Preface

The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” As the plugin ecosystem grows richer, manually maintaining dependencies, checking for updates, and managing enable/disable states through configuration files becomes cumbersome. dsh-plugin-mgr is a plugin management plugin. It adds a “Plugin Management” subpage to the DSH web interface, enabling card-based management of installed plugins and providing features for starting/stopping, uninstalling, version checking, and searching.

Core Features

This plugin implements its features using a Host/Client separated architecture and includes the following capabilities:

  • Card-based list and view switching: Displays installed plugins as cards, showing their name, version, running status, and start/stop toggle. Supports switching between single-column and double-column layouts, and automatically remembers user preferences.
  • Start/stop and uninstall management:
    • Start/stop: Enables or disables plugins by modifying the cordis.patch.yml configuration file. Changes take effect after approximately 1 second via Hot Module Replacement (HMR), and the state is preserved across restarts.
    • Uninstall: Supports one-click uninstallation with a secondary confirmation prompt. The uninstall flow first cleans up the start/stop configuration and then executes the dsh plugin remove command.
  • Details and search:
    • Details: Clicking a card expands its details, displaying the version number, installation source (npm/GitHub/local), repository URL, and plugin introduction.
    • Search: The toolbar provides a search box that supports case-insensitive filtering by name, description, or spec.
  • Update checking:
    • Only supports update checking for plugins from npm sources.
    • Automatically compares against the latest version in the npm registry (results cached for 5 minutes), and displays an “Updatable” badge on the card.
    • Supports one-click updates to the latest version. The update process does not overwrite existing start/stop states.
  • Runtime error display: Listens to the host’s fiber status events. If a plugin fails to load, the card displays a red “Failed to load” indicator, and the details page shows the specific error information. The failed state is automatically cleared after the plugin recovers.

Installation and Enabling

Before installation, make sure that DeepSeek Harness is installed in the host environment and that dsh web is running.

Use the official command to install the plugin:

dsh plugin --profile web add dsh-plugin-mgr

After installation, in the dsh web interface, go to “Settings” → “Plugins” tab, and click the “Plugin Management” subpage to view the list of installed plugins.

Implementation Details and Notes

  • Architecture design:
    • Host side: Responsible for registering API routes (list, start/stop, uninstall, update checking) and reading/writing the cordis.patch.yml configuration file.
    • Client side: Responsible for injecting the UI into the Plugins tab of the settings page, displaying the card list, search box, and details panel.
  • Security and limitations:
    • Host protection: Core infrastructure modules of the host cannot be started, stopped, or uninstalled by the plugin manager. The toggle and uninstall buttons for the plugin manager itself are disabled in the UI.
    • CSRF validation: All POST endpoints validate the CSRF middleware, and the request body size is limited to 64KB.
    • Update scope: Update checking only supports plugins from npm sources. Host modules and the plugin manager itself cannot be updated through this feature.
  • Stability and concurrency:
    • Write operations in the patch layer are serialized to prevent configuration corruption caused by concurrent interleaving.
    • Runtime error capture is implemented through cordis internal/status events, without relying on polling, allowing immediate detection of plugin failure and recovery states.

Ecosystem Background

The DeepSeek Harness plugin ecosystem is maintained by the community and has no official technical affiliation with DeepSeek or High-Flyer. Before using third-party plugins, be sure to review their source code and licenses.