Introduction

The core philosophy of DeepSeek Harness is “everything is a plugin.” As the number of plugins grows, manually managing the community catalog, the package manifest of the current Profile, and the Loader runtime becomes cumbersome and error-prone. dsh-plugin-console is a plugin manager installed in the DeepSeek Harness Web profile. It integrates community catalog synchronization, Profile package manifest inspection, Loader runtime viewing, pre-installation validation, isolated trial runs, and one-click Harness updates into the “Plugin Management” page in Settings, and performs underlying operations through the official dsh plugin command.

The plugin is maintained by AlexYin-Tongji and follows the MIT license. It does not provide marketing-style “empowerment”; instead, it helps developers manage the plugin ecosystem safely and controllably through concrete steps and validation mechanisms.

Core Features

This plugin mainly includes the following functional modules:

  • Plugin Store: Synchronizes the awesome-dsh-plugin catalog by default, and supports search, categorization, pagination, and local caching.
  • Pre-installation Validation: Before installation, checks valid SemVer, repository, HTTPS tarball, SHA-512 integrity, dsh.bundle.patch, and lifecycle scripts for npm packages; GitHub packages are pinned to commits.
  • Installed Manifest: Reads the Profile’s direct dependencies, bundle order, resolved package manifest, Loader entry/Fiber phase, and Web client capabilities.
  • Usage Instructions: Supports Markdown, MDX, RST, TXT, and extensionless READMEs, with source view supported.
  • Quick Update: Does not install automatically; executes after user confirmation. Supports version upgrades for community catalog entries and npm packages.
  • Quick Removal: Allows removal of direct dependencies only, and cleans up bundle configuration.
  • Pause Usage: Persists disabled state through a profile Loader patch.
  • Isolated Trial Run: Starts a full profile in a temporary DSH_HOME to detect inter-plugin or DSH/Cordis initialization conflicts.
  • Change Confirmation: Generates a plan valid for 5 minutes, validates the profile fingerprint and artifact integrity.
  • One-Click DSH Update: Provides a sidebar entry, supports checking the latest versions across channels, and one-click updates the Harness core.

Installation and Enabling

To install the plugin in the DSH environment, the official dsh plugin command is required.

dsh plugin --profile web add dsh-plugin-console@latest

After installation, go to the Settings page in DeepSeek Harness, and you can find the plugin’s control panel under the “Plugin Management” section.

Main Operations

The Plugin Store synchronizes the awesome-dsh-plugin catalog by default. It supports searching for plugins, browsing by category, and pagination. To improve response speed, catalog contents are cached locally.

2. Pre-installation Validation

When installing or updating a plugin, the system performs strict pre-validation:

  • Package Validity: Checks for a valid SemVer version number on the npm package.
  • Integrity: Validates the HTTPS tarball and SHA-512 integrity.
  • Dependency Check: Confirms whether dsh.bundle.patch and lifecycle scripts are present.
  • Source Locking: Packages from GitHub are pinned to specific 40-character commits to prevent supply-chain attacks.

3. Installed Manifest and Details

In the plugin management interface, you can inspect the detailed state of the current Profile:

  • Dependencies: Reads direct dependencies.
  • Load Order: Views the bundle order.
  • Runtime: Resolved package manifest, Loader entry, Fiber phase, and Web client capabilities.
  • Documentation Reading: Click a plugin card to view its README; supports Markdown, MDX, RST, and TXT formats, and includes a source view mode.

4. Update and Removal

  • Update: After the plugin manager detects a new version, it only shows an update button and does not execute automatically. Once the user confirms, the system performs the update. Packages listed in the community catalog are updated according to the validated artifact. npm packages can be updated only when the name, repository, valid upgrade version, and integrity all validate successfully.
  • Removal: To protect system stability, only direct dependencies can be removed, and system bundles are protected. Removal also clears the corresponding layer configuration in dsh.profile.bundles.

5. Isolated Trial Run and Change Confirmation

  • Isolated Trial Run: After installation or update, the system starts the full Web profile in a temporary DSH_HOME, on a random port, and in an isolated environment. This helps detect inter-plugin or DSH/Cordis initialization conflicts in advance. If the Loader entry, package version, bundle syntax, or HTTP resource validation for the target bundle fails, the system automatically restores the previous version.
  • Change Confirmation: All write operations first generate a plan valid for 5 minutes. Before execution, the profile fingerprint, current package state, and artifact integrity are revalidated.

6. One-Click DSH Update

A Harness update entry is added at the bottom of the left sidebar.

  • Version Check: Supports checking the latest versions across channels (e.g., latest/next); the panel displays the running, installed, and latest versions.
  • Update Execution: After clicking update, the Harness core can be updated with one click. Updates only support npm global installation, and precise validation plus isolated verification are performed to ensure all plugins are compatible before the update takes effect.

Security and Limitations

  • Removal Limitation: Only direct dependencies can be removed; system bundles are protected.
  • Security Boundary: The browser API only accepts typed install/update/remove/pause/resume operations, and child processes use argument arrays and shell: false.
  • Harness Update: Only npm global installation is supported.

Summary

dsh-plugin-console is an important management tool in the DeepSeek Harness plugin ecosystem. Through strict validation mechanisms, an isolated trial-run environment, and a standardized change confirmation process, it addresses security and stability issues in plugin management. For developers who need to manage Profiles and Loaders, this tool provides a complete closed loop, from discovery to installation and then to runtime monitoring.