YELEBAI/dsh-plugin-marketplace
已验证插件市场及DeepSeek Harness的自主注册表
Project Overview项目介绍
This repository is a natively built plugin marketplace for DSH, created specifically to host verified DSH plugins and maintain a central registry for the entire DSH ecosystem. Unlike uncurated collections that automatically index every repository tagged with dsh-plugin, this marketplace only includes plugins that have passed automated validation checks for manifest format, compatibility, and source integrity. To install the marketplace itself on your local DSH instance, you can run the official DSH CLI command dsh plugin --profile web add github:YELEBAI/dsh-plugin-marketplace#v0.9.4 to add it directly to your DSH web profile. After installation, you can start DSH and access the marketplace via the Settings > Plugins menu.
The marketplace has three primary pages that support different user workflows. The main plugin discovery page lets users search, sort, and filter plugins by category, star count, and 7-day growth trend, so you can easily discover and find the exact plugins you need for your use case. The installed plugins page lets you check for available updates, and perform bulk operations like updating, enabling, disabling, or uninstalling multiple selected plugins at one time. The admin and diagnostics page supports manual plugin installation via DSH command, conflict checks, and configuration of the agent installation workspace.
The marketplace requires Node.js version 22.19.0 or newer, or version 24.0.0 or newer, to run correctly on your local machine. It is licensed under the permissive MIT license, so you can use, modify, and distribute it freely in accordance with the terms of the license. While the automated validation process blocks malformed or incorrectly packaged plugins, it cannot guarantee that all third-party plugins hosted in the registry are completely safe, so you should always review the source and permissions of any plugin before installing it. If you want to contribute to the registry or run local scans, you will need pnpm and a personal GitHub access token.
YELEBAI/dsh-plugin-marketplace 是专门为 DeepSeek Harness (DSH) 打造的经过验证的插件市场与自主维护的中心 Registry。它每两小时扫描一次带 dsh-plugin 主题的公开仓库,仅将通过格式、兼容性和来源验证的插件纳入市场,支持合格插件一键安装,为需要额外检查的插件提供代理引导安装流程。
该插件市场提供三个核心功能页面:插件发现页支持按分类搜索、按星标数量和近期增长趋势排序筛选;已安装插件管理页支持单独或批量更新、启停、卸载插件;管理诊断页支持手动命令安装和冲突检测。它需要运行在 DSH 的 web 配置文件下,依赖 Node.js 22.19 以上或 24 以上版本,以及 DSH 核心依赖包 @deepseek-ai/cordis。
本项目采用 MIT 许可证开源,可免费使用。Registry 验证可以排除格式错误、结构不完整的伪插件,但无法保证第三方插件代码的绝对安全,用户安装前仍需确认插件来源可靠。如果需要在本地运行 Registry 扫描,还需要配置 GitHub 访问令牌和 pnpm 包管理器。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugin-marketplace(YELEBAI/dsh-plugin-marketplace)
仓库:https://github.com/YELEBAI/dsh-plugin-marketplace
本站详情页:https://www.yhbd.top/plugins/yelebai-dsh-plugin-marketplace/
本站登记:类型 collection · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 20 · 最近提交 2026-10-03 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 20 stars - an early-stage project星标 20,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:YELEBAI/dsh-plugin-marketplace#v0.9.4
把 YELEBAI/dsh-plugin-marketplace 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
[!IMPORTANT] 市场不会直接展示 GitHub
dsh-plugintopic 下的所有仓库。只有经过扫描器验证并写入中心 Registry 的插件,才会进入市场。
为什么使用它?
| 能力 | 说明 |
|---|---|
| 🔍 自动发现 | 每两小时扫描一次 topic:dsh-plugin archived:false |
| ✅ Registry 验证 | 检查 manifest、bundle patch、loader entry、运行产物和精确安装来源 |
| 🧩 dsh-std 预检 | 读取可选 dsh-plugin.json,验证 Community v0.15 与 dsh-TUI v0.15 的静态准入闭包 |
| ⚡ 一键安装 | 仅对全部自动安装条件均通过的插件开放 |
| 🤖 Agent 安装 | 为需要构建、生命周期脚本或人工判断的插件创建受约束的安装 Agent |
| 🧭 安装 Skill | Agent 强制加载内置安全工作流,自动选择精确来源、隔离构建或停止路径 |
| 🧱 Agent 工作区 | 默认使用市场专属工作区,也可选择已有目录,避免污染项目工作区 |
| ⌨️ 手动命令安装/更新 | 安全解析官方 DSH GitHub 命令,验证后安装或更新当前 Profile |
| 🧰 安装管理 | 按更新/启停状态筛选,单独或批量更新、卸载、启用、停用,并可安全重启 DSH |
| 📈 插件发现 | 支持分类、搜索、Star 排序和最近 7 天增长趋势 |
| 🔄 市场自更新 | 直接检查本仓库版本,并将更新来源固定到解析后的精确 commit |
快速开始
运行要求与分发说明
- Node.js:
^22.19.0 || >=24.0.0;使用 DSH 的 web Profile。 - DSH 依赖:
@deepseek-ai/cordis ^4.0.1、dsh-app-boot和dsh-typert-protocol ^0.1.0-rc.5,由peerDependencies声明。版本范围不代表每个 DSH Release 都经过独立运行时认证。 - 安装包包含编译后的 Host、Web Client、Typert 入口及对应类型声明;安装本插件无需执行构建或生命周期脚本。
zod是参数和远程协议校验所需的运行依赖,并非安装脚本。市场会访问 Registry/GitHub;用户发起安装或更新时还会调用包管理器并访问对应包源,读写当前 Profile 与选定的插件目录;Agent 任务使用独立工作区。这些权限不能等同于“无权限插件”或安全认证。
1. 安装
dsh plugin --profile web add github:YELEBAI/dsh-plugin-marketplace#v0.9.4
本地开发安装:
dsh plugin --profile web add D:/path/to/dsh_Market
2. 启动
dsh --profile web
3. 打开市场
进入 设置 → 插件 → 插件市场。
市场包含三个子页面:
- 插件市场:搜索、分类、排序、查看验证信息并安装插件。
- 已安装插件:过滤、检查更新,单独或批量更新、卸载、启用或停用当前 Profile 的插件。
- 管理与诊断:手动命令安装、选择插件安装位置并执行冲突诊断。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
freestylefly/awesome-gpt-image-2
awesome-dsh-plugin/awesome-dsh-plugin
zhu1090093659/dsh-web
dsh-market/dsh-market
superdesigndev/treg
AdamPlatin123/dsh-plugin-radar
0xsline/awesome-deepseek-harness