kyorakuyk/dsh-hotreload-plugin-manager
DeepSeek Harness插件:在运行的dsh Web中热安装/卸载/更新/启用-禁用配置文件插件包——无需重启,包含Web UI。
Project Overview项目介绍
This is a native out-of-tree plugin built exclusively for DeepSeek Harness (DSH). It allows users to install, uninstall, enable, and disable DSH plugins directly on a running DSH web instance without requiring a full restart of the service. It adds a dedicated plugin management tab to the DSH web settings interface, and supports installing valid DSH plugins from multiple sources including npm packages, git URLs, GitHub shorthand references, and local file paths. Unlike core-integrated plugins, this tool works entirely without modifying any DSH core code, keeping your local DSH checkout completely clean and unmodified.
The plugin reuses existing DSH launcher mechanisms to work, so no core changes are needed. When you install a plugin through this manager, it adds the target plugin as a real dependency to your current DSH profile directory, reads the plugin’s DSH patch configuration, and writes it to the user patch layer. Any changes take effect immediately after installation, and the configuration persists across DSH restarts. For installation requests that do not meet DSH plugin requirements, such as conflicting patch IDs or unresolvable package names, the manager will reject the request and automatically roll back any changes, leaving no residual files.
To use this plugin, you need to meet a few prerequisites first: Node.js version 22 or higher, pnpm version 10 or higher, and a pre-installed DSH with an initialized target profile that you want to add the manager to. You can install it directly via the DSH plugin CLI from GitHub, a local cloned copy, or npm, and you only need to restart your DSH web instance one time after installation completes. It is released under the open-source MIT license, and has a few documented limitations, most notably that changes to plugin module code require a DSH restart to take full effect.
这是一个专为 DeepSeek Harness(DSH)开发的树外原生插件,支持在运行中的 DSH 实例上直接完成插件的热安装、热卸载、禁用启用操作,全程无需重启 DSH 服务。它在 DSH Web 设置页新增了插件管理标签页,支持从 npm 包、git 地址、GitHub 简写、本地路径等多种来源安装符合规范的 DSH 插件,且不需要修改 DSH 内核代码。
它的工作流程复用了 DSH 启动器已有机制,安装时会将插件作为真实依赖添加到当前 profile 目录,读取插件的 DSH 补丁配置写入用户补丁层,操作完成后立即热生效,重启 DSH 后配置也会保留。对于不满足 DSH 插件规范、补丁行 ID 冲突、无法解析包名的安装请求,它会明确拒绝并自动回滚,不会留下残留垃圾文件。
使用本插件需要满足前置条件:Node.js ≥ 22,pnpm ≥ 10,已经安装 DSH 并初始化过目标 profile。安装可以直接通过 DSH 插件 CLI 从 GitHub、本地克隆或者 npm 安装,安装完成后需要重启一次 DSH Web 实例。本插件使用 MIT 许可证开源,已知限制包括模块代码变更需要重启 DSH 才能生效。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-hotreload-plugin-manager(kyorakuyk/dsh-hotreload-plugin-manager)
仓库:https://github.com/kyorakuyk/dsh-hotreload-plugin-manager
本站详情页:https://www.yhbd.top/plugins/kyorakuyk-dsh-hotreload-plugin-manager/
本站登记:类型 bundle · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-08-15 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add "@kyorakuyk/dsh-plugin-manager"
把 kyorakuyk/dsh-hotreload-plugin-manager 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-hotreload-plugin-manager
中文 | English
一个树外(out-of-tree)DeepSeek Harness 插件:在运行中的实例上直接完成插件的热安装、热卸载、禁用/启用——无需重启, 并提供 Web 设置页标签页:
- 🔥 热安装:按 spec(npm 包名 / git URL /
github:owner/repo/file:路径) 安装插件 bundle,立即热生效于运行中的dsh web,且重启后保留。 - 🔥 热卸载:移除 bundle——行与 fiber 即刻卸载、依赖被清理、陈旧的 bundle 层条目一并移除。
- 🔥 禁用 / 启用:在 UI 上一键切换已安装 bundle 的条目开关,状态持久化且立即生效。
- 热更新:热替换 bundle 的补丁行并实时重放配置(模块代码变更按 Node 进程内 缓存特性仍需重启)。
- 零内核改动:纯树外 bundle,dsh checkout 完全不被触碰。
- 双面包:一个 npm 包同时是 host 网关与浏览器设置标签页。
架构
┌────────────────────────────── 浏览器(React)──────────────────────────────┐
│ 设置 → 插件 → "插件管理"标签页(槽位 settings.plugins.tab) │
│ │ fetch('/plugin-manager/*') │
└────────┼──────────────────────────────────────────────────────────────────┘
▼
┌──────────────────────────── dsh web 进程 ──────────────────────────────────┐
│ webserver 路由(node:http)──▶ manager 核心 │
│ ① pnpm add/remove(profile 内的真实依赖) │
│ ② 行写入 profile 用户补丁层(cordis.patch.yml) │
│ ③ 根 Include entry.update → Loader 挂载/卸载 fiber │
│ 网关:TypertRemoteService(源码模式反射,无代码生成) │
└────────────────────────────────────────────────────────────────────────────┘
包是双面的:
- Node 半(
lib/index.js,tsc 编译)——PluginManagerGateway,一个注册为pluginManager的TypertRemoteService。api-gateway 可通过源码模式反射 分发它的@Remote方法(无需生成产物);同时它在 webServer 服务上注册浏览器 HTTP 传输。 - 浏览器半(
lib/client.js,esbuild 打包)——注册进settings.plugins.tab槽位(idmanager)的 Web 设置标签页,由dsh-client-modules发现,并以普通 模块表 bundle(window.__ModuleLoader__.load)形式服务。
工作原理
全部复用 launcher 已有的机制,因此插件不需要对 dsh checkout 做任何改动:
- 安装:在 profile 目录执行
pnpm add <spec>。包成为真实依赖(进入 profile 的node_modules与package.json,pnpm 不会剪除它)。管理器读取 该 bundle 的dsh.bundle.patch行,写入 profile 的用户补丁层 (cordis.patch.yml)。 - 热应用:直接对根 Include 条目调用
entry.update(携带新补丁列表)—— 与 launcher 用户补丁 watcher 相同的调用。管理器自己应用自己的写入,因为文件 watcher 可能漏掉紧跟其后的写入事件。 - 重启持久:用户补丁层在启动时被重新组合,因此已安装 bundle 在重启后保留,
且不触碰
dsh.profile.bundles(也就不会双组合行)。 - 卸载 / 更新:移除或替换行,并执行
pnpm remove/pnpm update(registry 包)或 remove + re-add(file:/link:——pnpm 的增量重拷不会 物化新增文件)。 - 启停:写入用户层禁用行(
{ id, disabled }),按 id 覆盖 bundle 行而不 产生重复。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
yannicksong0106/dsh-550c-boot
omdsh-dev/dsh-advisor
shuguang1994/project-blueprint
SummerSec/AI-Inner-Os
wlj521/dsh-ui-tweaks
PelyDeng/dsh-plugin-manager
codeAnqiang-ma/dsh-superpowers