LX2000WASD/dsh-plugin-manager-companion
Companion to the official DSH plugin manager: pre-install quality gate, environment diagnostics, marketplace, and upgrades.
Project Overview项目介绍
This is a native DSH plugin that supplements the official DSH plugin manager, replacing the older unmaintained dsh-web-plugin-manager. It is designed to work with DSH version 0.1.6-alpha.2 and newer, and fills all the functional gaps explicitly listed as unimplemented by the official plugin manager. You can install it via the DSH CLI with the command dsh plugin --profile <name> add dsh-plugin-manager-companion@latest, then enable it in the plugin management page and restart your profile to activate it. It adds pre-install quality gates, five-level environment diagnosis, multi-profile management and a community plugin marketplace, and provides both a graphical interface and a standalone CLI tool called dshpmc.
After installation and activation, the plugin automatically triggers a quality check before every plugin installation. It scans for common issues like undeclared imports, dependency mismatches, and unreachable entry points, and will automatically roll back the installation if any problem is found. It also supports pre-install verification in a temporary test environment, which is kept for 14 days by default with no limit on the number of test environments you can create. The environment console lets you run full health diagnostics across all your local DSH profiles, get root cause information and repair suggestions, and manage common profile operations. It is intended for DSH users who manage multiple DSH environments.
This plugin performs all write operations via DSH's official API channels and never directly modifies DSH's core configuration files like cordis.patch.yml. It is released under the open source MIT license. Full validation and automated testing has been completed on Linux. Most platform-specific fixes have been verified on Windows x64, though some features like terminal mode require Windows Terminal to work fully. It has not been tested on macOS, though cross-platform compatibility checks have been added for case-insensitive file systems. There are a few known limitations, such as some fixes requiring manual user operation.
这是一款为 DSH 官方插件管理器提供补充功能的原生插件,替代了已停止维护的旧版 dsh-web-plugin-manager,适配 DSH 0.1.6-alpha.2 及以上版本。它填补了官方插件管理器未实现的功能缺口,新增了安装前质量检查、五层环境诊断、多环境配置管理和社区插件市场功能,同时提供 dshpmc 命令行入口,也可集成进官方插件管理页使用。
用户安装启用后,可在插件安装环节自动触发质量门检查,提前发现依赖异常等问题,不合格会自动回滚,支持测试环境预安装验证。环境控制台可对本地所有 DSH 环境做分层健康诊断,提供问题根因与修复建议,还支持多环境的启停、备份恢复、跨环境复制插件等操作,方便需要管理多个 DSH 配置的开发者使用。
本插件完全基于官方通道执行写入操作,不直接修改核心配置文件,采用 MIT 许可开源。目前仅在 Linux 完成全量验证,Windows 完成大部分平台适配验证,macOS 尚未验证。存在少量已知限制,例如部分修复需要用户手动操作,质量门回滚可能遇到官方保护的残留文件。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugin-manager-companion(LX2000WASD/dsh-plugin-manager-companion)
仓库:https://github.com/LX2000WASD/dsh-plugin-manager-companion
本站详情页:https://www.yhbd.top/plugins/lx2000wasd-dsh-plugin-manager-companion/
本站登记:类型 collection · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-09-20 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-plugin-manager-companion@latest
把 LX2000WASD/dsh-plugin-manager-companion 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugin-manager-companion
DSH 官方插件管理器的补充:安装前质量门、五层环境诊断、多环境管理与插件市场。
前身是 dsh-web-plugin-manager(0.6.3,已停止维护)。 DSH 0.1.6-alpha.2 起官方自带插件管理页,旧仓库遮蔽官方页面并自建写权的做法不再适用,本仓库为重写。
截图
![]() 五层诊断:分组折叠,每条带严重度与证据;未查到的层显示「未查」 |
![]() 多环境启停、复制与备份恢复 |
![]() 卡片标出风险、分类与主题;详情展示索引原文 |
![]() 注册进官方插件页,点开自己的条目就是配置表单 |
目录
它做什么,不做什么
官方插件管理器的 README 列明了自己不做的事。本插件只补这些缺口。
| 能力 | 官方 | 本插件 |
|---|---|---|
| 组合包与插件行的启停 | 已有 | 不做 |
| 组合包安装与卸载 | 已有 | 不做(安装前插质量门) |
| 插件配置页托管 | 提供插槽 | 作为注册方接入 |
| 安装前静态检查 | 无 | 质量门 |
| 环境诊断 | 无 | 环境控制台 · 体检 |
| 修改另一个 profile | 明确不做 | 环境控制台 · 环境 |
| 普通插件模块的加载 | 声明为文件操作 | 技能与预设安装 |
| 版本列表与更新检测 | 明确不做 | 插件市场 |
写操作一律走官方通道:当前环境用官方 pluginManager 服务,跨环境用官方 runPluginCommand。
本插件不写 cordis.patch.yml,不直接调用 pnpm。
官方四处「明确不做」的原文引用、对应的本插件功能,以及官方补上后的退出方式,见 docs/OFFICIAL-DEPENDENCIES.md §1-F。
安装
dsh plugin --profile <name> add dsh-plugin-manager-companion@latest
要求 DSH >= 0.1.6-alpha.2。装好后在插件管理页启用,重启该 profile。
能力
安装前质量门
接在官方 installBundle 的「装但不激活」开关上:
inspect(spec):官方确认这个 spec 指向什么;installBundle(spec, { enabled: false }):官方装进环境,不激活;- 扫描该包:未声明的 import、声明了但没装、把官方包声明成普通
dependencies(会在 profile 里装出第二份副本,让官方 loader 行解析到它)、入口解析不到; - 不合格则
removeBundle回滚,合格则setBundleEnabled激活。
试装默认关闭。开启后,候选包会先装进 <环境名>-dpmc 测试环境并启动一次,通过后才装进真实环境。测试环境不设数量上限,默认保留 14 天。试装会在本机真实安装候选包并执行它自带的安装脚本。
环境控制台
一个设置页入口,三个子页:
- 体检:五层诊断。每条发现带证据(文件与行号,或运行时对象),处置分三级:可自动修复、需确认、仅报告。五层为 L1 依赖、L2 组合、L3 运行时、L4 一致性、L5 生态;某一层未查时,层计数显示「未查」,不显示 0。
- 环境:列出本机所有 profile 及其运行状态(进程与端口),支持启动(终端窗口或后台)、停止、新建、重命名、删除、跨环境复制插件、备份导出、差异对比与恢复。
- 设置:本插件配置,保存在官方 settings 服务中,在界面上修改。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →




freestylefly/awesome-gpt-image-2
awesome-dsh-plugin/awesome-dsh-plugin
zhu1090093659/dsh-web
dsh-market/dsh-market
superdesigndev/treg
AdamPlatin123/dsh-plugin-radar
0xsline/awesome-deepseek-harness