Introduction

The core philosophy of DeepSeek Harness (DSH) is that “everything is a plugin.” In the face of tens of thousands of plugins in the community, developers usually encounter two pain points: first, it is difficult to precisely discover tools that fit the current project stage from a massive ecosystem; second, there is a lack of a unified security management mechanism. Existing plugin distribution methods often depend on external networks or lack awareness of local project state.

smart-dsh-market is a localized plugin hub designed to solve the above problems. It integrates a massive plugin index, project lifecycle-aware recommendations, and a minimalist interaction interface, aiming to provide a local-first, zero-data-upload security plugin management experience.

Plugin Positioning

This plugin is maintained by the developer wsifan31-bit and is a DSH plugin marketplace based on the MIT license. It is not only a plugin index repository, but also a DSH productivity hub that integrates a dual-engine discovery mechanism, a security grading system, and intelligent recommendation features. Its core value lies in expanding the originally delayed index of 2,786 plugins to 12,435+ and being able to intelligently recommend plugins locally based on Git status.

Core Features

The plugin provides the following main capabilities:

  1. Dual-Engine Discovery and Massive Indexing
    By dynamically accessing local DSH Desktop caches, the plugin breaks through the previous search limitation of 2,786 plugins. It achieves real-time synchronization with the latest plugin ecosystem across the network, supports a dual-engine discovery mechanism, and ensures that developers can obtain the latest plugin resources.

  2. Dual-Track Security Grading System
    The marketplace implements tiered management for plugins:

    • Officially Curated: For 2,786 verified plugins, it uses SHA Commit locking and non-invasive static audit, supporting one-click silent second-level installation.
    • Community Exploration: For 9,649 community plugins, it automatically routes them to the Agent isolation sandbox for installation, preventing unverified code from directly intruding into the system.
  3. 26px Nano HUD Conversation Bottom Bar
    Below the DSH conversation input bar, an ultra-lightweight 26px floating bar is mounted. It detects local Git repository status in real time (branches, dirty workspace, commit frequency) and the project lifecycle stage, and recommends suitable plugins in the bubble on the spot without occupying the main chat space.

  4. Project Lifecycle Intelligent Inference
    The plugin can infer the project stage (such as architecture, prototype, implementation, testing, polishing, and maintenance) from local Git history and test proportion. Based on evidence-based scoring (match, quality, growth, freshness, compatibility), it can rank and recommend plugins.

  5. Local-First and Privacy Protection
    All scoring, stage detection, and cache indexing support 100% offline operation. The plugin does not call external models, nor does it upload any private code data.

Installation and Activation

The plugin can be installed using the following three methods:

Method 1: Install Using DSH CLI (Recommended)
Run the following command in the terminal to install the plugin entity within the node_modules scope of the current Profile:

dsh plugin --profile web add github:wsifan31-bit/smart-dsh-market

The desktop client also supports this command.

Method 2: One-Click Installation Script
* Windows: Directly double-click to run install.bat in the repository root directory, or execute powershell -ExecutionPolicy Bypass -File scripts/install-desktop.ps1 in PowerShell.
* Linux / macOS: Run bash install.sh in the terminal.

Method 3: Agent Installation
For complex build or configuration requirements, you can choose the Agent installation mode.

After installation is completed, start DSH and enter Settings → Plugins → Plugin Marketplace to use it.

User Guide

After entering the plugin marketplace, there are three main subpages:

  • Plugin Marketplace: Used for searching, categorizing, and sorting plugins, viewing verification information, and executing installation.
  • Installed Plugins: Used for filtering, checking updates, uninstalling, or disabling plugins in the current Profile.
  • Management and Diagnostics: Supports manual command installation, selecting custom installation locations, and executing conflict diagnostics.

Installation Mode Description
The marketplace supports three installation modes:
1. One-Click Installation: Suitable for scenarios where exact GitHub commit or npm versions have passed checks.
2. Manual Command Installation: Users paste official DSH commands, and the marketplace parses and locks the commit before safely installing.
3. Agent Installation: For plugins that require build authorization, lifecycle scripts, or additional verification, it creates an isolated session to execute.

Self-Built Registry
The plugin supports configuring custom Registries. By default, a centralized Registry is used. If the remote is unavailable, the marketplace automatically falls back to the package-bundled snapshot. Configuration can be done through environment variables or the registryUrl item in the plugin configuration.

Notes

  1. Dependencies and Installation Location
    The plugin relies on two Host-side protocol packages (@deepseek-ai/dsh-typert-protocol, @deepseek-ai/dsh-app-boot). These packages are designed as peerDependency and must be provided by the DSH runtime from hoisted storage. Do not change them to dependencies or bundle them, otherwise it will cause silent service failure. Installation must ensure that the plugin entity is placed within the node_modules scope of the Profile.

  2. Agent Workspace
    The Agent binds workspace paths by default to $DSH_HOME/marketplace/agent-workspace. Custom workspaces must exist in advance and be readable and writable.

  3. Conflict Diagnostics
    The built-in conflict diagnostic panel in the marketplace performs heuristic static detection on enabled plugins (such as duplicate Bundle ID, Cordis service registration formats) as a preventive line before startup crashes.

Conclusion

smart-dsh-market provides DSH users with a complete closed loop from discovery to installation to management through dual-engine discovery, security grading, and localized intelligent recommendations. It reduces the cost of finding suitable plugins and ensures security through isolation mechanisms, making it a practical tool for building localized DSH development environments.