Introduction

DeepSeek Harness (DSH) adopts a plugin-based architecture, which requires developers to manage a large number of plugins. Existing plugin management approaches are relatively vague in identity identification and on/off control. dsh-workshop is a lightweight plugin management panel maintained by Zlyraz, aimed at solving problems such as unclear plugin origins, lack of intuitive switches, and insufficient risk control.

Installation and Enabling

Installing this plugin requires using the DSH plugin manager. Run the following command in a terminal:

dsh plugin --profile web add github:Zlyraz/dsh-workshop

After installation, restart the DSH Web interface, then go to “Settings” -> “Plugins” -> “Lightweight Plugin Switch” tab to use it.

Identity Determination

This plugin determines the origin of a plugin by analyzing the entries enumerated via ctx.loader.entries() together with pnpm-lock.yaml. The determination logic is as follows:
* Official built-in: Entries whose origin cannot be found in the lockfile are considered shipped with DSH.
* NPM package: The origin is an npm semantic version.
* GitHub repository: The origin is codeload.github.com (locked commit).
* Local development: The origin is file: (local directory).
* Scope warning: If a GitHub repository impersonates the @deepseek-ai/ scope (such as dsh-plugin-hub), it will be marked with a warning.

Voice-Style Switch

The voice-style switch does not involve uninstallation; it is implemented by modifying the configuration layer. Through the POST /api/workshop/v1/toggle endpoint, the plugin appends or removes configuration blocks in $DSH_HOME/profiles/<profile>/cordis.patch.yml (for example, - id: X / disabled: true).

After the modification, HMR automatically reconstructs within about 1-3 seconds, so there is no need to restart DSH. However, note that infrastructure entries (loader, webserver, ui, storage, etc., 44 patterns in total) and the switch itself are locked and cannot be disabled.

Risk Labels

The plugin includes a manually maintained risk-list.json manifest. Changes to this manifest take effect immediately without a restart. For unlisted third-party plugins, it displays “Unrated”; for official built-in plugins, it displays “Officially Maintained”.

Security Validation

When implementing security validation, the plugin applies the following restrictions:
* Routes are limited to loopback access.
* Requests must be same-origin and pass Origin validation.
* File write operations are processed in a serial queue and use temporary files with atomic replacement to prevent configuration corruption caused by concurrent writes.

Notes and Secondary Development

  • Module ID constraint: The module id in the client bundle must equal the package name; otherwise, rendering exceptions may occur.
  • Property access: When using IDENTITY_LABEL or RISK_LABEL, use property access (L) => L.key rather than function calls.
  • Permission risk: This plugin runs with the permissions of the current DSH process. Check the source code and license before installing it.

Conclusion

dsh-workshop provides plugin identity tracing and voice-style switch capabilities in a lightweight way, making it suitable for developers who need to manage plugins in a fine-grained manner within DSH.