qinyre/dsh-plugin-install 预览 preview

qinyre/dsh-plugin-install

在 dsh 设置页里安装任意第三方插件的「安装」标签页。输入包名——npm spec、github:user/repo 或本地路径——即可安装,不必开终端,也不必经过插件市场;市场没收录的插件同样能装。

catalog descriptioncatalog 简介 / catalog description:给 dsh 设置页加「安装」标签页,按包名安装任意第三方插件。

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that adds a dedicated plugin installation tab to the DSH settings UI. It lets users install any third-party DSH plugin directly without opening a terminal or relying on the official DSH plugin marketplace. To install, users simply input a package identifier that can be an npm package spec, a GitHub user/repo path, or a local file path, and plugins not listed on the official marketplace can be installed just as easily. Installation follows the existing dsh plugin add / remove CLI workflow under the hood, so there are no conflicting state management systems.

After installation, the plugin adds one-click update checking for all installed plugins. It uses different update strategies based on how the plugin was installed: npm plugins check the npm registry for the latest version, GitHub installed plugins check the repository HEAD, and local plugins are marked as is with no automatic check. When an update is found, it runs version validation before proceeding, and will reject any update that would actually downgrade the installed plugin. All operations automatically add --config.minimum-release-age=0 to bypass pnpm’s 24-hour cool-down period for new releases.

The plugin includes multiple security protections to prevent common attack vectors. It uses a character whitelist for input validation to block shell injection attacks from malicious special characters like hyphens, semicolons, or redirect symbols. It enforces same-origin POST requests and only allows one installation, uninstall, or update operation to run at a time. It is available under the open-source MIT license, DSH Desktop comes with it pre-installed, and end-to-end testing requires Node.js 22.19 or higher and a local copy of the deepseek-harness source code.

这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,它在 DSH 的设置页面中新增了一个「安装」标签页,供用户安装任意第三方插件。用户只需要输入包名,支持 npm 规格、GitHub 仓库地址或者本地路径,就可以完成安装,无需打开终端,也不需要经过官方插件市场,未收录的插件也能直接安装。

所有安装、卸载和更新操作都遵循 DSH 原有的 CLI 命令逻辑,配置文件 dsh.profile.bundles 的状态同步完全和命令行一致,不存在两套独立逻辑。已安装插件支持一键检查更新,针对 npm、GitHub 和本地安装的插件分别采用不同的更新检查策略,更新时会做版本校验,避免误降级安装。

该插件采用 MIT 许可开源,内置多重安全防护,包括参数字符白名单校验、同源请求限制、单操作互斥锁等。DSH Desktop 已经预装了该插件,普通用户无需手动安装,开发人员可以通过本地源码路径安装进行二次开发。Node.js 需要 22.19 及以上版本才能运行端到端测试。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-plugin-install

把 qinyre/dsh-plugin-install 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-install

npm version License: MIT

在 dsh 设置页里安装任意第三方插件的「安装」标签页。输入包名——npm spec、github:user/repo 或本地路径——即可安装,不必开终端,也不必经过插件市场;市场没收录的插件同样能装。

「安装」标签页

安装、卸载与更新走的都是 dsh plugin add / remove 这条 CLI 路径,与命令行完全一致,dsh.profile.bundles 的同步由 CLI 负责,不存在第二套状态。已安装列表可以一键检查更新:npm 安装的对照 registry 的 latest 版本号,github 安装的对照仓库 HEAD 提交,本地链接则如实标注、不做检查;发现新版后单插件就地更新,更新前还会核对方向——registry 的 latest 不高于已装版本时拒绝执行,绝不把更新变成降级。每次 add 与 remove 都附带 --config.minimum-release-age=0:pnpm 11 默认开启 24 小时发布冷静期,@latest 会被静默解析到窗口外的旧版本,发布当天点更新等于原地不动;它还会在每次操作前对整个 lockfile 做策略校验,只要里面有窗口内发布的条目(例如显式钉版安装带进来的传递依赖),安装与卸载会一并被 ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION 拦死——界面上点名操作的包不受这层默认限制(旧版 pnpm 不认识该参数时自动去掉重试)。失败横幅现在也会带出 pnpm 打印在标准输出里的真实诊断,而不是只剩转发器的一句总结。更新完成后还会核对实际落地的版本号,与 registry latest 不一致时如实提示,而不是谎报成功。装好之后,纯客户端插件刷新页面即可生效;组合较复杂的插件会明确提示需要重启,页面上的「重启服务」按钮两种宿主都能用——在桌面宿主里交由壳层重启受监督的 sidecar,独立运行 dsh web 时则由插件自行接力:分离的中转进程等旧进程让出端口后按原启动命令拉起新实例,终端场景下再交接回原终端。

安装

dsh plugin --profile web add dsh-plugin-install

打开 Web UI 的 设置 → 插件,即可看到「安装」标签页。卸载在同一页面完成,或执行:

dsh plugin --profile web remove dsh-plugin-install

开发时也可以直接安装本地源码检出:dsh plugin --profile web add file:/path/to/dsh-plugin-install,包内的 prepare 脚本会自动构建出 lib/。

安全

写操作设有三重防护:spec 采用字符白名单校验,拒绝参数注入与 shell 元字符(如首字符 -、分号、重定向符),更新目标则只能取自已安装清单;POST 请求要求同源——官方桌面壳转发而来的请求没有 Origin 头,仅当回环 Host、回环连接对端、无代理痕迹且无跨站 Sec-Fetch-Site 标记时放行;同一时刻仅允许一个安装、卸载或更新操作运行。服务本身只绑定回环地址,上述措施构成纵深防御。

开发

npm install
npm run typecheck
npm test
npm run build

端到端 smoke 默认关闭,要求同级目录下存在 deepseek-harness 源码检出,且 Node ≥ 22.19:

DSH_DESKTOP_PLUGIN_SMOKE=1 npm test

它会创建临时 DSH_HOME,将本插件安装进 web profile,启动 dsh web,并对安装、卸载、取消、更新检查等路由逐一探测。

许可

MIT

← 上一个 Prev DSHGuard 下一个 Next dsh-layered-memory →