Diluka/dsh-agent-plugin-market

DSH (DeepSeek Harness) plugin: uses git repositories as an agent plugin marketplace, installing and loading Codex/Claude-format skills in place.

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that turns Git repositories into a distributable marketplace for agent skills and plugins. Once installed, it clones user-specified market repositories, discovers available skills from either enabled plugins or the root skills/ directory, and serves these skills directly through DSH’s native skill provider. It recognizes multiple marketplace and plugin manifest formats used by other coding agents including Claude, Codex, and Cursor, handles skill lifecycle management, and supports per-workspace configuration overrides for skills and plugins.

To use this plugin, you first add a marketplace by entering the Git repository URL (SSH or HTTPS), and can optionally pin the marketplace to a specific branch, tag, or commit. After adding a marketplace, you can update the pinned reference, install plugins from the marketplace, toggle skill enablement, set per-workspace overrides for plugins and skills, and manage approved Codex hooks if you have the optional bridge installed. This plugin is designed for DSH end users who want access to third-party skills and plugins hosted on Git, as well as developers who want to distribute their skills without a centralized hosting service.

dsh-agent-plugin-market is released under the open-source MIT license. It requires DSH version 0.1.5-rc.1 or newer to work correctly, and has a peer dependency on @deepseek-ai/dsh-client-ui-primitives which is included by default in DSH profiles. The optional Codex hooks feature requires an additional bridge package to be installed in the same DSH profile. You install the plugin via the DSH CLI with the command dsh plugin --profile web add github:Diluka/dsh-agent-plugin-market, then restart DSH to access the management panel in DSH settings.

这是一个专为DeepSeek Harness(DSH)开发的原生插件市场插件,使用Git仓库作为代理技能内容的分发市场。它会克隆指定的市场仓库,根据当前作用域启用的插件或者显式启用的根skills目录发现技能,并通过DSH技能提供者原地提供这些技能。它支持识别多种来自Claude、Codex、Cursor等不同代理的市场和插件清单格式,同时管理技能生命周期并支持工作区配置覆盖。

用户使用时,第一步添加Git格式的市场仓库地址,可指定分支、标签或commit作为引用,接着可以修改市场引用、安装插件、更新市场、管理技能启用状态,还能配置工作区专属覆盖和管理Codex钩子。它面向需要从第三方Git市场获取额外代理技能和插件的DSH用户,也适合想要分发自有技能的开发者使用,不需要中心化托管就能分发内容。

本插件采用MIT许可证开源,依赖DSH 0.1.5-rc.1及以上版本,运行时依赖@deepseek-ai/dsh-client-ui-primitives,该依赖由DSH默认配置文件提供。若需要启用Codex钩子功能,还需额外安装对应的bridge包。安装可通过DSH CLI命令行完成,安装后重启DSH即可在设置面板找到管理入口。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:Diluka/dsh-agent-plugin-market

把 Diluka/dsh-agent-plugin-market 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-agent-plugin-market

DSH(DeepSeek Harness)插件市场:将 Git 仓库作为 agent 内容市场。它克隆市场仓库,按当前作用域启用的插件或显式启用的根 skills/ 目录发现技能,并通过 DSH 技能 provider 原地提供这些技能。

  • 市场与插件清单:市场清单依次识别 .agents/plugins/marketplace.json、.claude-plugin/marketplace.json、.cursor-plugin/marketplace.json、.github/plugin/marketplace.json 和根 marketplace.json;插件清单依次识别 .codex-plugin/plugin.json、.claude-plugin/plugin.json 和根 plugin.json。
  • 技能生命周期:已安装插件的有效技能默认启用;市场根 skills/ 中未被插件引用的独立技能默认关闭,并可单独或按市场批量启用。
  • 工作区覆盖:设置页可在全局默认和已注册工作区之间切换。工作区为插件、插件技能和独立技能保存稀疏的启用/禁用覆盖;缺少覆盖时继承全局配置。
  • 代理工具:通过插件配置的「功能」开关控制 agent_market_info、agent_market_set_plugin 和 agent_market_set_skill,让代理查看市场状态并只修改工作区覆盖;支持注入简短工具用法提示词。工具关闭时也停止注入提示词,具体配置见 代理市场工具。home 路径会话会被 scoped restriction 隐藏这些工具;若运行时未能隐藏,执行时也会拒绝。
  • 原地加载:安装插件只保存安装状态,不复制市场文件。技能的 resourceBase 指向克隆后的技能目录,因此技能内的相对资源可用。
  • Codex hooks(可选):从 Codex 插件清单发现 hooks 配置;只有已安装的插件才能启用它们。启用需要设置页的双重确认、配置指纹审批和可用的 @deepseek-ai/dsh-hooks-codex bridge。
  • 设置页:设置菜单添加「技能与挂钩」区段,提供市场、插件、技能和 hooks 的管理及目录筛选。

安装

当前开发依赖和 CI 验证版本为 DSH 0.2.0-rc.2(当前 npm latest 与 next 发布线)。Host 显式注入 webServer;bundle patch 同时为 connection 提供方补充 webServer,保留其原有 webRuntime 依赖。这同时满足自定义 RPC 通道的调用方依赖及新版 Connection getter 的提供方 shadow 上下文检查,仅修改 Host 的注入列表仍会启动失败。

在 DSH Web 侧边栏「插件」中添加并安装 dsh-agent-plugin-market bundle。安装后在设置页「技能与挂钩」中管理市场。包的 cordis.patch.yml 将 Host 插件加入 web profile,package.json 中的 dsh.client 声明加载浏览器端设置页。

@deepseek-ai/dsh-client-ui-primitives、@deepseek-ai/dsh-home-paths 和 @deepseek-ai/schemastery 是运行时 peer dependencies,由 DSH 运行环境提供。工具与提示词开关保存在 profile entry 的 volatile Config fields 中,通过 DSH Config Forms 即时编辑,并以内联方式显示在插件 bundle 详情页。市场与技能功能不依赖 hooks bridge;bridge 缺失时,设置页显示通过 profile 依赖安装所需包的命令,并禁用 hooks 开关。Host RPC 使用 DSH 0.2.0-rc.2 的 Connection 通道,由运行时统一执行 Host/Origin 校验和浏览器会话 token 认证;通过认证的本机或网络 Web 页面都可管理 Host 上的市场、Git checkout 和 hooks。代理工具只暴露读取和工作区覆盖写入,不执行市场添加、删除、Git 更新、全局安装/卸载或 hooks 授权。

启用 Codex hooks(可选)

官方 DSH CLI 0.2.0-rc.2 已包含 Codex bridge;可用不代表 hooks 已授权,仍需设置页的双重确认。对于不含 bridge 的自定义部署,在运行于目标 profile 的 DSH shell 中执行以下命令,再重启 DSH。bridge 是可选的运行时依赖,不是可从侧边栏「插件」独立安装或加入 profile bundle 列表的 bundle:

pnpm --dir "$DSH_PROFILE_DIR" add @deepseek-ai/dsh-hooks-codex@0.2.0-rc.2 @deepseek-ai/dsh-hook-protocol@0.2.0-rc.2

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-clinepass-deepseekv4.1 下一个 Next dsh-clinebot →