kimiya1010/dsh-plugin-market
A DeepSeek Harness plugin market: search and one-click install GitHub dsh-plugin plugins straight from the web GUI
Listed
1
Market
Bundle verified
What it does
A plugin market for DeepSeek Harness: search and one-click install GitHub dsh-plugin plugins straight from the web GUI.
Best for
- DSH Web users who want to discover GitHub repositories tagged as DSH plugins without using the CLI.
- Users who want one-click installation, removal, and visibility into installed third-party plugins.
- Plugin authors who publish discoverable repositories under the GitHub dsh-plugin topic.
Not ideal for
- Catalogs outside GitHub or repositories that are not tagged with the dsh-plugin topic.
- Security-sensitive environments that cannot permit installation and execution of third-party repository code.
- Workflows requiring immutable installs unless users explicitly pin GitHub specifications to commits.
README
dsh-plugin-market
| *English | 简体中文* |
A DeepSeek Harness (DSH) plugin that lets users search for and install other plugins directly from the web GUI — no need to drop to a command line.
It adds a “Plugin market” tab under Settings → Plugins:
- 🔍 Search GitHub repositories tagged
dsh-plugin(sorted by stars) - 📋 Show each plugin’s name, description, and star count, with a link to its GitHub repo
- ⚡ One-click install (internally runs
dsh plugin --profile web add github:owner/repo) - 🗑️ One-click uninstall of installed third-party plugins
- 📦 List the plugins currently installed in the profile (
dsh.profile.bundles)
Install
Install it like any other DSH bundle:
# Install into your web profile straight from GitHub
dsh plugin --profile web add github:kimiya1010/dsh-plugin-market
# Restart the web GUI to activate it
dsh web
Or from a local checkout:
dsh plugin --profile web add ./dsh-plugin-market
Note: this plugin is plain JavaScript with no
preparebuild script, so agithub:install needs noallowedBuildsentry — it works out of the box.
Directory layout
dsh-plugin-market/
├── package.json # dsh.bundle (patch layer) + dsh.client (browser half) declaration
├── cordis.patch.yml # inserts the loader row into the composition
├── index.js # Host half: registers the /api/plugin-market HTTP bridge + search/install/uninstall
└── client.js # Client half: Settings "Plugin market" tab UI
How it works
-
Host half (
index.js): injects thewebServerservice and registers a same-origin prefix route/api/plugin-market:-
GET /api/plugin-market/search?q=<keyword>— calls the GitHub Search API (topic:dsh-plugin) -
POST /api/plugin-market/install(body{ "spec": "github:owner/repo" }) — runsdsh plugin add -
GET /api/plugin-market/list— reads the profile’sdsh.profile.bundles -
POST /api/plugin-market/remove(body{ "name": "…" }) — runsdsh plugin remove
-
-
Client half (
client.js): registers the “Plugin market” page into thesettings.plugins.tabslot and calls the HTTP bridge over same-originfetch, rendering the search box, result list, install/uninstall buttons, and the installed list.
Because the bridge lives on the port the web GUI itself listens on (same origin), there is no cross-origin issue and no change to the framework’s own Remote descriptors.
Publishing your own fork
Push this repo to your own GitHub and tag it with dsh-plugin
so other users’ plugin markets can find it. You can also publish to npm:
npm publish --access public
Security note
Installing a third-party plugin runs its author’s code on your machine (a prepare script may run
at install time, and the bundle is loaded at runtime). Only install plugins from sources you trust,
and pin to a commit (github:owner/repo#<sha>) when you want to prevent upstream changes from
silently altering behavior.
License
MIT
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:kimiya1010/dsh-plugin-market in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.