Runtime plugin loading for the Web UI: a watched hot directory installs/updates client-plugin bundles live on every open page, no restart. Includes a right-column subagent dashboard example.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:tianyaZTY/dsh-hot-plugin-host
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Runtime plugin loading for DeepSeek Harness Web — no restarts.
The DSH loader tree is composed at boot, so adding a static client plugin (a UI panel, a widget, a dashboard) normally requires restarting dsh web. This plugin fixes that: it watches a hot directory and installs/updates client plugin bundles at runtime on every open page.
write a bundle → ~/.dsh/hot-plugins/<id>/client.js
↓ (host polls every 1.5s)
/ hot-plugins/list + SSE events + bundle serving
↓ (browser half)
fetch → __ModuleLoader__.load → loader.create (full cordis fiber lifecycle)
↓
the plugin goes live on every open page — no restart, no refresh
Updates work the same way (overwrite the file → invalidate + live refresh). Delete the directory → the plugin disappears on next page load.
Install
# from this repo
mkdir -p ~/.dsh/profiles/web/node_modules
ln -s "$PWD" ~/.dsh/profiles/web/node_modules/dsh-hot-plugin-host
# add "dsh-hot-plugin-host" to dsh.profile.bundles in
# ~/.dsh/profiles/web/package.json
Then restart dsh web once (the host itself is a boot plugin). From then on, every future plugin ships through the hot dir with zero restarts.
npm:
dsh-hot-plugin-host(once published)
Usage
Drop a bundle into the hot directory:
mkdir -p ~/.dsh/hot-plugins/my-widget
cp examples/demo-widget/client.js ~/.dsh/hot-plugins/my-widget/
# within ~1.5s it is live on every open page
A hot bundle is the same __ModuleLoader__.load format as a boot bundle:
window.__ModuleLoader__.load({
id: "my-widget", // must equal the directory name
factory: (require) => {
// require() only modules in the client table: react, react/jsx-runtime,
// @deepseek-ai/dsh-client-runtime/client, ...
const inject = ["sessions", "slots", "locale"];
function apply(ctx) { /* full plugin powers: ctx.slots.register(...) */ }
exports.apply = apply;
exports.inject = inject;
return module.exports;
}
});
- id:
[A-Za-z0-9@._-], single path segment, no/ - routes:
GET /hot-plugins/list,GET /hot-plugins/events(SSE),GET /hot-plugins/<id>/client.js - hot dir:
DSH_HOT_PLUGINSenv override, default~/.dsh/hot-plugins(auto-created)
Examples
| Example | Description |
|---|---|
packages/dsh-client-ui-subagent-dashboard |
Subagent dashboard in the right column: live status, expandable details, background jobs, one-click open of the child session transcript. Ships as its own npm package; also works as a hot bundle. |
examples/demo-widget |
Minimal self-contained hot bundle: a live status chip. |
Security
The hot directory is a trust boundary, equivalent to the boot bundles list (a hot plugin gets full client-side service access). Local development machines only — never point it at untrusted content.
How it works
- Host half (
lib/index.js): registers/hot-pluginsroutes onctx.webServer(list / SSE / bundle), polls the hot dir (mtime+size → rev), broadcastschangeevents. - Browser half (
lib/client.js): injectsloader; reconciles on connect (list), subscribes to SSE, fetches changed bundles, executes them via the standard module loader, then mounts them withloader.create— the exact mechanism the officialdsh-cordis-client-runneruses for dynamic packages, giving hot plugins the full fiber lifecycle (activation gating, effect cleanup, status projection).
Related
- dsh-market — the community plugin market UI inside DSH (browse/search/one-click install)
- awesome-dsh-plugin — the curated registry this project is listed in
MIT
Links
More in this category
yjh051108/dsh-routing-suite★ 7003
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3666
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 166
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 155
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.