MCP server marketplace for DSH: browse a curated, npm-verified catalog and install MCP servers into the current profile with one click, live without restart.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-mcp-market
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:LKMeng2001/dsh-mcp-market
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
中文 | English
An MCP server marketplace inside DeepSeek Harness: browse a curated catalog and install MCP servers into the running profile with one click — live, no restart (powered by the official @deepseek-ai/dsh-mcp-client and the loader service).
Open Settings → MCP Market, search, click, done. The model immediately sees mcp__<serverName>__<tool> tools.
Features
- Browse / search / filter a bundled catalog (15 servers, every one verified usable), zh/en descriptions
- npm existence verification: every stdio entry is checked against registry.npmjs.org at load time; packages removed from the registry are greyed out and blocked from install (guards against dead entries and typosquat canaries)
- One-click install for
stdio(local process) andstreamable-http(remote URL); fill in command / args / env / url / headers before installing - Hot activation via
ctx.loader.create()— no restart; config persists across restarts - Installed list with enable/disable, config edit (HMR reconnect), and uninstall
- Manual "add a server" form for anything not in the catalog
- Offline fallback: remote registry JSON with an in-memory cache and a bundled snapshot
- Clean persistence: installs only touch a
# --- dsh-mcp-market managed ---block in the profile'scordis.patch.yml; your own edits are preserved verbatim
Install
# from npm (for everyone)
dsh plugin --profile web add dsh-mcp-market
# from a local checkout (dev only — replace the path with yours)
dsh plugin --profile web add "D:\path\to\dsh-mcp-market"
# update
dsh plugin --profile web update dsh-mcp-market
# remove
dsh plugin --profile web remove dsh-mcp-market
Restart dsh web, then open Settings → MCP Market.
Development
npm install
npm run build # tsc host → lib/, esbuild client → client/client.js
npm run typecheck
After changes: npm run build, restart dsh web (host changes; client changes can use a dev watcher).
Registry source
Live catalog: fetched from the GitHub Pages URL https://LKMeng2001.github.io/dsh-mcp-market/servers.json (canonical source is docs/servers.json in this repo — edit and push to update globally, no release needed), falling back to the bundled data/registry-snapshot.json (generated from docs/servers.json by npm run sync:catalog). A CI workflow checks every npm package in the catalog daily. Override per profile via the plugin config (registryUrl). Entry schema and the HTTP route/loader design are documented in README.zh.md.
Security
- Every mutating route is a same-origin POST with Origin checks
- MCP servers are third-party code/services: stdio servers spawn a local child process — install only sources you trust
- Config (incl. env) is stored in plaintext in the profile's
cordis.patch.yml; keep secrets out or encrypt before writing
License
MIT
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8121
Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.
dsh-market/dsh-market★ 4818
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
bradeGithub/DSH-Plugins-Marketplace★ 169
GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.
kingOfSoySauce/dsh-skin-market★ 165
Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.
awesome-dsh-plugin/dsh-find-plugin★ 154
Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.
Sanqi-normal/dsh-webui-market-plugin★ 103
In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.