Introduction

DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture. To facilitate managing community plugins, a centralized directory and validation mechanism is required. dsh-plugin-store integrates the plugin store directly into the DSH Web GUI settings, providing curated directories, GitHub discovery, and structural validation, enabling users to validate and install plugins without leaving the interface.

Core Features

  • Directory and Discovery: Provides a curated directory based on the awesome-dsh-plugin ecosystem (including offline-first snapshots) and real-time discovery from GitHub topic:dsh-plugin (taking the top 30 non-fork repositories).
  • Structural Validation: Only allows installation of plugins whose root package.json declares name, version, and dsh.bundle.patch. Real-time re-validation is performed before installation.
  • Security Mechanisms: All modification operations (POST) are limited to under 8KB and must pass same-origin checks and process-level random token validation.

Installation and Activation

Install to the web profile via CLI:

dsh plugin --profile web add github:anjaymi/dsh-plugin-store

After installation, restart the Web GUI:

dsh web

After restart, a “Plugin Store” tab appears under “Settings → Plugins” in the Web GUI.

Usage

  • Filtering and Search: Supports searching by repository name or description; the tab provides category filters for “All / Curated / Newly Discovered / Structurally Validated / Installed”; supports filtering by category.
  • Operations: Click “Validate and Install” or “Install” to trigger the validation or installation flow. The task panel displays installation status and output in real time.
  • Star Display: Displays the actual number of GitHub stars. If a curated entry is missing a star count, it is backfilled via a backend endpoint.

Notes

  • Uninstallation: Uninstallation is not supported in version v0.1.
  • Installation Restrictions: Only Git references in owner/repo format are accepted; binary files or local paths are not accepted.
  • Restart Requirement: After a successful installation, restart dsh web for the plugin to take effect.
  • Cache Mechanism: The directory cache is refreshed every 2 hours.
  • Configuration Requirements: The plugin runs with the permissions of the current DSH process; inspect the source code and license before installation.

Conclusion

This plugin addresses the pain points of plugin management in the DSH Web environment. Through structural validation and security constraints, it ensures installation reliability. For more details, please refer to the project homepage.