HGT158/dsh-plugin-share

Plugin插件 Native原生 ⭐ 2 MIT Markets & Collections市场与合集

把你这套 DSH 插件变成一段可粘贴的分享码,别人贴进去就能逐个安装 · Turn your DSH plugin set into one pasteable code, and anyone can install the plugins one by one

Project Overview项目介绍

dsh-plugin-share is a native DSH (DeepSeek Harness) built-in plugin that serializes the plugin list of the current profile into a single, offline, pasteable share code so other users can recreate the same setup without servers, accounts, or landing pages. It is installed via dsh plugin --profile web add 'github:HGT158/dsh-plugin-share#main' and adds a "插件分享" tab under Harness Web's Settings → Built-in Plugins. The code begins with D1, uses an NP1-style binary record with a trailing CRC32, is pure JavaScript with zero dependencies, and requires no build-script approval at install time. The repository ships a DSH bundle manifest (dsh.bundle.patch + dsh.client) and renders its controls through the official @deepseek-ai/dsh-client-ui-primitives library, making it unambiguously built for the DSH target.

The export side offers a "从当前 profile 导出" action that produces a copy-ready D1… blob; the import side parses that blob and renders one row per plugin showing the name, the source (npm, github.com, or builtin), the full install spec such as github:owner/repo#v1.2.3, and the action that will run. Each row gets its own button — Install, Upgrade, Enable, Disable, or a greyed-out "已是当前版本" — and a top-level "全部安装" option installs everything in one pass. Mid-flight failures abort the batch, roll back newly installed packages, and revert any builtin enable-state changes made during that session, while pre-existing upgrades are never destructively rolled back. The plugin targets DSH users who need to coordinate plugin sets across teammates, study groups, or community posts.

Strict safety rules apply throughout: only npm packages, github:owner/repo[#ref] references, and DSH's official optional builtins are accepted as sources, while local paths, file:, link:, portal:, workspace:, arbitrary HTTP(S) tarballs, and git+… / git@ / ssh:// are all rejected. Configuration fields such as config, apiKey, token, settings, and patch cause the encoder to fail immediately, so no secret-bearing payload can ever leave the host, and CRC32 only detects accidental corruption, not tampering. After installation the user must restart dsh and hard-refresh the browser with Ctrl+F5 to clear the client bundle cache, because the lockfile pins #main to a specific commit and updates require dsh plugin --profile web update dsh-plugin-share. The desktop profile is not installable through the CLI because the desktop app manages its own bundles, CI runs npm test and pnpm pack --dry-run on every push and pull request, and the project is released under the MIT license.

dsh-plugin-share 是一个面向 DSH(DeepSeek Harness)的原生内置插件,用来把当前 profile 里已装的插件清单序列化为一段离线可粘贴的分享码。它通过 dsh plugin --profile web add 'github:HGT158/dsh-plugin-share#main' 安装,并在 Harness Web 的「设置 → 内置插件」中新增一个「插件分享」标签页。导出与导入界面由插件本身提供,码以 D1 开头、采用 NP1 风格的二进制记录并附 CRC32,纯 JS 实现、零依赖、无需批准构建脚本。该仓库使用 DSH 的 bundle 清单(dsh.bundle.patch + dsh.client)打包,控件调用官方 @deepseek-ai/dsh-client-ui-primitives,明显是为 DSH 这一目标平台而构建。

典型用法分为两步:导出方点击「从当前 profile 导出」得到一段以 D1 开头的码,再复制到微信、Slack、论坛或 issue;接收方把码粘入文本框点「解析组合码」,下方会逐行列出每个插件的名称、来源(npm / github.com / builtin)、完整安装规格与将要执行的动作,每行有独立的「安装 / 升级 / 启用 / 停用」按钮,也可以顶部一键「全部安装」。它适合需要在团队或社群中快速同步插件集合、又不想暴露配置或 API key 的 DSH 用户。需要注意的是,桌面 profile 由桌面 App 自行管理,CLI 装不进去;已验证版本为 dsh 0.2.0-rc.2 加 Web profile。

依赖方面是纯 JS 零依赖、不执行构建脚本,但接收方也必须安装本插件才能导入,仓库根目录的 node src/cli.mjs decode D1... 可作为不愿装插件时的命令行解码退路。安全边界很明确:只接受 npm 包、github:owner/repo[#ref] 和官方 builtin,本地路径、file:、link:、portal:、workspace:、HTTP(S) tarball 与 git+…/git@/ssh:// 一律拒绝;CRC32 只防损坏不防篡改,码里绝不包含 config/apiKey/token/settings/patch 等字段,编码阶段遇到就直接报错。首批操作后必须重启 dsh,并在浏览器按 Ctrl+F5 强制刷新 bundle 缓存;CI 每次 push/PR 跑 npm test 与 pnpm pack --dry-run,仓库以 MIT 协议开源。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add 'github:HGT158/dsh-plugin-share#main'

把 HGT158/dsh-plugin-share 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-share icon

DSH Plugin Share

English | 中文

把「我这套装了哪些插件」变成一段可粘贴的离线分享码,别人贴进去就能逐个安装。

stars release DSH bundle

插件分享标签页

安装

dsh plugin --profile web add 'github:HGT158/dsh-plugin-share#main'
dsh --profile web

打开 Harness Web → 设置 → 内置插件 → 插件分享。

这个包是纯 JS、零依赖、没有构建脚本,所以安装时不会要求你批准任何 build script,装完即用。分享方和接收方都需要装它——码本身只是文本,导出和粘贴导入的界面由它提供。

已验证环境:dsh 0.2.0-rc.2 + Web profile(@deepseek-ai/dsh-base / @deepseek-ai/dsh-web-app)。桌面 profile 由桌面 App 自行管理,CLI 装不进去。

怎么用

① 导出:把你这套插件变成码

点「从当前 profile 导出」→ 文本框出现 D1... 开头的码 → 点「复制」,发给对方。

也可以点「展示二维码」,把当前这段码画成手机可扫的二维码(再点一次「收起二维码」收起);面板里显示版本与尺寸,可点「保存 SVG」(矢量,放大不糊)或「保存 PNG」(位图,聊天工具里到处都能预览)。

二维码面板

② 导入:把别人的码装到本机

把码粘进文本框,点「解析组合码」,下面会逐行列出每个插件的名称、来源、完整安装规格和将要执行的动作。每一行右侧都有自己的按钮:

按钮 含义
安装 本机没有 → 安装
升级 已装旧版本 → 升到码里的版本
启用 / 停用 已装但启用状态不一致 → 只改状态,不重装
已是当前版本 无需操作(灰色不可点)

不想手打码也行:点「扫码导入」选一张二维码图片,或者把图片直接拖进面板——识别出来的码会自动填进文本框并立刻解析。适合别人把二维码截图发给你、或你先存成图片的场景。

也可以点顶部「全部安装」一次装完;装完重启 dsh 生效,浏览器按 Ctrl+F5。

它能做什么

  • 离线自包含的码 — 不需要服务器、账号或落地页。码就是文本,能发微信、Slack、论坛、贴进 issue。组合码以 D1 开头,内部是 NP1 风格的二进制记录,末尾带 CRC32。
  • 只带清单,不带配置 — 码里只有三样:插件来源、版本、启用状态。config、settings、patch、apiKey、token 等字段在编码阶段就被拒绝,不存在「过滤后继续导出」的路径。
  • 逐条预览,绝不静默安装 — 解析只做解码和校验,不碰 profile;要装什么、从哪来(npm / github.com / builtin)、会做什么动作,全部先摆出来给你看。
  • 每个插件单独操作 — 一行一个按钮。可以只装其中两个,也可以全部安装;单个装完会自动重新解析,刷新那一行的状态。
  • 构建脚本默认拒绝 — 需要跑安装脚本的包会单独提示并等你显式批准,批准只对本次生效,不随码传播。
  • 失败即停并回滚 — 中途失败不会继续往下装,本次新装的会被撤销,本次改过的 builtin 启用状态会被恢复;已存在的升级不会被破坏性回滚。
  • 状态永远有解释 — 按钮为什么灰、现在在做什么、解析出来几条待处理,界面上一行文字直说,不会让你对着一个没有理由的禁用按钮发呆。
  • 短码优先 — 短清单直接用原始二进制;8 条以上才尝试 deflate-raw,且只在压缩结果更短时才采用。实测 5 个插件的混合样本(含 GitHub 来源)是 218 个字符,纯 npm / builtin 的清单更短(149 字符),微信、Slack、X 都能直接发。
  • 二维码导出 — 点「展示二维码」把当前码画成黑白二维码,手机相机直接扫走;自动选最小版本、M 级纠错,放不下时降到 L,还放不下会明确提示改用文本。「保存 SVG」存矢量(打印/嵌入),「保存 PNG」存位图(发聊天工具最保险)。
  • 扫码导入 — 选图或拖图都能识别,认出码就自动填进文本框并解析。识别完全在本机做,图片不上传;解出来的内容还要通过组合码的 CRC32 校验才会被采用,读错一个字都会明确报「识别失败」而不是塞进一个坏码。
  • DSH 原生外观 — 控件用官方 @deepseek-ai/dsh-client-ui-primitives 的 Button / Tag,配色走 --dsw-* 主题 token,跟设置里其它页面同一套视觉。
  • 完全离线 — 编码、解码、校验、连二维码生成都在本机完成,不访问任何第三方服务;只有你点安装时才会去 npm / GitHub 下载插件。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-auto-review 下一个 Next dsh-mcp-studio →