DSH 插件生态体检评分卡:同步 dsh-plugin 目录,对任意插件做质量与安全审计(0-100 分、A-D 等级、安全一票否决),榜单、搜索与历史评分曲线(目录持久化)。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:863683348/dsh-plugin-scorecard
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
DSH 插件体检评分卡:质量与安全审计、榜单与搜索。Quality & security scorecard, rankings and search for the dsh-plugin ecosystem.
一个 Cordis 插件,把「哪些插件值得装、哪个有风险」变成可执行的评分与报告:
- plugin_sync_catalog 同步 GitHub
dsh-plugintopic 目录(star 排序,可配上限) - plugin_audit <名称> 对单个插件出体检报告:0-100 分、A/B/C/D 等级、信号明细、证据链;高危安装脚本一票否决(🚨 封顶 30 分)
- plugin_top 榜单(按评分 / star / 最近更新)
- plugin_search <关键词> 语义搜索目录
- plugin_history <名称> 历史评分曲线(时间/分数/等级、趋势方向)
- plugin_export 导出目录与评分开放数据 JSON(默认
.dsh/scorecard-export.json)
Compatibility
Tool schemas are validated against the @deepseek-ai/dsh-tools value-schema DSL at plugin load (checked against dsh-tools 0.1.0-rc.6 and 0.1.1-rc.2). Earlier releases used JSON-Schema required at the root of output.schema and closed nested objects without declared properties, which made the host abort the whole profile boot with unsupported JSON schema: schema.required is not supported by the value schema DSL and could reject the tool's own results. Current releases fix both; if an affected version left your DSH unable to start, remove the plugin from the profile (or upgrade) — no data is lost.
评分模型
| 维度 | 满分 | 说明 |
|---|---|---|
| 维护活跃度 | 30 | 最近 push、star 量、是否归档 |
| 文档质量 | 25 | README、描述、许可证、标签 |
| npm 可装性 | 15 | npm 包存在性、更新度、周下载 |
| 安全 | 30 | 安装脚本高危模式(curl |
等级:A ≥80 · B ≥60 · C ≥40 · D <40。命中高危模式 → 封顶 30 分 + 🚨 不推荐。
安装
dsh plugin add dsh-plugin-scorecard
或编辑 profile 的组合:cordis.patch.yml 已内置 insert 条目(id: dsh-plugin-scorecard)。
配置(可选)
| 字段 | 默认 | 说明 |
|---|---|---|
| githubToken | "" | GitHub Token,提升 API 限额(无 Token 时 60 次/小时) |
| securityScan | true | 是否扫描安装脚本 |
| cacheTtlMs | 900000 | 目录缓存 TTL(含工作区文件缓存) |
| catalogFile | .dsh/scorecard-catalog.json |
目录持久化文件(会话工作区内) |
| historyFile | .dsh/scorecard-history.json |
评分历史文件(会话工作区内) |
| historyMaxEntries | 100 | 历史快照条数上限 |
| exportFile | .dsh/scorecard-export.json |
开放数据导出文件(会话工作区内) |
| maxCatalogSize | 200 | 每次同步的仓库数上限 |
开发
node --check lib/index.js
node test/scorer.test.mjs # 主模块方式(沙箱里勿用 node --test)
node test/format.test.mjs
路线图
- v0.2 ✅:目录持久化(JSON 缓存)+ 历史评分曲线(plugin_history)
- v0.3 ✅:目录增量同步(新增/更新/未变/移出)+ 开放数据导出(plugin_export)
- v0.3:Web 设置页榜单(ui-settings-plugins 扩展点)+ 开放数据导出 JSON
- v0.4:企业审计报告导出 / 私有化
License
MIT
链接
同类插件
zhu1090093659/dsh-web#packages/dsh-plugin-manager★ 8296
设置 → 插件 分区里的插件管理 Tab:从 npm/git 安装带进度、下次启动生效的启停开关、安装冲突对账可撤销、失败一键转交修复会话。
dsh-market/dsh-market★ 5354
在 DeepSeek Harness 设置页内浏览、搜索并安装社区插件,支持分类筛选、一键更新与停用,以及主题切换与配置备份。
kingOfSoySauce/dsh-skin-market★ 181
原生皮肤市场与生命周期管理器,发现社区皮肤、展示预览与兼容状态,并提供已验证的一键安装或手动安装入口。
bradeGithub/DSH-Plugins-Marketplace★ 169
面向 GitHub dsh-plugin 话题的插件与技能市场:设置页内逛自动收录的全量索引(CI 每 2 小时刷新),一键安装带类型识别、安装脚本与宿主依赖遮蔽安全检查、环境变量密钥管理,并附 STANDARD.md 识别层规范。
awesome-dsh-plugin/dsh-find-plugin★ 166
会话内直接找插件:按关键词/分类搜索本精选 registry,返回描述与可直接执行的安装命令。
Sanqi-normal/dsh-webui-market-plugin★ 104
dsh Web GUI 内的社区插件市场:浏览 awesome-dsh-plugin.com 目录,从 设置 → 插件 → 插件市场 安装/卸载插件到 profile。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。