Sanqi-normal/dsh-webui-market-plugin
dsh Web GUI 社区插件市场:浏览 awesome-dsh-plugin.com 插件目录,一键安装/卸载到 profile。为 DeepSeek Harness (dsh) Web GUI 提供的社区插件市场:浏览、安装和卸载插件到 profile 中。
Project Overview项目介绍
This is a native plugin built exclusively for the DeepSeek Harness (DSH) web profile that adds a community plugin marketplace directly into DSH’s web GUI. Users can browse the official curated plugin directory hosted at awesome-dsh-plugin.com right from the DSH settings menu, no external browser required. It matches DSH’s existing interface style, automatically switches between light and dark theme based on system settings, and also supports automatic language switching between Chinese and English based on your system locale. To install, you can run dsh plugin --profile web add @sanqi-normal/dsh-webui-market-plugin via the DSH CLI for the simplest npm-based installation.
This plugin is designed for DSH users who prefer managing community plugins directly from the web UI instead of using the command line. It supports browsing plugins by category, searching for specific plugins, filtering to show only already installed plugins, and sorting results by GitHub star count or date of addition to the directory. When you install a plugin, it can automatically sync the plugin to all initialized local DSH profiles, including both web and desktop profiles. All operations like install, update, and uninstall are queued in FIFO order, so you can queue multiple tasks at once and check progress or cancel tasks at any time.
This plugin relies on peer dependencies provided by the DSH host environment, including @deepseek-ai/cordis, @deepseek-ai/dsh-client-runtime, and @deepseek-ai/dsh-client-ui-slots, so users do not need to install these manually. It is compatible with DSH versions 0.0.1-rc.2 and above (excluding 0.0.1-rc.1) and 0.1.0-rc.2 and above, and it is released under the open source MIT license. Besides the recommended npm installation method, you can also install it directly from the GitHub source code via the DSH CLI. After installation, you will need to restart the DSH web service for the plugin to take effect, and if you install from GitHub and get a pnpm build error, you need to add the package to your pnpm-workspace.yaml allowBuilds list first.
这是一款专为DeepSeek Harness(DSH)Web端开发的原生插件,用于在DSH的Web图形界面内部提供社区插件市场功能。用户可以直接在「设置→插件→插件市场」中浏览awesome-dsh-plugin.com的官方插件目录,完成插件的安装、更新与卸载操作。界面风格与DSH前端保持一致,跟随系统深浅色主题切换,同时支持按系统语言自动切换中英文显示。
该插件面向需要在DSH Web端便捷管理社区插件的用户,支持按分类浏览目录、搜索关键词、过滤已安装插件,还可一键按Star数热度、收录时间排序。安装插件时支持自动同步到本地所有已初始化的DSH配置档(包括Web和桌面端),所有安装、更新、卸载任务组成先进先出队列,可实时查看进度、取消任务或排查错误。
本插件依赖DSH宿主环境提供的@deepseek-ai/cordis、@deepseek-ai/dsh-client-runtime等包,用户无需手动安装,支持DSH 0.0.1-rc.2以上版本,遵循MIT开源协议。安装方式支持从npm注册表或GitHub源码安装,安装后需重启Web服务生效,使用GitHub源安装时若被pnpm拦截,需将包名加入配置文件允许构建列表后重试。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-webui-market-plugin(Sanqi-normal/dsh-webui-market-plugin)
仓库:https://github.com/Sanqi-normal/dsh-webui-market-plugin
本站详情页:https://www.yhbd.top/plugins/sanqi-normal-dsh-webui-market-plugin/
本站登记:类型 collection · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 104 · 最近提交 2026-08-22 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- This site's static screen found no obvious risk signal (stars, license, activity, manifest)本站静态筛查没发现明显风险信号(星标、许可证、更新活跃度、清单完整度)
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @sanqi-normal/dsh-webui-market-plugin
把 Sanqi-normal/dsh-webui-market-plugin 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-webui-market-plugin
English | 中文
在 dsh web GUI 内部的社区插件市场:浏览 awesome-dsh-plugin.com 的插件目录,直接在 设置 → 插件 → 插件市场 里安装 / 卸载插件到 profile。界面风格与 harness 前端一致(跟随系统深浅色主题),支持中英文(按系统语言自动切换)。
推荐 awesome-dsh-plugin.com 网站的实现 dsh-market。
效果展示

安装
方式一:从 npm registry 安装(推荐,无 git 克隆 / prepare 脚本步骤):
dsh plugin --profile web add @sanqi-normal/dsh-webui-market-plugin
方式二:从 GitHub 源码安装:
dsh plugin --profile web add github:Sanqi-normal/dsh-webui-market-plugin
安装后重启 web 服务生效:
pnpm dsh web
GitHub 源安装会执行包内 prepare 脚本,如被 pnpm 拦截,把提示的包名加入 profile 的 pnpm-workspace.yaml 的 allowBuilds 后重试。
pnpm 11 起,依赖树中"构建脚本未在 allowBuilds 中显式放行或拒绝"的包会直接导致 ERR_PNPM_IGNORED_BUILDS。若该包在当前 profile 不需要执行构建脚本,可把对应项写成 false(明确拒绝)而不是 true(放行执行);市场插件的试装验证会继承真实 web profile 的 pnpm-workspace.yaml,因此这里的 true/false 决策也会作用于试装环境。
宿主依赖说明
本插件是 DSH web profile 内运行的插件,不是独立 npm 应用。以下 peer 依赖由 DSH 宿主环境提供,用户无需手动安装:
@deepseek-ai/cordis@deepseek-ai/dsh-client-runtime@deepseek-ai/dsh-client-ui-slots
当前版本面向 DSH 0.0.1-rc.2+(不含已知解析问题的 0.0.1-rc.1)及 0.1.0-rc.2+ 环境。若使用纯 npm registry 工具解析本包,可能因为 DSH 上游部分 host 包未发布而提示依赖图不完整,这属于 DSH 宿主依赖的发布问题。
使用
打开 设置(Settings)→ 插件(Plugins)→ 插件市场(Plugin Market):
- 目录按分类分组,支持搜索与"已安装"过滤;每个卡片显示 GitHub Star 数(无数据不显示),可一键按 最热(Star 降序,无 Star 的排最后)/ 最新(收录日期) 排序,或恢复官网默认顺序;大目录分批渐进渲染,避免打开瞬间一次性插入数百卡片造成卡顿
- 点 详情 查看该插件的官方安装命令(含目标 profile)
- 跨 Profile 安装 / 一键同步(desktop 等):官网目录只发布
--profile web命令,而桌面端(desktop shell)启动的是自己独立的 profile(如desktop),市场装进 web 的插件桌面应用不会自动加载。面板顶部有 安装设置(含说明)与 跨 Profile 同步 区,自动列出本机已初始化的 profile:- 默认「有什么装什么」:
安装设置里的「自动同步到其它 profile」默认开启——安装插件时自动装到本机所有已初始化的 profile(有 web 装 web,有 desktop 也装 desktop;在确认框直接选了 desktop 的也会自动补装到 web);关闭后仅装到安装时选择的 profile - 安装确认框可选目标 profile(默认 web);跨 Profile 同步 区把 web 里已装的插件一键补装到目标 profile(只新增缺失项)
- 同步是本地复制:源已在源 profile 安装过(syncFrom 校验),所以不再受目录白名单限制——装在 web 但不在精选目录的插件(如 aegis)也能同步;每个补装任务照常做安装前快照 + FIFO 队列,装完后重启对应应用生效
- 默认「有什么装什么」:
- 安装 / 更新 / 卸载 组成 FIFO 任务队列:多个插件可以连续排队提交,任务面板固定在右下角、不随页面滚动隐藏,实时显示「排队中 / 校验中 / 执行中 / 完成 / 失败 / 已终止 / 超时」,可取消排队项、终止执行项、查看每个任务的 pnpm 日志;每个任务默认超过 120 秒自动超时(可用环境变量
DSH_MARKET_OP_TIMEOUT_MS调大,如300000);遇到 pnpm 的临时网络错误(GET ... error/ETIMEDOUT/ECONNRESET等)会自动重试一次,持续失败时给出代理/镜像排查提示;一键更新全部会把所有可更新插件依次加入队列;队列头部「清空」可一键清除全部已完成/失败记录(逐条清除也支持),清除会同步到服务端,刷新或重新打开面板后不会再次出现 - 失败后询问 DSH:安装 / 更新 / 卸载失败(含超时、已终止、已拒绝)后,失败弹窗和任务队列的失败行会出现 询问 DSH 按钮;点击后前端会新建一个对话,并把操作目标、状态、环境信息和完整错误日志作为 prompt 自动发送给 AI,方便直接排查或解释状况
- pnpm ≥11 默认开启 24 小时 minimumReleaseAge 供应链策略:依赖里刚发布(24 小时内)的包会让所有安装/更新/卸载被 pnpm 拦截。遇到 ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION 时市场会自动把违规的 name@version 合并进 profile 的 pnpm-workspace.yaml 的 minimumReleaseAgeExclude(同名多版本写成 name@v1||v2 联合,避免 pnpm 只认首条同名规则)并自动重试一次,无需手动改配置
- 停用 / 启用:停用保留依赖与磁盘文件,只把插件移出激活的 bundle 层(重启后仍保持停用);启用按原顺序恢复,免删装;卡片操作区横向排列在卡片底部,避免右侧按钮拥挤
- 本机插件:列出所有由依赖管理的插件(含在市场之外安装的、以及未进 bundle 层的 client-only/普通依赖),标注目录内/目录外、已停用、来源类型,可直接停用、启用或卸载(内置 bundle 与本地 link/file 源不会提供删除)
- 每个插件卡片显示真实的已安装状态(与 profile 的
package.json同步):安装状态按「作者 + 仓库」(owner/repo)识别,目录里有同名插件(如两个作者的dsh-memory)时,装了哪个作者就只显示哪个已安装,不会误标另一位作者的卡片;「本机插件」列表也会显示解析出的owner/repo身份 - 顶部显示插件目录来源官网链接,可直接打开
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
hyqibot/A-share-Ai
realguan/dsh-dock
euanguo/dsh-studio
Yui-Little/dsh-mobile-shell
Toukaiteio/dsh-plugin-installer