springbrand-lab/dsh-plugin-market
DeepSeek Harness Web 设置的插件市场:可在任何本地配置文件中安装、更新和移除插件。
项目介绍Project Overview
本插件为 DeepSeek Harness Web 设置中的可视化插件市场,支持浏览、搜索、安装、更新与删除插件,覆盖 web、headless 等本地 profile,并可在 SpringBrand Desktop 中自更新。适用于通过统一界面管理 DSH 插件及依赖。注意:第三方插件非安全背书,仅安装可信来源;当前 profile 的更改会自动重启 DSH。
This plugin provides a visual marketplace inside DeepSeek Harness Web settings for browsing, searching, installing, updating, and removing plugins across local profiles such as web and headless, and it self-updates in SpringBrand Desktop. Use it to manage DSH plugins and dependencies from one interface. Caveat: third-party plugins are not security-endorsed, so install only sources you trust, and current-profile changes trigger an automatic DSH restart.
请帮我了解并安装插件:【dsh-plugin-market】【https://github.com/springbrand-lab/dsh-plugin-market】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add @springbrand/dsh-plugin-marketplace
把 springbrand-lab/dsh-plugin-market 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
@springbrand/dsh-plugin-marketplace
English | 中文
The visual plugin marketplace built into DeepSeek Harness Web settings and bundled with SpringBrand Desktop. Open Settings → Plugin Marketplace to browse and search the catalog, then install, update, or remove plugins.

Install from scratch
You do not need DSH preinstalled.
Install the LTS version of Node.js, then close and reopen your terminal.
Install DSH and pnpm:
npm install --global pnpm @deepseek-ai/dshConfirm that DSH is available:
dsh --versionInstall the marketplace:
dsh plugin --profile web add @springbrand/dsh-plugin-marketplaceStart DSH Web:
dsh web
Keep the terminal open. Your browser normally opens automatically; otherwise, open the http://127.0.0.1:... address printed in the terminal. Then go to Settings → Plugin Marketplace.
If dsh is still not found after reopening the terminal, use:
npx @deepseek-ai/dsh plugin --profile web add @springbrand/dsh-plugin-marketplace
npx @deepseek-ai/dsh web
Already have DSH?
dsh plugin --profile web add @springbrand/dsh-plugin-marketplace
dsh web
What you get
- Browse and search by name, author, description, or npm package, with visible plugin categories, repository avatars, and compact GitHub Star counts.
- Profile management across
web,headless, and other local profiles under ordinary DSH; SpringBrand Desktop limits operations to its active profile. - Install, update, and remove in one place, with exact installed versions, visible update badges and counts, and one-click updates to the latest published version.
- Installed view covering both catalog entries and profile dependencies that are not listed in the catalog.
- Marketplace self-updates in SpringBrand Desktop by installing the latest release into the active profile; removing that profile override falls back to the version bundled with the app.
- Clear activation timing: changes to the current profile restart DSH automatically; changes to other profiles apply on their next launch.
Security
- Installation is limited to catalog entries marked
bundle,installable, andnpm. - The server resolves the npm package name from the catalog again instead of accepting an arbitrary source from the browser.
- Updates and removals accept only valid npm package names already installed in the selected profile.
- Mutation endpoints accept same-origin JSON POST requests only, with an 8 KiB body limit.
- Ordinary DSH commands are launched with argument arrays, never through a shell. SpringBrand Desktop delegates to its managed package-operation service. Only one plugin operation runs at a time.
Plugins are third-party code. Catalog inclusion is not a security endorsement; install only sources you trust.
How it works
[Web settings]
|
v
[Local HTTP API from this plugin]
|
+--> [dshplugin.market/api/catalog]
|
+--> ordinary DSH: dsh plugin --profile <profile> add|update|remove <package>
|
+--> SpringBrand Desktop plugins: desktopPnpm.runPlugin()
|
+--> SpringBrand Desktop marketplace override: desktopPnpm.run()
Under ordinary DSH, the marketplace targets the running profile by default and can select another profile in the UI. SpringBrand Desktop exposes only its active profile, runs package operations through desktopPnpm, and requests an orderly application restart through desktopProfiles. Third-party plugins use runPlugin() so DSH reconciles their bundle layers. The marketplace's own profile override uses direct run() because its row already belongs to Desktop; reconciling it as another bundle would duplicate that row. The plugin does not provide arbitrary hot-mounting or seamless port handoff.
Which profiles appear as targets
Under ordinary DSH the profile list is web, headless, the profile this process was launched with, and every directory under <DSH home>/profiles, sorted by name. The DSH home is DSH_HOME when set, otherwise ~/.dsh. profiles/node_modules is never offered as a target.
A profile appears in the list before it has been initialized, so a plugin can be installed into headless from a web session without creating the profile first. What the Installed view reports for each profile is that profile's own package.json dependency map — which is why it also lists packages that were installed outside this marketplace and are absent from the catalog. SpringBrand Desktop also reports the marketplace version bundled with the app; its first self-update creates a profile dependency that takes precedence after restart.
Configuration
Override these fields in the profile's Cordis configuration:
config:
profile: web
catalogUrl: https://dshplugin.market/api/catalog
restartDelayMs: 1500
profile: the profile used by an ordinary DSH process; read from the launch arguments by default. SpringBrand Desktop always uses its active profile.catalogUrl: the plugin catalog JSON URL; HTTP and HTTPS are supported.restartDelayMs: delay before restarting an ordinary DSH process, from 500 to 30000 milliseconds. SpringBrand Desktop owns its restart timing.
Uninstall
Remove the package from the marketplace's Installed tab, or run:
dsh plugin --profile web remove @springbrand/dsh-plugin-marketplace
Development
npm install
npm run check
License
MIT
nexu-io/open-design
ruvnet/ruflo
amruthpillai/reactive-resume
volcengine/OpenViking
Molunerfinn/PicGo
titanwings/colleague-skill
nocobase/nocobase
Tencent/WeKnora