Introduction¶
DeepSeek Harness (DSH) adopts a plugin-based architecture, which requires developers to manage a large number of plugins. Existing plugin management approaches are relatively vague in identity identification and on/off control. dsh-workshop is a lightweight plugin management panel maintained by Zlyraz, aimed at solving problems such as unclear plugin origins, lack of intuitive switches, and insufficient risk control.
Installation and Enabling¶
Installing this plugin requires using the DSH plugin manager. Run the following command in a terminal:
dsh plugin --profile web add github:Zlyraz/dsh-workshop
After installation, restart the DSH Web interface, then go to “Settings” -> “Plugins” -> “Lightweight Plugin Switch” tab to use it.
Identity Determination¶
This plugin determines the origin of a plugin by analyzing the entries enumerated via ctx.loader.entries() together with pnpm-lock.yaml. The determination logic is as follows:
* Official built-in: Entries whose origin cannot be found in the lockfile are considered shipped with DSH.
* NPM package: The origin is an npm semantic version.
* GitHub repository: The origin is codeload.github.com (locked commit).
* Local development: The origin is file: (local directory).
* Scope warning: If a GitHub repository impersonates the @deepseek-ai/ scope (such as dsh-plugin-hub), it will be marked with a warning.
Voice-Style Switch¶
The voice-style switch does not involve uninstallation; it is implemented by modifying the configuration layer. Through the POST /api/workshop/v1/toggle endpoint, the plugin appends or removes configuration blocks in $DSH_HOME/profiles/<profile>/cordis.patch.yml (for example, - id: X / disabled: true).
After the modification, HMR automatically reconstructs within about 1-3 seconds, so there is no need to restart DSH. However, note that infrastructure entries (loader, webserver, ui, storage, etc., 44 patterns in total) and the switch itself are locked and cannot be disabled.
Risk Labels¶
The plugin includes a manually maintained risk-list.json manifest. Changes to this manifest take effect immediately without a restart. For unlisted third-party plugins, it displays “Unrated”; for official built-in plugins, it displays “Officially Maintained”.
Security Validation¶
When implementing security validation, the plugin applies the following restrictions:
* Routes are limited to loopback access.
* Requests must be same-origin and pass Origin validation.
* File write operations are processed in a serial queue and use temporary files with atomic replacement to prevent configuration corruption caused by concurrent writes.
Notes and Secondary Development¶
- Module ID constraint: The module id in the
client bundlemust equal the package name; otherwise, rendering exceptions may occur. - Property access: When using
IDENTITY_LABELorRISK_LABEL, use property access(L) => L.keyrather than function calls. - Permission risk: This plugin runs with the permissions of the current DSH process. Check the source code and license before installing it.
Conclusion¶
dsh-workshop provides plugin identity tracing and voice-style switch capabilities in a lightweight way, making it suitable for developers who need to manage plugins in a fine-grained manner within DSH.