The DSH plugin architecture allows users to extend functionality through the Web UI. Skills are typically stored in the ~/.dsh/skills directory. Manually searching for skill tarballs on GitHub and downloading them into the installation directory can be cumbersome. The dsh-skill-market plugin integrates a “Skill Market” into DSH’s Web settings page, providing search and one-click installation capabilities.
Plugin Introduction¶
This plugin is maintained by user QQ-M and is designed to simplify the process of acquiring skills. It integrates the Skill Market into the Web UI settings page, allowing users to directly search for GitHub repositories in the browser and install skills with one click into the model-readable root directory based on the repository structure.
Core Features¶
- GitHub Search: Prioritizes repositories with the
dsh-skilltopic, while also supporting keyword search. - Repository Layout Check: Automatically identifies the repository structure. If
SKILL.mdexists in the root directory, it is treated as a single skill; ifskills/<name>/SKILL.mdorskills/<name>.mdexists, it is identified as multiple skills. - One-Click Installation: Downloads a tarball by calling the GitHub codeload endpoint, then extracts it and copies the skill files to the configured installation directory (default:
~/.dsh/skills). - Skill Management: Provides a list of installed skills and supports uninstallation. During uninstallation, skill files are moved to a
.trash-*directory for easy recovery. - Security Protection: Applies same-origin POST protection to write operations (install/uninstall).
Installation and Enabling¶
Install it using the official plugin command:
dsh plugin --profile web add "github:QQ-M/dsh-skill-market"
After installation, restart the Web server (dsh web) so the plugin can load the browser-side settings entry.
Configuration¶
The plugin can be configured via cordis.patch.yml. The default configuration is as follows:
| Configuration Item | Default Value | Description |
|---|---|---|
installDir |
~/.dsh/skills |
Installation directory for skills |
githubToken |
'' |
GitHub token string |
githubTokenFile |
'' |
File path containing the GitHub token |
searchLimit |
20 |
Maximum number of search results |
If no token is configured, the plugin reads the GITHUB_TOKEN environment variable. Anonymous search is limited to about 10 requests/minute, so it is recommended to configure a token for high-frequency searches.
API Endpoints¶
All endpoints are mounted under the /skill-market/api/ path and return JSON-formatted data:
GET /api/search?q=<query>: Search skillsGET /api/repo?owner=&repo=: Check repository detailsPOST /api/install { owner, repo, ref? }: Install a skillGET /api/installed: View the list of installed skillsPOST /api/uninstall { name }: Uninstall a skill
Technical Architecture¶
The plugin consists of two parts:
- Host Half (
index.js): Runs on the server side, provides the/skill-market/api/*routes, and handles GitHub interaction, file download, extraction, and installation logic. - Client Half (
client.js): Runs in the browser. It is a__ModuleLoader__bundle that requires no build step and is responsible for injecting the “Skill Market” tab into the DSH settings page.
In terms of dependencies, the Host only depends on Node.js built-in modules and @deepseek-ai/schemastery; the Client depends on react.
Notes¶
- Permissions and Security: The plugin runs with the permissions of the current DSH process. Please review the source code and license before installing.
- Community Ecosystem: This plugin is a community catalog project and has no official affiliation with DeepSeek or High-Flyer.