Sidebar skill hub: scan Claude/Codex/Cursor/Gemini skill directories for one-click import, manage global/project skills (toggle, trash), and install from dropped folders, zip archives, or local paths of any size.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-skill-station
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:WilShi/dsh-skill-station
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
English | 中文
A skill hub inside DeepSeek Harness: one sidebar button opens a panel that scans the skill libraries of Claude Code, Codex CLI, Cursor, and Gemini CLI, imports skills with one click, manages global and project skills, and installs a skill folder by dragging it in.
Install
dsh plugin --profile web add dsh-skill-station
Restart dsh web. The station appears as a 技能站 button above Settings in the sidebar, and as a settings section.
What you get
- Skill library — every skill in the writable roots, grouped: global
~/.dsh/skills, shared~/.agents/skills, and per-workspace<project>/.dsh/skills/.agents/skills. Search and user-defined scene tags, enable/disable (rewrites thedisable-model-invocationfrontmatter flag), delete into a restorable trash. - Detail, edit, export — open any skill to browse its file tree and edit files in place (saving SKILL.md re-reads the invocation flags live), download it as a re-importable zip, and scaffold new skills from a wizard. A diagnostics pass flags every skill the host loader would ignore — strict-YAML, missing fields, legacy keys — with one-click repair for broken frontmatter.
- External import — read-only scan of
~/.claude/skills,~/.codex/skills,~/.cursor/skills,~/.gemini/antigravity/skillsand~/.gemini/skills, plus each selected workspace's.claude|.codex|.cursor|.gemini/skills. Pick candidates, choose a target root, import with a conflict policy (skip / rename / replace — replaced skills go to the trash). Skills appear in the session catalog without a restart. - Drag-and-drop install — drop a skill folder (or several) or a
.ziparchive onto the install tab, or pick them. Zip archives are decompressed server-side, which also carries large skills with vendored dependency trees. Files are validated (SKILL.md with kebab-casenameanddescription) and previewed before anything is written. - Local path install — paste the absolute path of a skill folder already on this machine and the server copies it disk-to-disk: no upload, no size limit. Every install is staged and renamed into place, so a failed copy never leaves a half-installed skill.
- Trash — deletions move to
~/.dsh/skill-station/trashwith an origin manifest; restore or empty from the panel.
Security model
- Writes only ever land inside the writable skill roots listed above; every path is containment-checked after normalization, symlinks are never followed during copies, and uploads reject traversal segments.
- Mutating HTTP endpoints reject cross-origin requests; the API is served on the same local server as the GUI.
- External agent directories are scanned read-only; the station never modifies them.
- Uploaded and imported skills are third-party content — review them before enabling.
Config
All fields optional, under the dsh-skill-station plugin row in your profile patch:
plugins:
dsh-skill-station:
maxBodyBytes: 67108864 # upload request cap (default 64 MB)
sources: # replace the default scan sources entirely
- id: claude
label: Claude Code
userDirs: ['~/.claude/skills']
projectDirs: ['.claude/skills']
Development
npm install
npm run build # tsc server build + esbuild client bundle
npm test # vitest unit tests
node scripts/smoke.mjs # in-process API smoke (needs a prior build)
The client bundle is served through the shell's window.__ModuleLoader__ and registers into the sidebar.footer.action and settings.section slots.
License
MIT
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-skill-explorer★ 8405
Skill center for the dsh web GUI: browse all loaded skills grouped by source, enable or disable model invocation, create new skills, and delete into a recoverable trash.
GanyuanRan/Aegis★ 1322
Software-engineering method pack for coding agents, with skills for baseline-first planning, systematic debugging, prompt hygiene, verification before completion, and repair/retirement tracking.
superdesigndev/superdesign-skill★ 624
Design skill for UI and marketing graphics on the Superdesign canvas: reads the repo for context, extracts its design system, then generates and iterates branchable design drafts, flow pages, and reusable components through the Superdesign CLI.
linhay/harmony-next.skills★ 360
HarmonyOS NEXT skill bundle for DeepSeek Harness with offline API references and DevEco, HDC, and emulator automation guidance.
dhicoc/dsh-reverse-skill★ 206
Complete reverse-skill pack (85 SKILL.md) as a DeepSeek Harness Cordis plugin: reverse engineering, authorized pentesting and security-research skill router.
sandbaseai/sandbase-skills★ 201
Mounts 88 packaged research, social-intelligence, marketing and business Agent Skills into dsh through the filesystem Skill provider.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.