Introduction¶
The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” As the plugin ecosystem expands, installing, managing dependencies, and checking versions one by one from the command line becomes increasingly cumbersome and prone to configuration errors. dsh-plugin-hub is a graphical plugin store designed for the DSH Web UI. It allows users to browse, search, and one-click install GitHub repositories under the dsh-plugin topic directly from their browser. In addition to serving as a general-purpose plugin distribution channel, dsh-plugin-hub itself contains 21 built-in functional modules and presets 16 commonly used plugins, aiming to simplify the lifecycle management of DSH plugins.
Core Features¶
Graphical Management and Discovery
A “Plugin Store” entry appears at the bottom of the DSH Web UI sidebar. The store supports filtering by 12 categories, 7 sorting options (Random, Health, Stars, Rating, Downloads, Updated, Name), and provides search and installed filtering. Users can view a plugin’s trust badge and download source, and click the “Install” button to write the plugin to cordis.patch.yml, making the configuration effective in real time.
21 Built-in Plugins and Offline Presets
dsh-plugin-hub itself is a package with 22 lines of configuration (1 core + 21 sub-plugins), covering five categories: basic kernel, security and quality, publishing pipeline, insights and content, and operations. All built-in plugins can be individually enabled or disabled under “Plugin Store” in the Settings page.
In addition, to address the “empty store” issue caused by synchronization delays for new users, the plugin includes 16 offline preset plugins (such as dsh-cost-meter and dsh-notification). These plugins are written to the local directory by hub-ext-seed-catalog and follow an “insert-only, no overwrite” principle: once a package is actually synced and written, the preset directory will no longer overwrite its contents.
Health and Security
The store provides a Top 20 Health leaderboard, displaying plugin trust levels and dynamic trends. The details page includes the score breakdown, version release timeline, and a trend chart based on actual npm download counts. Before installation, the plugin uses a security scan to detect dangerous scripts, sensitive file reads, dynamic execution, and suspicious outbound connections, and blocks non-compliant installations through conflict detection and quality gates.
Publishing and Auditing
One-click publishing is supported. By providing a Markdown description, it simultaneously pushes code to a GitHub repository and publishes an npm package. The publishing process includes a security scan, a version consistency guard (checking whether package.json, README, exports, etc. have been synchronously updated), and quality gate checks. All actions (installation, uninstallation, enable/disable, rating, publishing) are recorded in the audit log and persisted to a local SQLite database.
Installation and Enablement¶
Install the plugin from the command line:
dsh plugin --profile web add dsh-plugin-hub
After installation, a “Plugin Store” entry appears in the sidebar, and a “Plugin Store” configuration section is added to the Settings page. On first use, it is recommended to click “Sync Now” in the Settings page to load the local mirror cache.
Design and Implementation¶
Declarative Dependencies and Decoupling
To avoid deadlock issues caused by hard dependencies (i.e., “provider disabled → consumer remains Pending indefinitely”), dsh-plugin-hub uses declarative dependency management. The dependencies between plugins are declared in the configuration manifest, rather than hard-injected via Cordis inject. When a user disables a plugin (such as “Store Database”), other modules that depend on it actively report a “dependency block” and yield, no longer providing services or registering a UI; when the plugin is re-enabled, the dependency chain recovers automatically.
Two-Level Switch Mechanism
The plugin supports two levels of control:
1. Installation level: Configure disabled: true in cordis.patch.yml to control whether the plugin is loaded.
2. Runtime level: Manage by group under “Built-in Plugins” in the DSH Settings page, modify storages/plugin-store/plugins.json, and restart DSH to apply the changes.
Note: The four plugins disabled by default (changelog / baike / skill-store / diagnostics) do not have disabled: true written in patch.yml. This is because if the loader does not load the module, the code inside the module cannot read the switch from the Settings page, preventing the setting from taking effect. The disabled-by-default state is implemented by the module’s own startup logic, ensuring the switch is reversible.
Built-in Plugin Details¶
Usage and Costs
hub-ext-usage provides dated price tables and supports looking up historical prices. It records the Tokens and cache hit rate for each request in a session, and displays the difference between the price at the time and the current price. Price tables are managed by version; when prices change, only a new version is appended, and historical data is immutable.
Operations and Diagnostics
hub-ext-backup supports exporting the database and plugin state snapshots via VACUUM INTO, retains only the latest 10 backups, and supports a second backup before rollback. hub-ext-diagnostics (disabled by default) can export a diagnostic report in Markdown format, including environment details, plugin status, dependency statistics, and audit logs.
Notes¶
- Version Compatibility: This plugin is compatible with DSH
0.1.5-rc.1(based on cordis 4.0.2). - Permission Requirements: The plugin runs with the current DSH process permissions, and the publishing feature requires a valid GitHub Token to be configured.
- Ecosystem Note: DSH is an open-source project, and dsh-plugin-hub is a community-maintained plugin with no official affiliation with DeepSeek / High-Flyer.