fuyao606/dsh-plugin-manager

在 DeepSeek Harness(DSH)Web GUI 的「设置」面板里管理本机插件:列出、启用、禁用、安装、卸载 web profile 的插件,无需命令行手动操作。

catalog descriptioncatalog 简介 / catalog description:DeepSeek Harness Web GUI plugin manager

Project Overview项目介绍

This is a DSH-native plugin that adds a full-featured graphical plugin management interface to the DeepSeek Harness Web GUI. It eliminates the need for manual command line operations when managing DSH web profile plugins, letting users perform all core plugin management actions directly through the web settings panel. To install the plugin, users can simply run the dsh plugin --profile web add github:fuyao606/dsh-plugin-manager command in their local terminal. The repository already includes pre-built output in the lib/ directory, so no local build step is required for regular end users to get up and running.

After installation, users must restart the dsh web service and perform a hard refresh of their browser to activate the new plugin interface. Once activated, the plugin adds a new "Plugin Manager" section under the DSH settings menu, where users can view all installed plugins sorted by type and current status. Users can enable or disable existing plugins with a single click, install new DSH plugins by entering a valid npm package name, and uninstall existing user plugins directly from the graphical interface. This tool is designed for any DSH developer who prefers graphical management over manual command line operations.

The plugin follows strict security practices to prevent common attack vectors like CSRF and command injection on the local DSH instance. It only allows valid npm package name formats for in-interface installation, and blocks any untrusted input that could lead to malicious command injection. For local development, it requires Node.js version 20 or higher and uses pnpm as the official package manager for building. The plugin is released under the open source MIT license, and it only depends on DSH's built-in React module with no external runtime dependencies for end users.

这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,用于在 DSH Web 界面的「设置」面板中管理本机 web profile 下的插件,支持对已安装插件进行列出区分用户插件与内置模块、启用禁用操作,也支持直接在界面完成新插件的安装与卸载,全程无需手动执行命令行,大幅简化了 DSH 插件的日常管理流程。

用户安装该插件后,只需重启 DSH Web 服务并在浏览器执行硬刷新,就能在 DSH 的设置面板找到插件管理入口。日常使用中,用户可直观查看所有插件的当前状态,一键切换插件的启用禁用状态,输入合法的 npm 包名即可快速安装符合规范的 DSH 插件,非常适合所有使用 DSH Web 界面的开发者简化插件日常管理。

本插件仅依赖 DSH 内置的 React 模块,无需额外安装第三方依赖,使用 MIT 许可开源免费。所有操作仅修改对应 profile 的 package.json 和 node_modules,修改后必须重启 DSH Web 并刷新浏览器才能生效。插件内置安全校验机制,可防范 CSRF 攻击和命令注入风险。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:fuyao606/dsh-plugin-manager

把 fuyao606/dsh-plugin-manager 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-manager

在 DeepSeek Harness(DSH)Web GUI 的「设置」面板里管理本机插件:列出、启用、禁用、安装、卸载 web profile 的插件,无需命令行手动操作。

功能

  • 列出:读取 $DSH_HOME/profiles/web/package.json(dependencies + dsh.profile.bundles)与 node_modules 里的实际版本,区分「用户插件」与「内置模块」。
  • 启用 / 禁用:切换插件在 dsh.profile.bundles 中的挂载(禁用保留安装,仅下次启动不再加载)。
  • 安装:输入 npm 包名,在 profile 目录跑 pnpm add <spec>,并按安装状态自动对账 bundles。
  • 卸载:一键 pnpm remove <name>,并对账 bundles。

所有改动只落到 profile 的 package.json / node_modules,需重启 dsh web 并硬刷新浏览器后生效(host 半改动无法热加载)。

安装

方式一:从 GitHub(推荐,免构建脚本)

仓库已提交构建产物 lib/,直接装:

dsh plugin --profile web add github:fuyao606/dsh-plugin-manager

方式二:本地开发

git clone https://github.com/fuyao606/dsh-plugin-manager.git
cd dsh-plugin-manager
pnpm install
pnpm build

# 装进 web profile(本地 link,改完 rebuild 后重启即可)
dsh plugin --profile web add ../dsh-plugin-manager

方式三:npm(若已发布)

dsh plugin --profile web add dsh-plugin-manager@latest

装完重启 dsh web 并硬刷新浏览器,打开 **设置 →「插件管理」**即可使用。

开发

pnpm install
pnpm typecheck   # tsc --noEmit
pnpm build       # tsdown → lib/index.js(host)+ lib/client.js(client)

仓库刻意提交了构建产物 lib/(见 .gitignore 注释),改 src/ 后需 pnpm build 重新生成并提交,保证 GitHub 安装免构建脚本。

安全

  • 路由走与 /api 网关一致的浏览器信任围栏(Host 回环 / trustedHosts + 同源),阻止恶意网页对本地 DSH 服务做 CSRF 安装/卸载。
  • install 的包名规格做白名单校验,避免经 shell: true 调 pnpm 时被注入;仅支持 npm 包名(name / @scope/name,可选 @version),github: / file: 等规格需走命令行。

架构

  • host 半 src/index.ts → lib/index.js:/plugin-manager/api JSON API(list / enable / disable / install / remove)。
  • client 半 src/client/index.tsx → lib/client.js:注册 settings.section slot,渲染管理界面。
  • 只依赖模块表提供的 react;@deepseek-ai/* 服务面全部用结构化类型镜像,无值依赖。

快速开始

安装并打开管理器

仓库已提交 lib/ 构建产物,推荐直接从 GitHub 安装:

dsh plugin --profile web add github:fuyao606/dsh-plugin-manager

也可以固定到指定版本:

dsh plugin --profile web add github:fuyao606/dsh-plugin-manager#v0.1.1

安装完成后重启 DSH:

dsh web

然后进入 设置 → 插件管理。安装、升级或修改任意插件后,都要重启 dsh web,并在浏览器执行硬刷新(Windows/Linux:Ctrl+Shift+R,macOS:Cmd+Shift+R)。Host 侧的 bundle 挂载不会热加载,仅刷新页面不会使配置生效。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-hub 下一个 Next dsh-excel-panel →