Foreword

DeepSeek Harness promotes the “everything is a plugin” philosophy, allowing developers to flexibly extend application capabilities. However, as the plugin ecosystem expands, the community has become filled with half-finished products, random forks, and various unverified projects. Finding usable plugins amid noisy search results can be time-consuming and may pose security risks.

dsh-plugin-market aims to provide a verified plugin catalog inside the DeepSeek Harness Web client. Through a localized verification mechanism and browsing interface, it helps users securely discover and install plugins without leaving the DSH interface.

Plugin Positioning

This is a plugin marketplace that runs inside the DSH Web client. It does not run as a standalone web service; instead, it is embedded directly in the DeepSeek Harness browser interface.

This plugin was developed by user 2160039878-cyber and is released under the MIT license. Its core design principle is “verification first”: built-in catalog entries are checked manually or by scripts to ensure basic installability.

Installation and Enablement

The installation process consists of two steps: first, add the plugin to DSH’s web configuration; then, start the web client.

  1. Run the following command to install the plugin:
dsh plugin --profile web add github:2160039878-cyber/dsh-plugin-market
  1. Start the DeepSeek Harness Web client:
dsh web
  1. Open http://127.0.0.1:3080/ in a browser, find the “Plugin Market” button in the top-right corner of the page, and open it.

Core Features

The plugin provides capabilities to browse, search, and verify plugins while strictly following security principles.

1. Verified Catalog Browsing

The plugin includes a localized verified catalog. After opening the panel, you can view the list of verified plugins without making any network requests. The catalog contains entries in categories such as marketplaces, managers, skins, workflows, runtimes, and developers.

2. Search and Discovery

  • Multilingual search: Supports Chinese and English search.
  • Chinese mapping: The plugin includes built-in Chinese search expansion. For example, searching Chinese terms corresponding to skins, marketplaces, sandboxes, sessions, or templates automatically maps to the corresponding English labels.
  • GitHub discovery: The local catalog is limited. Users can click the “Search GitHub” button to explicitly discover potential plugin sources through GitHub search.
  • Manual indexing: When search indexing is slow, users can manually paste an exact owner/repo value or a GitHub repository URL to trigger a query.

3. Information Display and Actions

  • Overview information: The list directly displays the Chinese summary, star count, programming language, last updated time, and description.
  • Installation command copy: For built-in verified entries, the plugin generates and displays an installation command that includes a specific Git commit hash, which can be copied and used directly.
  • Repository actions: You can open the matching repository directly on GitHub and check whether the repository conforms to DSH plugin specifications.

4. Security Mechanisms

  • No automatic remote installation: The plugin does not automatically install remote code.
  • No key access: It does not read the user’s DSH API keys or access the private GitHub API.
  • No hidden writes: It does not perform automatic writes to the user’s DSH configuration files.
  • Installability check: Before attempting installation, the plugin quickly checks package.json, dsh.bundle.patch, patch files, and the web client entry point to determine whether the repository looks like a real DSH plugin.

5. Performance and Stability

  • Local-first: The built-in available plugin list is fully provided by local data, preventing the panel from failing to open due to network issues.
  • Non-blocking design: The panel does not automatically search when opened, preventing error messages when api.github.com is blocked or rate-limited.
  • Version pinning: Built-in entries are pinned to specific Git commits to ensure version consistency.

Typical Usage

In practical use, the plugin mainly solves two problems: finding verified plugins and checking whether unfamiliar repositories on GitHub are suitable for installation.

  1. Find built-in plugins:
    Open the Plugin Market panel and browse the 12 built-in verified entries. If you need to install one, copy the installation command generated by the panel and run it.

  2. GitHub discovery and verification:
    Click the “Search GitHub” button, enter a keyword, or paste a repository URL directly. In the search results, the plugin indicates whether the repository looks like a real DSH plugin. For entries discovered through GitHub, they may be shown as installable, but they are not marked as locked to a commit.

Applicable Scenarios and Notes

This plugin is suitable for developers or advanced users who need to manage the plugin ecosystem in a DSH environment and seek stable plugin sources.

Notes:
- This plugin is only a browser-side helper tool, and it is rendered using public GitHub search results.
- It does not store any local data or Tokens.
- Although the built-in catalog is verified, it is recommended to review the source code and license before installing any plugin, especially those discovered through GitHub search.