:PLUGIN_ROOT的兼容别名。CLAUDE_PLUGIN_DATA:PLUGIN_DATA的兼容别名。
插件会把经验证的配置交给已安装的 Codex bridge。具体支持哪些事件点以及非 command hook 的执行语义由所安装的 bridge 和协议版本决定,不在本插件中硬编码。
审批使用配置来源和内容的 SHA-256 指纹,并在当前 hooks 配置指纹匹配已保存审批时生效。禁用、配置指纹变化、插件卸载和市场移除都会处置已挂载的 hook Fibers;当前 hooks 配置消失或不再是可用对象时也会清除对应审批。市场更新只在 Git 操作期间暂停该市场 hook Fibers,随后重新检查当前配置;更新是否成功不会直接撤销或恢复审批。审批仍有效但 bridge 注册失败时,审批保留,状态显示加载错误。
运行时存储
运行时基目录是 @deepseek-ai/dsh-home-paths 根据 $DSH_HOME 或默认 ~/.dsh 解析的 DSH home,再追加 agent-plugin-market。以下以 <dsh-home> 表示该解析结果:
- 市场、插件、技能开关和 hooks 审批:
<dsh-home>/agent-plugin-market/config.json - 市场克隆目录:
<dsh-home>/agent-plugin-market/markets/<id>/ - 生成的 bridge 配置:
<dsh-home>/agent-plugin-market/generated-hooks/ - 每个市场插件的 hooks 数据:
<dsh-home>/agent-plugin-market/hook-data/
每个工作区的覆盖文件是 <workspace>/.dsh/agent-plugin-market.json。运行时写入 version: 1,以及 plugins、pluginSkills 和 standaloneSkills 三组稀疏布尔覆盖值;没有某个覆盖键时继承全局状态。设置页和代理写入工具都使用同一个工作区覆盖文件。工作区文件可以按团队需要提交到版本控制或加入忽略规则。为避免目录逃逸,.dsh 目录和配置文件都不能是符号链接;用户 home 目录本身不作为工作区覆盖根,避免和全局配置目录混用。市场克隆、hooks 和 hooks 审批仍保存在 <dsh-home>。
卸载
在 DSH Web 侧边栏「插件」中卸载 dsh-agent-plugin-market bundle。如果 profile 的自定义 cordis.patch.yml 仍保留该包的插入条目,请移除该条目后重启 DSH。
开发与验证
pnpm install --frozen-lockfile
pnpm lint
pnpm test
pnpm typecheck
node --check lib/*.js test/*.test.js
git diff --check
pnpm lint执行eslint lib test;仓库的 ESLint 配置检查lib/**/*.js和test/**/*.js,并忽略test-repos/。pnpm test执行 Node 原生node --test。运行时扫描测试使用@platformatic/vfs的内存文件系统,并覆盖技能去重中的符号链接场景。pnpm typecheck执行tsc -p tsconfig.json,以 JavaScript + JSDoc 检查lib/**/*.js,加载types/client-bundle.d.ts,且不生成输出。- CI 启动检查用
.github/pin-dsh.cjs将 CLI 与 profile 子安装中的 DSH 依赖统一到DSH_VERSION,同时固定已验证的 Cordis 配套版本,并使用独立缓存。DSH0.2.0-rc.2已精确声明其 DSH 依赖;仍需固定本插件的通配 peer 和框架 patch 范围,避免 smoke 安装漂移。Smoke job 按当前 DSH CLI 通过 pnpm 准备临时 profile 并应用包内的 Cordis patch。矩阵只区分 profile 是否显式安装 hooks 依赖;CLI 已自带 bridge,因此不代表运行时真正缺少 bridge。hook manager 在 bridge 不可用时的降级由 Node 测试覆盖。升级 CI 目标版本时需一并核验 CLI 与框架配套契约。
架构
| 半端 | 文件 | 职责 |
|---|---|---|
| Host composition root | lib/index.js |
注入 DSH 服务,加载可选 bridge,创建 runtime、service 和 hook manager,注册技能 provider 与统一认证 RPC。 |
| Host runtime | lib/market-runtime.js |
管理全局与工作区配置路径和持久化,解析市场/插件清单,按会话 cwd 扫描与读取有效技能。 |
| Host service | lib/market-service.js |
执行市场 Git 生命周期、全局安装状态、工作区覆盖、技能开关、hooks 授权、状态视图和启动自动更新。 |
| Host features | lib/market-features.js |
注册 DSH 功能设置,按开关管理工具和简短系统提示词的生命周期。 |
| Host tools | lib/market-tools.js |
定义市场状态读取、工作区插件/技能覆盖工具及其用法提示,并为 home 路径会话做 scoped restriction。 |
| Host config model | lib/market-config.js |
纯配置状态转换:市场、插件安装、全局技能开关与工作区覆盖解析。 |
| Host Codex adapter | lib/codex-hook-manager.js |
检查 hooks 来源,协调审批,生成 bridge 配置并管理 Fiber 生命周期。 |
| Host hook plan | lib/hook-reconcile-plan.js |
纯 desired/active 差异计划,确定处置和挂载顺序。 |
| Host hook helper | lib/codex-hooks.js |
解析 hooks 来源和相对路径,计算指纹,生成稳定存储键并注入 command 环境。 |
| Client | lib/client.js |
浏览器入口,注册插件「功能」配置、「技能与挂钩」设置页和工作区配置弹窗;文件内拆分目录模型、共享控件与页面实现。 |
| Profile composition | cordis.patch.yml |
将双端插件包插入 web profile。 |
Hook 元数据按协议键存入 hookConfigs;当前实现只挂载 codex 适配器。
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8568
Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.
dsh-market/dsh-market★ 5992
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
kingOfSoySauce/dsh-skin-market★ 186
Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.
awesome-dsh-plugin/dsh-find-plugin★ 179
Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.
bradeGithub/DSH-Plugins-Marketplace★ 171
GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.
Sanqi-normal/dsh-webui-market-plugin★ 104
In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.