Introduction

The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” Building on this, the next directional step is to build toolchains that can “self-assemble.” The dsh-plugin-dynamic-assembler plugin allows agents to discover and load plugins at runtime based on natural language requirements, while controlling risk through static auditing and user confirmation mechanisms.

The following sections introduce the plugin’s core capabilities, installation and configuration, and typical usage.

Core Capabilities

The plugin provides a complete dynamic assembly toolchain, including the following key features:

  1. Runtime Discovery: Scans loaded plugins at runtime via ctx.registry, without relying on hard-coded lists.
  2. Official-First Policy: Prefers matching official @deepseek-ai/* plugins; third-party plugins are considered only when official plugins cannot satisfy the requirement.
  3. Third-Party Governance Policy: Configures unofficialPolicy (default ask) to determine how to handle third-party plugins. Supports ask (ask), allow (allow), or deny (deny).
  4. Built-In Static Security Audit: Performs static scanning before plugin loading, generates a score and level (green/yellow/red), and provides a basis for security decisions.

Installation and Enablement

After installing the plugin, it must be enabled in the configuration file.

  1. Install:
    npm i dsh-plugin-dynamic-assembler
  1. Configure:
    Add the following configuration to the profile’s cordis.patch.yml. New entries must be wrapped with - insert::
    - insert:
        - id: dynamic-assembler
          name: dsh-plugin-dynamic-assembler
          config:
            denyList: []                  # 不允许组装的能力名称关键词
            unofficialPolicy: ask         # ask | allow | deny
            pluginSources: []             # 第三方插件源(npm 名称或本地路径)
If you need to use a local plugin that is not available on npm, list its path or npm package name in `pluginSources`.

Tools and Usage

The plugin provides 8 core tools for discovering, planning, executing, and unloading plugins.

1. assemble_inspect (Audit)

Performs a static security audit of a plugin. It scans for dangerous patterns (such as eval, child_process) and checks metadata (license, repository, etc.).
* Parameters: plugin (plugin name or package name), github_repo (optional; used for GitHub Releases auditing).

2. assemble_plan (Planning)

Analyzes a natural language requirement, discovers matching plugin capabilities in ctx.registry, and generates an assembly plan (without actually loading).
* Parameters: requirement (natural language description of the requirement).

3. assemble_execute (Execution)

Loads plugins according to the plan. If sensitive operations or third-party plugins are involved, user confirmation is required.
* Parameters: names (list of plugin names), confirm (whether to confirm), allow_unofficial (whether to allow third-party plugins), force (force-load plugins with a red audit result).

4. assemble_unload (Unloading)

Unloads all plugins dynamically loaded by this plugin, for rollback or cleanup.

Typical Conversation Flow

  1. Requirement Planning:
    The model calls assemble_plan with the requirement. The system matches capabilities among loaded plugins and returns an assembly plan.
  2. User Confirmation:
    The model calls assemble_execute with the confirmed list of plugin names, the confirmation flag, and the allow-third-party-plugins flag.
  3. Rollback:
    When the current flow needs to be interrupted, call assemble_unload to release all dynamically loaded resources.

Applicable Scenarios and Notes

This plugin is suitable for developers who need to build “self-evolving” agents. When using it, note the following:

  • Permission Risk: Static audit is a risk signal, not a security guarantee. Once a plugin is loaded, it has full Node process permissions, and malicious code may evade scanning. Please install only plugins from trusted sources.
  • Environment Requirements: Requires Node.js version >= 22.
  • Sensitive Operations: Operations involving networking, filesystem, Shell, subagents, MCP, code execution, or credentials must be explicitly confirmed using the confirm_sensitive parameter.

Summary

dsh-plugin-dynamic-assembler provides DeepSeek Harness with a closed-loop capability from natural language requirements to dynamic plugin loading. Through its official-first policy and configurable third-party governance mechanisms, it delivers agent self-assembly while retaining necessary security controls.

Plugin documentation and source code: GitHub | Community Directory