GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:bradeGithub/DSH-Plugins-Marketplace
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
中文 · English
A plugin marketplace for DeepSeek Harness (DSH): it indexes every repository under the GitHub dsh-plugin topic and presents them as cards in the DSH Web GUI settings page — one-click install, version detection, and auto-update, no command line required.
- Install
- What you do in the settings page
- Versus searching GitHub yourself
- How plugin authors get listed
- Known limitations and disclaimer
Install
Official CLI (recommended — installed and registered by Harness's own mechanism):
dsh plugin --profile web install bradeGithub/DSH-Plugins-Marketplace
Uninstall / update:
dsh plugin --profile web remove bradeGithub/DSH-Plugins-Marketplace
dsh plugin --profile web install bradeGithub/DSH-Plugins-Marketplace # reinstall = update
Without the dsh CLI, use the install script (it automatically defers to the CLI when detected):
| Platform | Command |
|---|---|
| Windows (PowerShell) | irm https://raw.githubusercontent.com/bradeGithub/DSH-Plugins-Marketplace/main/install.ps1 | iex |
| macOS / Linux | curl -sL https://raw.githubusercontent.com/bradeGithub/DSH-Plugins-Marketplace/main/install.sh | bash |
[!WARNING] The install script downloads and executes code from this repository — trust-to-execute; review the script before running it. The official CLI path runs no third-party scripts. The plugin registers itself into
~/.dsh/profiles/web/cordis.patch.ymland loads with every DSH start; after installing, restart DSH (re-rundsh web) and refresh the page.
Manually: clone this repository to ~/.dsh/profiles/web/node_modules/dsh-plugin-marketplace and register it in ~/.dsh/profiles/web/cordis.patch.yml:
- insert:
- id: dsh-plugin-marketplace
name: dsh-plugin-marketplace
One sentence to hand to an AI (any AI with command execution works):
Install the DSH plugin marketplace (dsh-plugin-marketplace): run
dsh plugin --profile web install bradeGithub/DSH-Plugins-Marketplace; if there is no dsh CLI, clone https://github.com/bradeGithub/DSH-Plugins-Marketplace into ~/.dsh/profiles/web/node_modules/dsh-plugin-marketplace and register it in ~/.dsh/profiles/web/cordis.patch.yml (id: plugin-marketplace, name: dsh-plugin-marketplace), then restart dsh web.
What you do in the settings page
- Restart DSH, open the Web GUI, and go to Settings → DSH Plugin Marketplace.
- The list loads automatically (installed first, the rest by stars); the search box filters by name, category chips filter by column.
- Card buttons: Install (live-scrolling log) — if
API_KEY-style material is required a dialog asks for it (submit or skip); Update (appears when a newer version is detected); Installed (greyed out, nothing to do). - Switch to the General Skills tab to browse 20000+ skills with search, pagination, and one-click install.
Versus searching GitHub yourself
| Capability | This marketplace | Manual search & clone |
|---|---|---|
| Distribution | CI-built static index with multi-level fallback: Contents API → jsDelivr → raw → bundled index → disk cache; zero requests inside the 10-min TTL, search API (10 req/min unauthenticated) only when all sources fail | Every browse and page-turn spends unauthenticated API quota |
| Ingestion | CI scans the dsh-plugin topic every 2 hours and merges results into the index |
Depends on awesome lists or keyword searches — coverage is luck |
| Type adaptation | Auto-detects cordis plugin / SKILL.md / agent preset / install script, then installs dependencies and registers entries | You identify the plugin type, install deps, and write registration entries by hand |
| Risk confirmation | Third-party install scripts and npm lifecycle scripts ask for confirmation first; material is passed as env vars only and never persisted | You execute scripts from unknown repos directly |
| Version awareness | Installed version is compared against the index automatically; the button shows «installed vX → vY» | You track upstream releases and re-clone manually |
How plugin authors get listed
Tag your repository with the dsh-plugin topic — CI merges it into the index within 2 hours, no application or issue needed. Type-detection rules, install shapes, and common anti-patterns: STANDARD.en.md (中文).
flowchart LR
CI["GitHub Actions<br/>incremental topic:dsh-plugin scan every 2 h"] -->|committed back to main| REG["registry.json / skills.json<br/>static index"]
REG -->|"① Contents API .gz"| UI["marketplace list page"]
REG -->|"② jsDelivr → raw (.gz first)"| UI
REG -.->|"③ bundled index → disk cache"| UI
UI -.->|"only when all fail"| API["GitHub Search API<br/>10 req/min · 10-min TTL"]
UI --> CMP{"compare against installed.json<br/>six-stage installed detection"}
CMP -->|"not installed / update needed"| INS["clone → detect type → env-var scan"]
INS --> GATE{"install script or<br/>npm lifecycle script?"}
GATE -->|yes| OK["runs after in-page confirmation"]
GATE -->|no| DONE["write cordis.patch.yml<br/>and installed.json"]
OK --> DONE
CMP -->|"installed version is lower"| UPD["show «Update» button"]
- The index contains repo metadata only (name / description / stars / updated_at / topics / license); installs still clone directly from
github.com. - Six-stage installed detection: install manifest → managed-directory heuristics (
dirOwners) → self-identification → profile-mapping hit (slug/repo name/pkg_namewith bidirectionalrepositorycheck) → script cache → cached package-name mapping re-checked against profiles;@deepseek-ai/*official plugins are auto-excluded. - Marketplace self-update only accepts maintainer SSH-signed release tags (local verification + tag↔version↔commit SHA binding; unverifiable updates fail closed).
Layering, the index-build algorithm, the version-source table, and detection details: docs/ARCHITECTURE.md; the security model: docs/SECURITY.md.
~/.dsh/
├── profiles/web/
│ ├── node_modules/dsh-plugin-marketplace/ ← the plugin itself
│ └── cordis.patch.yml ← registration entry
└── marketplace/
├── cache/<owner>__<name>/ ← clone cache (install & version data source)
└── installed.json ← install manifest
| Endpoint | Method | Description |
|---|---|---|
/api/marketplace/list |
GET | plugin list (with installed / version state); ?refresh=1 forces a re-fetch |
/api/marketplace/skills |
GET | general skills list |
/api/marketplace/install |
POST | {repo, answers} → done / awaiting-input / aborted / failed / manual |
/api/marketplace/uninstall |
POST | {repo} full uninstall (registration entry and install record included) |
/api/marketplace/self-update |
GET / POST | self version check / signature-channel self-update |
/api/marketplace/check-update |
POST | manual version check for npm-type plugins |
/api/marketplace/feedback |
POST | install feedback, sanitized and synced to a GitHub issue |
/api/marketplace/env-keys / env-edit |
GET / POST | read env-var keys / write values for installed plugins |
/api/marketplace/backup · restore/diff · backup/webdav · restore/webdav |
GET / POST | backup export / restore diff / WebDAV push & pull |
/api/marketplace/logs |
GET | sanitized install-log export |
All write operations share one auth model: loopback requests pass directly; LAN requests require lanWrite: true plus the x-dsh-marketplace-token session header. Uninstall relies on the installed.json record — only plugins installed via this marketplace can be fully uninstalled. Full contract (body fields / return values / status machine): docs/HTTP-API.md.
Known limitations and disclaimer
- The install endpoint has no user authentication; protection is a loopback / LAN Host allowlist plus a CSRF header and Origin check — do not expose the DSH web port to untrusted networks.
- An install is a single long-lived POST (clone + build + material-confirmation rounds); a short-timeout reverse proxy may cut the connection — the backend keeps running, refresh the page to confirm the result.
- Version detection only applies to cordis plugins with a
package.json; skills / presets / script types have no version concept. - «Installed» detection for script-type plugins relies on the cache directory; deleting the cache makes them installable again.
- Every plugin in the marketplace comes from a third-party repository maintained by its own authors and is not affiliated with DSH or this marketplace; listing is not a recommendation or endorsement. The marketplace is provided AS-IS with no warranty on plugin quality, security, or compatibility, and accepts no liability for any direct or indirect loss (including data loss, system damage, or privacy leaks) caused by installing or using third-party plugins — evaluate each repository yourself before installing. Full limitation list: docs/USAGE.md §7-8.
Harness Desktop: a third-party, community-maintained Windows desktop app whose stable release bundles this marketplace (entry submitted by the desktop author, who also maintains the marketplace fork shipped with the desktop app); awesome-dsh-plugin: the community-curated list that powers the «community listed» badge, cross-linked with this marketplace. Neither is affiliated with DeepSeek.
Code contributors: lgnorant-lu (write-endpoint auth, security hardening PR #63, mechanized testing system PR #66, and more core work), baiyuscc13724-max (Harness Desktop integration and install-flow simplification #1/#2), anupamme (OrbisAI Security — verify-installability SSRF allowlist #213); any / bubble / tatakaria — early contributions. Ecosystem collaborators: qing3a (dsh-plugin-verify, powering the "✓ verified" badge), wwumit (skills-catalog, powering the "disclosed ✓" badge), ylwl1997 (dshbase listing mutual recognition), the awesome-dsh-plugin maintainers (mutual listing PR #994).
Thanks to every user who reported issues through marketplace feedback or GitHub issues — your reports directly drive the fix cadence. To contribute, see docs/CONTRIBUTING.md and the STANDARD.en.md §7 self-check list.
Development and contribution: docs/DEVELOPMENT.md and docs/; version history: docs/CHANGELOG.md. License: MIT.
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8178
Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.
dsh-market/dsh-market★ 5004
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
kingOfSoySauce/dsh-skin-market★ 169
Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.
awesome-dsh-plugin/dsh-find-plugin★ 156
Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.
Sanqi-normal/dsh-webui-market-plugin★ 104
In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.
vlln/plugin-registry#console★ 58
Ecosystem infrastructure: a thin browser console for managing official repository plugins (zero patches) plus a make-dsh-plugin skill for guided plugin development.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.