DSH Marketplace

DSH-Plugins-Marketplace

bradeGithub/DSH-Plugins-Marketplace

GitHub-topic-driven plugin & skill marketplace: a Settings page that browses the auto-collected registry (the whole dsh-plugin topic plus the skills index, CI-refreshed every 2 hours) with one-click install, type detection, install-script and host-shadow-dependency safety confirmations, env-key management, and the STANDARD.md recognition spec.

1679JavaScriptMITSource

Install

Add DSH-Plugins-Marketplace to DeepSeek Harness

via GitHub · GitHub source

Installing from GitHub runs the project's build script, which pnpm blocks until you allowlist it — run the command once and pnpm prints the exact key to add under `allowBuilds` in ~/.dsh/profiles/web/pnpm-workspace.yaml.

What happened when we ran it

Installed cleanly when we ran it

Every command here is run in a throwaway container against a clean profile, and the result is whatever the harness recorded — not a guess from the source. Last run 6d ago.

Show it in your README

install verified — dshmarketplace

For maintainers: the badge serves this listing's latest sandbox verdict, so a re-run updates it on its own — and it links readers to the full result here.

Due diligence

Before you install DSH-Plugins-Marketplace

  • Source of record: bradeGithub/DSH-Plugins-Marketplace — present in the community registry that DSH's own plugin market installs from.
  • Licensed under MIT.
  • Detected: terminal surface, requires credentials. Read the source before granting these.
  • A listing here is not a security review. Plugins run with your agent's permissions.

What DSH-Plugins-Marketplace does

Abstract repository streams pass through detection and safety gates into local installation blocks.

DSH-Plugins-Marketplace is a DeepSeek Harness plugin that provides a Web GUI catalogue for GitHub-hosted DSH plugins and general skills. It reads a CI-generated registry.json index, served through jsDelivr with a raw.githubusercontent.com fallback, and uses GitHub Search API only if both index sources fail. GitHub Actions refreshes the index every two hours by scanning the dsh-plugin topic; installation still clones repositories directly from GitHub.

From Settings, the marketplace identifies SKILL.md repositories, agent presets containing preset.yml and agent.cordis.yml, Cordis plugins containing package.json, and repositories with install.sh or install.ps1. It can install skills under ~/.dsh/skills/, presets under ~/.dsh/.agent-presets/, and Cordis plugins in the Web profile. It records installation state, compares versions, and requests confirmation before running third-party installers or npm lifecycle scripts. If a repository asks for API_KEY, TOKEN, or SECRET, the page pauses for input and passes the material as environment variables rather than storing it on disk. It also performs the documented host-shadow-dependency safety check.

This is intended for developers who want to discover and install community repositories from the DSH Web settings page instead of handling each repository manually. It is a poor choice for environments that do not use the DSH Web profile, cannot restart DSH after registration changes, or do not permit terminal commands and third-party installation scripts. The plugin reaches GitHub, the local DSH profile and marketplace clone directory, and may execute repository-provided scripts with the agent’s available permissions. DSH-Plugins-Marketplace does not provide a human-reviewed catalogue: topic tagging controls automatic inclusion.

DSH-Plugins-Marketplace documentation

How it behaves

The Web settings page loads the plugin catalogue from registry.json, distributed through jsDelivr and then raw.githubusercontent.com. If both fail, it paginates the GitHub Search API and caches that result for 10 minutes. The CI job scans the GitHub dsh-plugin topic every two hours, merges and deduplicates repository metadata, excludes deepseek-harness, and sorts the generated index by Star count. Installation is performed separately by cloning the selected repository into ~/.dsh/marketplace/.

The page checks installed state when the marketplace opens. Its documented checks use installed.json, directory heuristics, package-name mappings, the package’s repository field, and a cached clone. Cordis plugin versions are compared with locally cached information; npm-published plugins use npm dist-tags. An available newer version changes the action to 更新 / update.

Installation targets

Detected repository Target or action
SKILL.md ~/.dsh/skills/
preset.yml and agent.cordis.yml ~/.dsh/.agent-presets/
package.json Install dependencies and register in the Web profile
install.sh or install.ps1 Ask for confirmation, then execute the script

When API_KEY, TOKEN, SECRET, or another required environment variable is detected, installation pauses for submitted material or an explicit skip. The material is supplied as environment variables and is not written to disk.

Configuration and commands

The plugin is registered in ~/.dsh/profiles/web/cordis.patch.yml with an entry containing id: dsh-plugin-marketplace and name: dsh-plugin-marketplace. The Web profile is documented with hmr disabled, so registration or code changes require restarting DSH with dsh web before refreshing the page. The official CLI installation, removal and update workflow uses the web profile; the marketplace itself also provides an in-page install and update action.

Requirements and safety

The documented setup expects the DSH Web profile. The CLI route requires dsh and pnpm; the repository also documents PowerShell for Windows and bash with curl for macOS and Linux when using its installer. Before running a third-party install.sh, install.ps1, or npm lifecycle script such as prepare, install, or postinstall, the page requests confirmation. Rejecting the prompt cancels the operation and cleans its traces. Host allowlisting and a CSRF header protect the HTTP surface, while environment-variable handling is minimised and isolated.

Known limits

The index is metadata rather than a review system: automatic inclusion follows GitHub topic detection, and the community badge is not an endorsement. Installation still contacts GitHub directly. If the CDN and raw index are unavailable, the GitHub Search API fallback is subject to its cache and API availability.

Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub

Same category

Alternatives to DSH-Plugins-Marketplace

dsh-plugin-manager

zhu1090093659

7.6k

Plugin manager tab in DSH Settings → Plugins: install from npm or git with progress, enable/disable switches effective at next startup, conflict reconciliation with undo, and one-click hand-off to a fix session.

Installed cleanly when we ran it

npm packageTypeScript17d ago

AI review

dsh-plugin-manager

What it is — Adds a plugin management tab in DSH settings for installing from npm or git.

Who it is for — Users who need to install and manage plugins from npm or git in DSH. Users who do not need to handle installation conflicts do not need this plugin.

Watch out — Sandbox test passed: installed in a new profile and registered by the harness. No obvious issues found.

The verdict — I would install it because it supports switching at next startup and conflict reconciliation with undo.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
Source

dsh-market

dsh-market

4.7k

Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.

Installed cleanly when we ran it

npm packageTypeScript5d ago

AI review

dsh-market

What it is — A plugin market inside DeepSeek Harness for browsing, searching, and installing community plugins.

Who it is for — If you need to extend plugin capabilities in your DeepSeek Harness web configuration, this is suitable. If you are using an older host, you can skip it because the market disables itself and shows in the browser console.

Watch out — Sandbox test passed: installed in a new profile and registered to the profile. No obvious pitfalls found, but requires providing an API key or token.

The verdict — I would install it because it supports configuration backup via WebDAV or Gist sync.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Details

dsh-find-plugin

awesome-dsh-plugin

148

Find plugins without leaving the agent: search this curated registry by keyword or category, with ready-to-run install commands.

Installed cleanly when we ran it

npm packageJavaScript8d ago

AI review

dsh-find-plugin

What it is — A tool to search the DSH plugin ecosystem via agent dialogue.

Who it is for — When you want the agent to discover specific plugins like terminal TUI or WeChat notification plugins. If you prefer to directly install known plugins using npm commands instead of letting the agent search automatically.

Watch out — It passed sandbox testing after installation in a new profile and was registered. No obvious issues found. Third-party plugins require manual review of the source and pinning a commit.

The verdict — I would install it because it lets the agent automatically search the plugin ecosystem and provide install commands, but I would review the source first as they are third-party.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
Details

dsh-skin-market

kingOfSoySauce

135

Native skin marketplace and lifecycle manager that discovers community skins, displays previews and compatibility status, and provides verified one-click or manual installation paths.

Installed cleanly when we ran it

npm packageTypeScript21d ago

AI review

dsh-skin-market

What it is — A plugin for DSH web profile that discovers community skins, displays previews and manages verified installations.

Who it is for — If you need to customize the DSH web profile interface with additional skins beyond built-in options, this plugin is suitable. If you already have a reliable skin management system in your profile, you can skip it.

Watch out — Installation succeeds in a fresh profile and registers with harness. No obvious issues found.

The verdict — I would install it because it offers a straightforward way to add community skins to DSH web profile, with the condition that you are using the web profile.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source
111

DeepSeek Harness 社区内置插件市场(dsh-plugin)— 搜索插件、下载并安装 4000+ 人工精选社区插件,每日更新、完全免费。内置在 Harness「设置 → 插件中心」,无需离开应用即可浏览、搜索、安装各类 AI 插件。

Installed cleanly when we ran it

npm packageTypeScript19d ago

AI review

dsh-plugin-hub

What it is — DeepSeek Harness community plugin market, allowing searching, downloading and installing community plugins within the app.

Who it is for — Suitable for users who need to integrate various AI plugins into DeepSeek Harness. Those who only use official plugins can skip this.

Watch out — Sandbox test passes: installed in a new profile and registered by Harness. No obvious issues found.

The verdict — I would install it because it is free and daily updated.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source

In-harness plugin market for the dsh web GUI: browse the awesome-dsh-plugin.com catalog and install/uninstall plugins into a profile from Settings → Plugins → Plugin Market.

Installed cleanly when we ran it

npm packageJavaScript1mo ago

AI review

dsh-webui-market-plugin

What it is — Provides plugin market interface for DeepSeek Harness web GUI to browse and install community plugins.

Who it is for — Users of DeepSeek Harness web profile can use this to install community plugins when extending agent capabilities. Users not using web GUI or not needing community plugin features do not need to install this plugin.

Watch out — Sandbox test showed successful installation and registration into the profile. Installing from source requires manually allowing the build script. No obvious pitfalls found.

The verdict — I would install it because it supports cross-profile synchronization, but only under the condition that the target profile is initialized.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details