ouyangyipeng/dsh-marketplace
DeepSeek Harness 的安全实时插件市场
Project Overview项目介绍
ouyangyipeng/dsh-marketplace is a native DeepSeek Harness bundle plugin that adds a dedicated Marketplace tab to DSH's settings page. It pulls the full list of public repositories tagged dsh-plugin from GitHub, letting users discover, search, install, update, and remove plugins all within the DSH interface. It works with both standard DSH web profiles and DS-Harness Desktop. Starting with DS-Harness Desktop v0.2.0, this plugin is included offline by default, so users don't need to install it manually. For standalone installation on a standard DSH web profile, you need to run the DSH CLI install command to add it manually.
For regular DeepSeek Harness users, this plugin acts as a one-stop hub for community plugins, eliminating the need to leave DSH to search GitHub for new plugins. Plugin developers can add the dsh-plugin topic to their GitHub repository to have their plugin automatically indexed and discoverable by all Marketplace users. Every plugin installation goes through a validation step that checks the manifest, entry paths, and bundle format before it is added to the user's profile, to catch broken or non-compliant packages early. Installation failures roll back any changes automatically, so your existing profile remains intact even if something goes wrong.
This project is licensed under the MIT open source license, and is an unofficial community-maintained project not affiliated with DeepSeek. To install it manually on a web profile, you need Node.js version ^22.19.0 or >=24.0.0, and pnpm available in your system PATH. It uses GitHub's public search API to fetch the plugin catalog, and caches results for 10 minutes with ETag revalidation to avoid hitting rate limits. The marketplace does not verify third-party plugin code for malicious content, so users should always review a third-party plugin's source code before enabling it.
ouyangyipeng/dsh-marketplace 是一个专为 DeepSeek Harness 开发的原生插件包,它会在 DSH 的设置插件页面添加一个 Marketplace 标签页,同步获取 GitHub 上标记为 dsh-plugin 的所有公开社区仓库,让用户能够在 DSH 界面内完成插件的发现、搜索、安装、更新和卸载全流程,支持标准 DSH Web 配置和 DS-Harness Desktop 两种使用环境。
普通 DSH 用户可以通过这个插件一站式获取社区共享的 DSH 插件,不用自己跳转到 GitHub 寻找下载,简化了插件安装管理流程。DSH 插件开发者也可以给自己的仓库添加 GitHub topic:dsh-plugin 标记,让插件被自动收录,获得更多社区曝光。插件安装过程会自动验证格式和路径,保证安装流程的安全性和规范性。
本项目采用 MIT 许可证开源,是社区维护的非官方项目,不隶属于 DeepSeek。安装要求 Node.js 版本为 ^22.19.0 或 >=24.0.0,并且配置好 pnpm 在系统 PATH 中。DSH Desktop v0.2.0 及以上版本已经内置了该插件,无需用户手动安装,跟随版本更新即可。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-marketplace(ouyangyipeng/dsh-marketplace)
仓库:https://github.com/ouyangyipeng/dsh-marketplace
本站详情页:https://www.yhbd.top/plugins/ouyangyipeng-dsh-marketplace/
本站登记:类型 collection · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-12 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"
把 ouyangyipeng/dsh-marketplace 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
简体中文 · English
官网 · 安装 · 安全 · 架构 · Desktop · 开发
dsh-marketplace 本身就是一个 DeepSeek Harness bundle。它把 GitHub topic:dsh-plugin 的实时社区仓库放进 设置 → 插件 → Marketplace,让插件发现、搜索、检查、安装、更新和卸载留在同一个 Harness 界面里。
[!IMPORTANT] Marketplace 能检查包格式和收紧安装过程,不能证明第三方插件可信。插件重启后会在 DSH 进程内运行;启用前仍应阅读源码。
安装
DS-Harness Desktop
DS-Harness Desktop 从 desktop-v0.2.0 起离线内置固定版本的 Marketplace。打开应用后进入 设置 → 插件 → Marketplace,不需要先安装本插件。
内置版本显示“Desktop 内置”,不能在 Marketplace 里更新或卸载自己;它随经过验证的 Desktop release 更新。其他插件仍安装进 Desktop 隔离的 web profile。
标准 DSH Web profile
需要当前 DeepSeek Harness、Node.js ^22.19.0 || >=24.0.0 和位于 PATH 中的 pnpm:
dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"
重启 dsh web,然后打开 设置 → 插件 → Marketplace。
更新或卸载独立安装的 Marketplace 使用 DSH 原生命令:
dsh plugin --profile web update dsh-marketplace
dsh plugin --profile web remove dsh-marketplace
一条插件从发现到激活
flowchart LR
Topic["GitHub topic:dsh-plugin"] --> Cache["Catalog cache + ETag"]
Cache --> UI["Marketplace Client"]
UI --> Stage["pnpm add --ignore-scripts"]
Stage --> Inspect["Manifest + exports + path checks"]
Inspect --> Profile["Atomic profile edit"]
Profile --> Restart["Restart DSH"]
- Host 最多读取 GitHub Search 的 10 页、每页 100 个公开仓库。
- Client 在本地按名称、作者、简介和 topic 搜索,并按更新时间、Stars 或名称排序。
- 点击安装时,候选包先进入独立临时项目;这一步不修改用户 profile。
- 包通过预构建入口、bundle patch 和路径检查后,才正式写入 profile dependency。
dsh.profile.bundles使用原子文件替换;安装失败时不激活,卸载失败时恢复旧 manifest。- 生命周期变化在重启 DSH 后生效。
安全边界
| Marketplace 会做 | Marketplace 不会承诺 |
|---|---|
用严格的 owner/repository 语法解析仓库 |
审核插件业务逻辑或作者身份 |
始终以 pnpm add --ignore-scripts 暂存和安装 |
把安装后的插件放进运行时沙箱 |
要求安全包名、预构建 Host 与标准 dsh.bundle.patch |
证明仓库没有恶意代码 |
声明 Web Client 时要求预构建 ./client export |
读取私有仓库或保存 GitHub token |
| 检查 patch/entry 的真实路径仍位于包目录内 | 让源码包或依赖构建脚本的仓库自动兼容 |
| 逐项传递子进程参数,不拼接 shell command | 绕过 DSH 的重启激活语义 |
| 只允许同源 loopback + 进程 nonce 调用写接口 | 把 Marketplace 变成远程管理 API |
| 把 GitHub 数据作为 React 文本渲染,不插入 HTML | 加载远端头像或仓库 HTML |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
freestylefly/awesome-gpt-image-2
awesome-dsh-plugin/awesome-dsh-plugin
zhu1090093659/dsh-web
dsh-market/dsh-market
superdesigndev/treg
AdamPlatin123/dsh-plugin-radar
0xsline/awesome-deepseek-harness