Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-find-plugin
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:awesome-dsh-plugin/dsh-find-plugin
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
English | 中文
A plugin that finds plugins — think /find-skills from skills.sh, for DSH.
Tell your agent what you want ("notify me on WeChat when a task finishes"), and it searches the DSH plugin ecosystem on GitHub for you — top results by stars, each with a one-line description and an install command.
Install
# from npm (prebuilt, recommended)
dsh plugin --profile web add dsh-find-plugin
# or from GitHub
dsh plugin --profile web add github:awesome-dsh-plugin/dsh-find-plugin
Usage
Restart dsh web after installing, then just talk to the agent — it calls
find_dsh_plugin on its own whenever plugin discovery helps:
- "What terminal TUI plugins are there?"
- "I want to get a WeChat notification when a task finishes — any plugin for that?"
- "Find me something for reviewing git diffs inside DSH."
Each result comes back with stars, a description, the repo link, and a
ready-to-run dsh plugin add command — ask the agent to install one and
it can run the command for you.
How it works
- Live GitHub repository search scoped to the official
dsh-plugintopic, re-ranked by stars (5-minute per-query cache). - When a result is also listed on
awesome-dsh-plugin, its hand-written
bilingual description from
plugins.jsonreplaces the GitHub one (thelangparameter picks the language) — ranking is untouched. - Every result comes with a ready-to-run
dsh plugin addcommand. Plugins are third-party code — review the source and pin a commit.
Rate limits and offline fallback
GitHub's search API allows only 10 requests/minute per public IP when
unauthenticated, and that quota is shared by every host behind the same egress
IP (carrier CGNAT, corporate NAT, …), so a search can fail with HTTP 403 for
reasons outside your control. The plugin therefore:
- uses the
GITHUB_TOKENDSH credential when one is configured (30 req/min, account-scoped, immune to shared-IP exhaustion). Optional — without it the tool still works, just closer to the anonymous limit; - retries a rate-limited (403/429) or failed request once, then degrades instead of failing: it falls back to keyword matches from the curated list and says so in the result note;
- caches the curated list on disk (
$DSH_HOME/cache/dsh-find-plugin/) and revalidates it withIf-None-Match/If-Modified-Since, so restarts and offline runs use the full ~3400-entry list instead of the small bundled snapshot. - says why a request failed. Node reports every transport failure as a bare
fetch failedand hides the useful part incause, so the plugin surfaces the chain (fetch failed ← certificate has expired (CERT_HAS_EXPIRED)) and names the one trap that otherwise looks like a plugin bug: a system proxy or VPN accelerator, which Node'sfetchignores unless DSH itself was started withNODE_USE_ENV_PROXY=1(or--use-env-proxy). A browser has no such rule — which is why GitHub opens fine and this still fails.
Compatibility
DSH plugin APIs are prerelease-versioned, and node-semver only lets a
prerelease satisfy a range that carries a prerelease on the same
major.minor.patch — so a peer range pinned to one host line silently stops
matching the next one. The declared @deepseek-ai/dsh-tools range therefore
names every shipped line through 0.1.7, and npm run check:peers (run in CI)
resolves the current latest/next host lines from the registry and fails the
day a new one is not covered.
Development
npm run typecheck # tsc --noEmit
npm test # offline tests (mocked fetch)
FINDP_LIVE=1 npm run test:live # opt-in real-network cases
License
MIT © awesome-dsh-plugin
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8076
Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.
dsh-market/dsh-market★ 4713
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
bradeGithub/DSH-Plugins-Marketplace★ 168
GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.
kingOfSoySauce/dsh-skin-market★ 162
Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.
Sanqi-normal/dsh-webui-market-plugin★ 103
In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.
vlln/plugin-registry#console★ 58
Ecosystem infrastructure: a thin browser console for managing official repository plugins (zero patches) plus a make-dsh-plugin skill for guided plugin development.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.