AwesomeHou/dsh-plugin-marketplace 预览 preview

AwesomeHou/dsh-plugin-marketplace

DeepSeek Harness 的插件市场——实时同步 GitHub 的 dsh-plugin 主题(1800+ 仓库),在可搜索、分页的设置标签页中呈现,支持一键安装和代理工具(market_search / market_install)。

Project Overview项目介绍

This repository is a DSH-native plugin that adds a full-featured plugin marketplace to DeepSeek Harness, pulling all plugin listings directly from the GitHub dsh-plugin topic. It registers two new tabs in DSH's existing Settings > Plugins panel: one for browsing and searching the full public plugin catalog, and another for managing plugins you have already installed. It also exposes four agent tools that let the DSH AI agent search for plugins, install new plugins, list installed plugins, and update existing plugins directly. The plugin supports full pagination of all results, so you are not limited to just the first 50 plugins returned by the GitHub API.

The marketplace is targeted at end users of DeepSeek Harness who want a convenient centralized way to discover new third-party plugins for their DSH instance. When you find a plugin you want to install, you just click the install button on the plugin card, and the marketplace will handle the entire installation process automatically. It detects the plugin structure, prioritizes npm-published plugins for faster, more stable installs, and handles common installation errors with clear, actionable error messages instead of raw unreadable technical output. If direct installation fails, it can fall back to an agent-assisted installation that creates a dedicated work area for the agent to handle non-standard setups.

The plugin is released under the permissive MIT license, so you can use, modify, and redistribute it freely in accordance with the license terms. It requires pnpm to manage plugin dependencies, and includes built-in handling for common pnpm issues like version mismatches and stalled download processes. After you install the plugin via either the DSH CLI command or by asking the DSH agent to install it for you, you will need to restart DeepSeek Harness for the marketplace to load properly. It also includes a self-update check that notifies you when a new version of the marketplace itself is available, so you can update it in one click.

本仓库是专为DeepSeek Harness(DSH)开发的原生插件,它将GitHub的dsh-plugin话题转换为一个完整的插件市场。它在DSH的「设置→插件」面板中新增了两个标签页,还提供了一组Agent工具,允许AI Agent直接搜索、浏览、安装、更新和管理第三方DSH插件。它支持对话题下所有插件进行全量分页,打破了50条结果的限制,并且使用GitHub原生搜索查询所有可用插件。

本插件面向需要集中发现和管理第三方DSH插件的DeepSeek Harness用户设计。典型使用流程是:用户在DSH设置的插件市场标签页中打开插件市场,搜索或浏览找到需要的插件,点击一键安装按钮后,插件会自动处理整个安装流程,包括依赖检测、错误分类处理,如果直接安装失败还会回退到Agent辅助安装。安装完成后,用户可以直接在市场界面检查更新、启用、禁用或卸载已安装的插件。

本插件以MIT许可证开源,使用pnpm管理依赖,内置了针对不同pnpm大版本的兼容性处理。它自带停滞看门狗,会自动终止卡住的安装进程并重试一次,避免无限等待。安装完成后需要重启DeepSeek Harness才能生效,支持两种安装方式:通过DSH CLI手动安装,或者直接让DSH Agent完成自动安装。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 30 stars - an early-stage project星标 30,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add https://github.com/AwesomeHou/dsh-plugin-marketplace

把 AwesomeHou/dsh-plugin-marketplace 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-marketplace

English | 中文

GitHub

一个 DeepSeek Harness 的永久插件,把 GitHub dsh-plugin topic 变成插件市场——既是 设置 → 插件 里的标签页,也提供一组模型工具,让 agent 自己就能搜索并安装插件。

插件市场截图 插件市场截图

插件市场:搜索、浏览、一键安装、检查更新。

功能

  • 全量分页 — 完整 topic 按页拉取(默认 50 / 最大 100),UI 带"加载更多"按钮。不再有"只看 50 个"的硬限制:total 反映真实的 total_count。
  • 搜索 — 关键词搜索走 GitHub 自己的 q(所以是在整个 topic 里搜,而不是只在已加载的页里过滤),UI 搜索框和 market_search 工具都用它。
  • Agent 工具(Host 侧通过 ctx.tools.register 注册):
    • market_search(q?, page?, perPage?) — 返回 topic 仓库的 JSON 列表(full name、star、语言、简介、URL)。
    • market_install(spec) — 通过 dsh plugin --profile web add -w <spec> 安装到 web profile。执行前会校验 spec 是否含 shell 元字符;完成后提示需要重启 harness。
    • market_installed() — 列出 web profile 已安装的第三方插件:启用状态、当前版本、最新版本与是否可更新(含市场自身的更新状态)。内置插件不在此列。
    • market_update(name) — 把某个已安装插件更新到最新版本(需重启 harness 生效)。
  • 安装(默认:直装,优先 npm 包) — 每个插件卡片都有 安装 按钮,点击后通过 POST /api/market/install 启动确定性的异步安装任务:host 侧 planInstall 先探测仓库形态——根 package.json 声明了 dsh.bundle/dsh.client 的根级插件走标准 dsh plugin add -w <spec>;已发布到 npm 的插件优先用 name@<latest> 装 npm 版(快、稳、免 GitHub 拉取,pnpm 把插件及运行时依赖如 ws/node-pty 一起装进 profile);未发布到 npm 的用 github spec;monorepo/workspace 根则克隆到 $DSH_HOME/marketplace-src、corepack pnpm 构建后 link: 注册(沙箱内自带 node_modules,依赖可解析)。装完做真实结果校验(进入 dsh.profile.bundles、入口文件存在、运行时依赖可解析——后一条专门防“link 缺依赖导致启动失败”的历史回归)。注意:不能用 link: 装根级插件。卡片内联渲染 App Store 式进度条(阶段 / 百分比 / 已下载 / 速度 / ETA / 实时日志),可取消。
  • pnpm 兼容层(借鉴 dsh-market) — 所有安装子进程注入 CI=true(pnpm ≥10 无 TTY 时不再无限等交互提示而卡死,遇错直接报错);检测到 pnpm 大版本漂移(ERR_PNPM_VIRTUAL_STORE_DIR_MAX_LENGTH_DIFF / PUBLIC_HOIST_PATTERN_DIFF,即 modules 目录由别的 pnpm 大版本创建)会自动 pnpm install 重建 modules 目录并重试一次。失败分类 classifyPnpmFailure 覆盖:预发布 peer 解析、构建脚本拦截(IGNORED_BUILDS/GIT_DEP_PREPARE_NOT_ALLOWED)、幽灵依赖 404、发布新鲜度等待期、workspace 缺失、pnpm 缺失等,统一给可操作文案而不是裸报错。
  • 安装卡住自动止损 — pnpm / git 在死网络或过慢的下载上可能零输出挂死(例如 GitHub 暂不可达时停在"正在解析依赖… 8%")。host 侧带停滞看门狗:一段时间(默认 120s,可用 DSH_MARKET_STALL_MS 覆盖)没有任何进度(无输出行、无字节增长)就杀掉进程树 → 自动直连重试一次(去掉字节统计代理)→ 若再次停滞则快速失败并提示「检查网络后重试,或改用「让 agent 安装」」,不再无限转圈等到 10 分钟超时。
  • 对等依赖失败识别 — 若插件声明了 @deepseek-ai/*@^0.1.0-rc.6 这类预发布对等依赖,dsh plugin add 可能以 ERR_PNPM_NO_MATCHING_VERSION 退出。host 侧会识别并给出可操作的说明(而不是裸的 "exit 1"),卡片同时提供 「让 agent 安装」 兜底按钮——agent 会按仓库 README / 安装脚本处理这类结构。
  • workspace 缺失的友好报错 — host 侧在安装/更新前检查 web profile:package.json 或 pnpm-workspace.yaml 缺失时,market_install / /api/market/install 会返回可操作的错误信息(告诉用户如何创建 pnpm-workspace.yaml 或重新初始化 profile),而不是 pnpm 那种晦涩的 --workspace-root may only be used inside a workspace。
  • agent 安装方案(兜底,专属工作区新开对话) — 当直装失败时(尤其对等依赖 / 非标准结构场景),卡片上会出现 「让 agent 安装」 按钮。点击后 host 会确保一个专属安装工作区($DSH_HOME/marketplace-install,经 GET /api/market/install-workspace 暴露),client 通过 runtime 的 workspaces.create / sessions.create / sessions.open 在该工作区新开一个对话并切过去,再把固定提示词 session.prompt 发给那个会话——由 agent 读 README 并自行决定安装方式,不污染当前会话、无需手动选工作区。若 runtime 服务不可用则回退为发给当前会话。代码在 lib/client.js 的 installViaAgent。更新/停用/卸载仍走 host 接口(/api/market/update 等)。
  • 更新插件(有新版本提示) — 每个已安装插件都会对照最新版本(npm registry 的 latest,或 GitHub 默认分支 package.json 的 version,GitHub 插件优先)。有新版本时在卡片上标 可更新 并给 更新 按钮(/api/market/update)。
  • 区分内置 / 后安装 — dsh.profile.bundles 里来自 profile 模板的包是内置插件(随 harness 提供,不能停用 / 卸载),dependencies 里的是后安装插件。已安装标签页只展示后安装(第三方)插件,内置插件不列出(页面顶部有声明)。
  • 后安装插件可停用 / 卸载 — 停用 / 启用(/api/market/set-enabled)通过把它移出 / 移回 dsh.profile.bundles 实现(依赖保留);卸载(/api/market/uninstall)通过 dsh plugin --profile web remove <name> 移除依赖并自动从 bundle 层摘除。两者都需重启 harness。
  • 写 profile 的操作串行落盘(可放心同时卸载多个) — 安装 / 更新 / 卸载 / 停用 / 启用都会读改写同一份 profile package.json(以及同一份 node_modules),host 侧把它们统一排进一条 FIFO 队列(onProfileWrite)。此前同时点多个插件的 卸载,两个 dsh plugin remove 会先各自读到旧 manifest 再写回,最后一次写入把前一个插件的依赖又恢复了——所以"同时卸载几个,最后只删掉一个"。现在它们依次执行,批量卸载会全部生效;对同一个插件重复 / 重叠的卸载是幂等的无变化返回,内置插件仍被明确拒绝(内置插件不能卸载),不会被误当成"已删除"而静默放行。
  • 进行中只留一个按钮 — 某个插件正在执行某个操作时,卡片上只保留它自己的那个按钮并把文案改成 更新中… / 停用中… / 启用中… / 卸载中…,其余按钮隐藏;不再出现"原按钮 + 一个通用处理中按钮"两个按钮同时转圈的情况。停用状态标记为 已停用(此前显示为"已关闭")。
  • 市场自更新检查 — 插件市场(本插件)会检查自己的最新版本(从其 GitHub 仓库 package.json 读取)。有新版本时在"插件市场"和"已安装"两个标签页顶部显示横幅:vX → vY · 立即更新。
  • 声明来源 — 插件市场标签页顶部声明插件清单的来源:GitHub dsh-plugin 话题(github.com/topics/dsh-plugin),通过 GitHub Search API 实时同步。
  • 并入插件设置 — 注册两个 settings.plugins.tab(market 插件市场、installed 已安装),与自带的"插件配置"、"插件列表"并列。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev everything-kiro 下一个 Next dsh-computer-use →