Preface

The core design philosophy of DeepSeek Harness is “everything is a plugin.” During development, developers need to find available plugin tools from the community index. There is currently no native Web UI for browsing the community directory on dshplugin.org. The dsh-client-plugin-store plugin provides a standalone “Plugin Store” section in the settings page for browsing, searching, and installing community plugins.

What Is It

This is a community plugin store panel that allows users to access the dshplugin.org index directly from the DeepSeek Harness Web UI settings. It supports sorting by stars and provides copyable, commit-pinned installation commands.

Core Features

  • Browsing and Searching: Browse and search the dshplugin.org community index directly in the settings panel (containing 4000+ plugins).
  • Sorting: Supports sorting by star count.
  • Command Copying: Provides copyable, commit-pinned installation commands.
  • Standalone Section: Registers a standalone “Plugin Store” section in the settings navigation.
  • Direct Actions: Installs or uninstalls plugins directly through double-click confirmation within the panel.
  • Endpoint Protection: The installation endpoint includes three layers of protection (custom request headers, Origin same-origin validation, and a whitelist mechanism).

Installation

Run the following command to add the plugin:

dsh plugin --profile web add github:shiyi-0x7f/dsh-client-plugin-store

Usage

  1. After installation, restart dsh --profile web (or dsh-shell).
  2. Open the settings page; a standalone “Plugin Store” section will appear in the left navigation.
  3. Browse or search plugins in the panel, or click an installation command to copy it.
  4. Double-click an entry in the panel to confirm; this can directly install or uninstall a plugin (effective after restart).

Technical Details and Notes

  • Host Side: Registers a same-origin route /plugin-store/catalog through ctx.webServer to proxy the community catalog (the endpoint does not send CORS headers and cannot be accessed directly by browsers).
  • Caching and Configuration: Catalog data uses an in-memory cache with a duration of 1 hour; config.catalogUrl can be used to change the source address.
  • Browser Side: Registers settings.section through ctx.slots.
  • Style Compatibility: Uses --dsw-alias-* tokens, following any theme or skin.
  • Security Restrictions: Installation specifications only accept github:owner/repo#fullsha values defined in the catalog, which is a whitelist mechanism.
  • Permissions and Security: The plugin runs with the current dsh process privileges; check the source code and license before installation.