Introduction

The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In a plugin ecosystem, determining which plugins are worth installing, whether they meet security standards, and how to configure the environment quickly often requires working across multiple tools. dsh-insight unifies requirement recommendation, quality scoring, security auditing, and environment recipes into a single decision surface. Installing this single package provides a complete decision conclusion, instead of manually piecing together answers across three tools.

Core Features

This plugin contains five main modules, covering the full workflow from discovery to decision-making:

  1. plugin_guide: Requirement recommendation. Based on the user’s input requirements, it recommends the best-matching plugins (built-in 84 curated plugins across 14 categories, including reasons and installation commands).
  2. recipe: Environment recipes. It provides community recipes, and users can deploy an entire environment with one click via the apply command (e.g., notification stack, security audit package).
  3. plugin_rank: Health score ranking. It calculates a plugin health score (0-100) based on dimensions such as maintenance, documentation, and the NPM ecosystem.
  4. plugin_audit: Security scan. It performs static security scanning on a local directory, detecting risks such as data leakage, credentials, obfuscation, and persistence.
  5. plugin_verdict: Installation decision. It combines the score, security scan results, and requirement matching to output an installation recommendation (install / caution / research / avoid).

Installation and Dependencies

The installation command is as follows:

dsh plugin --profile <profile> add dsh-insight

This plugin depends on the following peer dependencies:

  • @deepseek-ai/cordis (^4.0.1)
  • @deepseek-ai/dsh-system-prompt (^0.1.0-rc.6)
  • @deepseek-ai/dsh-tools (^0.1.0-rc.6)
  • @deepseek-ai/schemastery (^3.18.1)

Usage Examples

  • Find plugins: plugin_guide (need=”scrape a webpage”)
  • Deploy environment: recipe (search need=”mobile remote”) → apply
  • View rankings: plugin_rank (sort=score)
  • Security audit: plugin_audit (dir=/path/to/checkout)
  • Final decision: plugin_verdict (repo + need + optional dir)

Design and Security

  • Pure logic layer: The core code (match.js, recipe.js, scoring.js, security.js, verdict.js) can all be unit tested independently and has zero dependencies.
  • Scoring model: The 0-100 score consists of four parts: Maintenance (30) + Documentation (25) + NPM (30) + Ecosystem (15).
  • Security mechanisms: The plugin itself makes zero network requests; plugin_audit performs read-only scanning only on the specified local directory, with a clear trust boundary.

Repository

https://github.com/863683348/dsh-insight