ouyangyipeng/dsh-marketplace 预览 preview

ouyangyipeng/dsh-marketplace

Collection合集 Native原生 ⭐ 2 MIT Markets & Collections市场与合集

DeepSeek Harness 的安全实时插件市场

Project Overview项目介绍

ouyangyipeng/dsh-marketplace is a native DeepSeek Harness bundle plugin that adds a dedicated Marketplace tab to DSH's settings page. It pulls the full list of public repositories tagged dsh-plugin from GitHub, letting users discover, search, install, update, and remove plugins all within the DSH interface. It works with both standard DSH web profiles and DS-Harness Desktop. Starting with DS-Harness Desktop v0.2.0, this plugin is included offline by default, so users don't need to install it manually. For standalone installation on a standard DSH web profile, you need to run the DSH CLI install command to add it manually.

For regular DeepSeek Harness users, this plugin acts as a one-stop hub for community plugins, eliminating the need to leave DSH to search GitHub for new plugins. Plugin developers can add the dsh-plugin topic to their GitHub repository to have their plugin automatically indexed and discoverable by all Marketplace users. Every plugin installation goes through a validation step that checks the manifest, entry paths, and bundle format before it is added to the user's profile, to catch broken or non-compliant packages early. Installation failures roll back any changes automatically, so your existing profile remains intact even if something goes wrong.

This project is licensed under the MIT open source license, and is an unofficial community-maintained project not affiliated with DeepSeek. To install it manually on a web profile, you need Node.js version ^22.19.0 or >=24.0.0, and pnpm available in your system PATH. It uses GitHub's public search API to fetch the plugin catalog, and caches results for 10 minutes with ETag revalidation to avoid hitting rate limits. The marketplace does not verify third-party plugin code for malicious content, so users should always review a third-party plugin's source code before enabling it.

ouyangyipeng/dsh-marketplace 是一个专为 DeepSeek Harness 开发的原生插件包,它会在 DSH 的设置插件页面添加一个 Marketplace 标签页,同步获取 GitHub 上标记为 dsh-plugin 的所有公开社区仓库,让用户能够在 DSH 界面内完成插件的发现、搜索、安装、更新和卸载全流程,支持标准 DSH Web 配置和 DS-Harness Desktop 两种使用环境。

普通 DSH 用户可以通过这个插件一站式获取社区共享的 DSH 插件,不用自己跳转到 GitHub 寻找下载,简化了插件安装管理流程。DSH 插件开发者也可以给自己的仓库添加 GitHub topic:dsh-plugin 标记,让插件被自动收录,获得更多社区曝光。插件安装过程会自动验证格式和路径,保证安装流程的安全性和规范性。

本项目采用 MIT 许可证开源,是社区维护的非官方项目,不隶属于 DeepSeek。安装要求 Node.js 版本为 ^22.19.0 或 >=24.0.0,并且配置好 pnpm 在系统 PATH 中。DSH Desktop v0.2.0 及以上版本已经内置了该插件,无需用户手动安装,跟随版本更新即可。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"

把 ouyangyipeng/dsh-marketplace 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DSH Marketplace — 把插件社区变成你的应用市场

简体中文 · English

官网 · 安装 · 安全 · 架构 · Desktop · 开发

dsh-marketplace 本身就是一个 DeepSeek Harness bundle。它把 GitHub topic:dsh-plugin 的实时社区仓库放进 设置 → 插件 → Marketplace,让插件发现、搜索、检查、安装、更新和卸载留在同一个 Harness 界面里。

真实 DeepSeek Harness 设置页面中的 DSH Marketplace 插件列表

[!IMPORTANT] Marketplace 能检查包格式和收紧安装过程,不能证明第三方插件可信。插件重启后会在 DSH 进程内运行;启用前仍应阅读源码。

安装

DS-Harness Desktop

DS-Harness Desktop 从 desktop-v0.2.0 起离线内置固定版本的 Marketplace。打开应用后进入 设置 → 插件 → Marketplace,不需要先安装本插件。

内置版本显示“Desktop 内置”,不能在 Marketplace 里更新或卸载自己;它随经过验证的 Desktop release 更新。其他插件仍安装进 Desktop 隔离的 web profile。

标准 DSH Web profile

需要当前 DeepSeek Harness、Node.js ^22.19.0 || >=24.0.0 和位于 PATH 中的 pnpm:

dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"

重启 dsh web,然后打开 设置 → 插件 → Marketplace。

更新或卸载独立安装的 Marketplace 使用 DSH 原生命令:

dsh plugin --profile web update dsh-marketplace
dsh plugin --profile web remove dsh-marketplace

一条插件从发现到激活

flowchart LR
  Topic["GitHub topic:dsh-plugin"] --> Cache["Catalog cache + ETag"]
  Cache --> UI["Marketplace Client"]
  UI --> Stage["pnpm add --ignore-scripts"]
  Stage --> Inspect["Manifest + exports + path checks"]
  Inspect --> Profile["Atomic profile edit"]
  Profile --> Restart["Restart DSH"]
  1. Host 最多读取 GitHub Search 的 10 页、每页 100 个公开仓库。
  2. Client 在本地按名称、作者、简介和 topic 搜索,并按更新时间、Stars 或名称排序。
  3. 点击安装时,候选包先进入独立临时项目;这一步不修改用户 profile。
  4. 包通过预构建入口、bundle patch 和路径检查后,才正式写入 profile dependency。
  5. dsh.profile.bundles 使用原子文件替换;安装失败时不激活,卸载失败时恢复旧 manifest。
  6. 生命周期变化在重启 DSH 后生效。

安全边界

Marketplace 会做 Marketplace 不会承诺
用严格的 owner/repository 语法解析仓库 审核插件业务逻辑或作者身份
始终以 pnpm add --ignore-scripts 暂存和安装 把安装后的插件放进运行时沙箱
要求安全包名、预构建 Host 与标准 dsh.bundle.patch 证明仓库没有恶意代码
声明 Web Client 时要求预构建 ./client export 读取私有仓库或保存 GitHub token
检查 patch/entry 的真实路径仍位于包目录内 让源码包或依赖构建脚本的仓库自动兼容
逐项传递子进程参数,不拼接 shell command 绕过 DSH 的重启激活语义
只允许同源 loopback + 进程 nonce 调用写接口 把 Marketplace 变成远程管理 API
把 GitHub 数据作为 React 文本渲染,不插入 HTML 加载远端头像或仓库 HTML

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-plugin-token-billing 下一个 Next dsh-deepseek-vision →