When developing DeepSeek Harness (DSH) plugins, agents often need to invoke external command-line tools (such as gh, jq, ffmpeg). Directly concatenating Shell scripts in code for installation carries injection risks and is difficult to verify. dsh-cli-store provides a reviewed registry and installer specifically designed to manage these external CLI tools.

What Is It

dsh-cli-store is a DSH plugin maintained by Harzva, designed to solve installation and verification issues for external CLI tools. It does not replace the DSH plugin marketplace; instead, it serves as a registry that describes binary tools running outside DSH and integrates them into agents through DSH Bundles.

Core Features

After installation, the plugin registers the following tools:

  • dsh_cli_search: Search within the local registry.
  • dsh_cli_list: List all registry entries for the current platform.
  • dsh_cli_discover: Search public sources through adapters and save the results.
  • dsh_cli_saved: Read locally saved discovery results.
  • dsh_cli_install_discovered: Install saved entries that have been verified against their source.
  • dsh_cli_doctor: Check the version responses of registered CLIs.
  • dsh_cli_install: Show the installation plan and execute it.

Installation and Enabling

Installing the plugin requires DSH’s profile web mode:

dsh plugin --profile web add https://github.com/Harzva/dsh-cli-store/releases/latest/download/dsh-cli-store-0.3.0.tgz

Typical Usage

  • Search for tools:
  dsh-cli-store search workbench
  • List the registry:
  dsh-cli-store list --
  • Discover over the network and save:
  dsh-cli-store discover "image cli" --source github --limit 10 --save
  • View saved items:
  dsh-cli-store saved image --
  • Install discovered items:
  dsh-cli-store install-discovered homebrew:ffmpeg --confirm --no-dry-run
  • Diagnose a CLI:
  dsh-cli-store doctor gh
  • View the installation plan:
  dsh-cli-store plan install gh
  • Execute the installation:
  dsh-cli-store install gh --confirm --no-dry-run

Security and Limitations

The plugin adopts a security-first design:

  • Registry entries and installation parameters are reviewed data, not raw Shell fragments.
  • Child processes use shell: false, preventing arbitrary Shell string evaluation.
  • Executable installers are limited to package manager commands allowed by the code (such as brew install and winget install), while manual installers only provide documentation.
  • DSH defaults to dry-run mode; both confirm=true and dryRun=false must be set to perform write operations.
  • Doctor mode only invokes declared CLIs and their version parameters.
  • Discovery is read-only unless explicitly requested, and discovery results are treated as untrusted metadata and displayed only as data.

Suitable Scenarios and Cautions

It is suitable for DSH plugin developers who need to manage a large number of external CLI tools. Note that the plugin runs with the permissions of the current DSH process; review the source code and license before installation.

Summary

dsh-cli-store provides a controllable external tool management solution for the DSH ecosystem through strict permission control and validation mechanisms.

  • Project homepage: https://github.com/Harzva/dsh-cli-store
  • Plugin directory: https://www.skillhub.cn/plugins/Harzva/dsh-cli-store