Windows Package Manager: search, install, upgrade, uninstall, import/export and pin software through native tools.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:WODE25500/dsh-winget
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Windows Package Manager (winget) integration for DeepSeek Harness (dsh) — let your dsh agent search, install, upgrade, uninstall, and import/export Windows packages through native tools. All commands run non-interactively, so they work headlessly.
Independent community project, not official. Based on Microsoft's winget-cli (MIT).
Features
- 9 native dsh tools:
winget_search/winget_show/winget_install/winget_upgrade/winget_list/winget_uninstall/winget_export/winget_import/winget_pin - Bundled
SKILL.mdteaching the agent when and how to use them - Schemastery config (
wingetPath/alwaysAcceptAgreements/timeoutMs) - Bundle patch layer (
cordis.patch.yml) — drop into any profile - Non-interactive + auto-accept agreements by default (required for headless)
- Safety-first: install/uninstall/upgrade-all descriptions tell the agent to confirm first
Prerequisites
- DeepSeek Harness (dsh)
- Windows 10 1809+ / Windows 11 with winget (
winget --version)
Install
As a bundle in a profile
- insert:
- id: winget
name: './src/index.js'
config:
wingetPath: winget
alwaysAcceptAgreements: true
Local patch overlay
pnpm dsh web --patch ./dsh-winget/cordis.patch.yml
Then ask the agent: "Use winget_search to find VS Code and show its details."
Tools
| Tool | Behavior |
|---|---|
winget_search |
search (query/id/name/moniker/tag) |
winget_show |
package details (versions/source/installer) |
winget_install |
install (changes the system — confirm first) |
winget_upgrade |
upgrade one or all (all=true) |
winget_list |
installed packages / filter / export |
winget_uninstall |
uninstall (confirm first) |
winget_export / winget_import |
manifest export/import |
winget_pin |
version pinning add/list/remove |
Config
| Key | Default | Purpose |
|---|---|---|
wingetPath |
winget |
path to winget.exe |
alwaysAcceptAgreements |
true |
auto-accept package/source agreements |
timeoutMs |
600000 |
per-call timeout (installs can be slow) |
Known limitations
- winget has no JSON output in this build; tools return the table text (model-readable)
- Installs requiring admin may fail (UAC cannot prompt in non-interactive mode) — the error is returned as-is
- Some msstore packages require a Microsoft account
Layout
dsh-winget/
src/index.js # plugin entry: 9 tools + config
skills/winget/SKILL.md # agent skill
docs/ # docs
cordis.patch.yml # bundle patch layer
License
MIT.
Links
More in this category
yjh051108/dsh-routing-suite★ 7000
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3678
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 324
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 212
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
Fishquito7/dsh-skill-mcp-panel★ 175
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
lire1131/dsh-undo-savepoint★ 172
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.