Sidebar skill picker: lists installed skills with Global and repo badges, session checks plus persistent auto-start, optional Guard, Codex/Grok/Hermes user skills, and /skill injection.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:wyzh0117/dsh-skill-select
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
dsh-SkillSelect
English · 中文
DSH web plugin: pick installed skills from a sidebar and inject them into the current session.
Features
- Lists every configured skill. Marks Global, and a repo label when it can be inferred.
- Skills: session-only checks. A skill appends
/skill-nameto the composer; a fully checked repo writes/repoand expands on send. Hiding and reopening the tab clears this session's checks. - Auto-start: persistent defaults, injected once on the first message of each session. Same grouping and checkboxes as Skills.
- Sort: Repo (default) / Name / Most used / Source. Repo and Source views fold by group.
- Guard (off by default): when on, model
skilltool calls outside Auto-start ∪ this session's picks are rejected. Typed/skillis never blocked. - Uses frontmatter
descriptionwhen present; otherwise generates one English line and caches it. Never writes skill files. - Also lists Codex / Grok / Hermes user skills (builtins skipped). Duplicates across agents are listed separately. Checks write
/name@agent; the plugin injects that source'sSKILL.md. These are not registered in the model'savailable_skills. - Update runs
git pullon git-backed skills and re-fetches skills with a per-skill origin marker. Root-level markers and skills with no source are skipped. A changelog appears in the panel.
Install
Web profile only.
dsh plugin --profile web add "github:wyzh0117/dsh-skill-select#main"
# local development — use link: so edits apply after restart
# dsh plugin --profile web add "link:/path/to/skill-select"
Restart dsh web, then hard-refresh the browser (Cmd/Ctrl+Shift+R).
DSH compatibility
| Plugin | DSH | Notes |
|---|---|---|
| 0.2.0 (current) | ^0.2.0-rc.2 |
Registers against the official right sidebar (see below). |
| 0.1.1 | ^0.1.0-rc.6 || ^0.1.5-rc.1 |
Last release for the 0.1.x lines; on 0.2.x the peer gate below skips it silently. |
| 0.1.0 | ^0.1.0-rc.6 |
Broken on 0.1.5+ — see below. |
dsh 0.2.0-rc.2 gates compatibility hard. dsh-app-boot reads the
package.json peerDependencies whose name is @deepseek-ai/dsh or starts
with @deepseek-ai/dsh-, runs
semver.satisfies(runtimeVersion, range, { includePrerelease: true }), and on
any failure it skips the whole bundle: the module is never imported and the
plugin row shows as disabled — silently. If the plugin stops loading after a
DSH upgrade, check these peer ranges against dsh --version first.
engines.dsh in dsh.plugin.json is not enforced in rc.2 (kept as metadata
only). Forced-load escape hatch when you really must: dsh plugin allow-version, which writes <profile>/compatibility.json.
rc.2 also split session reads into two tracks. ctx.sessions is now an
in-memory store of live sessions: sessions.get(id) answers only for a
session this process has activated. A session you merely opened in the web UI is
cold, so the old single-path code returned session "…" not found (404) for
every session that was visibly on screen. openSkillView() covers both: a live
agent becomes the scope and ctx.agentPresets.serviceFor(agent, "skills") picks
the registry; a cold session is read with
ctx.sessionQuery.observeSession(id, { projectionMode }) (→ header.cwd,
projections.values.agentPreset) and given a standing scope from
ctx.agentPresets.acquireScope(preset), because listing skills for a session
that never entered the process still needs one. Each handle is released in a
finally (Symbol.dispose / Symbol.asyncDispose) — an unreleased scope pins
the preset registry. SESSION_QUERY_SESSION_NOT_FOUND maps to 404, any other
query failure to 500, and hosts without sessionQuery fall back to
sessions.get(). Symptom to remember: a 200 response with skills: [],
while the same session clearly has skills available to the model, means the cold
path could not obtain a scope — usually because a @deepseek-ai/dsh-* row in the
profile was version-skipped and acquireScope (which pulls in the shell /
sandbox / tool chain) threw.
DSH 0.1.5 changed the client module table: @deepseek-ai/dsh-client-runtime is no
longer a seed package, so require("@deepseek-ai/dsh-client-runtime") throws
missed the module table and the browser reports Failed to load plugins
(the host itself starts fine). 0.1.1 replaces it with ctx.sessions.scope(sessionId)
and declares the 0.1.5 range. Client code may only require() platform seed
modules — which is why sidebar icons are inline SVG components.
Upgrading DSH? DSH upgrades only the CLI — plugins already installed in the profile keep the old API. Re-resolve them afterwards:
dsh plugin --profile web update # re-resolve github:/registry plugins
# link:/ local checkouts are used in place — just restart dsh web
Then run npm test in this repo: tests/dsh-compat.test.js fails loudly when a
DSH named export disappears, a client seed package goes away, or a
@deepseek-ai/dsh-* peer range no longer covers the installed runtime.
Sidebar
The plugin registers a tab in the official DSH right sidebar (dsh ≥ 0.2), in two stages — both must be correct:
- Page type —
ctx.sidebarRightTabs.register({ id: "dsh-skill-select", kind: "skill-select", priority: "extension", title: () => "Skills", guide: [{ id: "dsh-skill-select", order: 70, /* … */ icon: SkillIcon }] }).kindis the discriminatorctx.sidebarRight.openTab(kind)uses; theguideentry is what shows Skills on the sidebar guide page.guide[].idis required — two entries without anidthrow "duplicate guide entry id". - Keyed slots —
ctx.slots.register({ name: "sidebar.right.pane.tab", key: "dsh-skill-select", inject: () => ({ rootCtx: ctx }) }, SkillSelectTab)for the body andsidebar.right.pane.tab.titlefor the pill title. The slotkeymust equal the stage-1 id, not the kind; a list-shaped{id, order}on a keyed slot is a failed registration. Both registrations run insidectx.effect(...)viactx.slots.inject(slotName, cb), so load order can't break them.
Open the right sidebar and pick Skills on the guide page.
ctx.sidebarRight.openTab("skill-select") always expands the sidebar and
throws while no Session is on screen. The tab body receives sessionId plus
useTabInfo(), gates its skill fetch on tab.visible, and resets the
session's checks on hide→show.
No third-party sidebar and no self-drawn fallback UI: without the official sidebar there is simply no tab.
Develop
node --test
node --check lib/index.js && node --check lib/client.js
Design: docs/design.md.
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-skill-explorer★ 8405
Skill center for the dsh web GUI: browse all loaded skills grouped by source, enable or disable model invocation, create new skills, and delete into a recoverable trash.
GanyuanRan/Aegis★ 1322
Software-engineering method pack for coding agents, with skills for baseline-first planning, systematic debugging, prompt hygiene, verification before completion, and repair/retirement tracking.
superdesigndev/superdesign-skill★ 624
Design skill for UI and marketing graphics on the Superdesign canvas: reads the repo for context, extracts its design system, then generates and iterates branchable design drafts, flow pages, and reusable components through the Superdesign CLI.
linhay/harmony-next.skills★ 360
HarmonyOS NEXT skill bundle for DeepSeek Harness with offline API references and DevEco, HDC, and emulator automation guidance.
dhicoc/dsh-reverse-skill★ 206
Complete reverse-skill pack (85 SKILL.md) as a DeepSeek Harness Cordis plugin: reverse engineering, authorized pentesting and security-research skill router.
sandbaseai/sandbase-skills★ 201
Mounts 88 packaged research, social-intelligence, marketing and business Agent Skills into dsh through the filesystem Skill provider.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.