How it behaves
The Web settings page loads the plugin catalogue from registry.json, distributed through jsDelivr and then raw.githubusercontent.com. If both fail, it paginates the GitHub Search API and caches that result for 10 minutes. The CI job scans the GitHub dsh-plugin topic every two hours, merges and deduplicates repository metadata, excludes deepseek-harness, and sorts the generated index by Star count. Installation is performed separately by cloning the selected repository into ~/.dsh/marketplace/.
The page checks installed state when the marketplace opens. Its documented checks use installed.json, directory heuristics, package-name mappings, the package’s repository field, and a cached clone. Cordis plugin versions are compared with locally cached information; npm-published plugins use npm dist-tags. An available newer version changes the action to 更新 / update.
Installation targets
| Detected repository |
Target or action |
SKILL.md |
~/.dsh/skills/ |
preset.yml and agent.cordis.yml |
~/.dsh/.agent-presets/ |
package.json |
Install dependencies and register in the Web profile |
install.sh or install.ps1 |
Ask for confirmation, then execute the script |
When API_KEY, TOKEN, SECRET, or another required environment variable is detected, installation pauses for submitted material or an explicit skip. The material is supplied as environment variables and is not written to disk.
Configuration and commands
The plugin is registered in ~/.dsh/profiles/web/cordis.patch.yml with an entry containing id: dsh-plugin-marketplace and name: dsh-plugin-marketplace. The Web profile is documented with hmr disabled, so registration or code changes require restarting DSH with dsh web before refreshing the page. The official CLI installation, removal and update workflow uses the web profile; the marketplace itself also provides an in-page install and update action.
Requirements and safety
The documented setup expects the DSH Web profile. The CLI route requires dsh and pnpm; the repository also documents PowerShell for Windows and bash with curl for macOS and Linux when using its installer. Before running a third-party install.sh, install.ps1, or npm lifecycle script such as prepare, install, or postinstall, the page requests confirmation. Rejecting the prompt cancels the operation and cleans its traces. Host allowlisting and a CSRF header protect the HTTP surface, while environment-variable handling is minimised and isolated.
Known limits
The index is metadata rather than a review system: automatic inclusion follows GitHub topic detection, and the community badge is not an endorsement. Installation still contacts GitHub directly. If the CDN and raw index are unavailable, the GitHub Search API fallback is subject to its cache and API availability.
Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub