Introduction¶
DeepSeek Harness (DSH) adopts the “everything is a plugin” philosophy. When an Agent extends its capabilities, it faces issues such as complex community plugin sources, floating versions, and difficult-to-control potential risks. dsh-agent-plugin-research is an agent-specific tool used to complete discovery, version pinning, risk checks, and user confirmation before installing DSH community plugins, and to provide post-installation verification and activation plans.
Basic Positioning¶
This is an agent-specific bridge for DSH plugin discovery, auditing, installation, and verification. It is maintained by Asteroid0449 and under the MIT license. It does not provide settings pages, a visual marketplace, client bundles, or Web routes; instead, it acts as a backend capability for the Agent to assist with plugin discovery, auditing, installation, and verification.
Core Features¶
The plugin provides seven fixed tools, always registered in a fixed order:
- Retrieval and Inspection: Search GitHub, npm, private indexes, or offline curated tables; inspect manifest, installation scripts, and
cordis.patch.ymlrisks. - Installation and Removal: Use pnpm to permanently install or remove dependencies and coordinate bundle manifests.
- Verification and Planning: Verify package identity, lockfiles, patches, and profile layers; detect capabilities currently visible to the Agent and generate activation steps.
- Manifest Management: List profile dependencies, runtime entry points, and ordered bundle layers.
Installation and Enablement¶
Before installation, make sure the environment meets the requirements: Node.js >= 22.19.0, DSH >= 0.1.0-rc.8.
Run the following command in the download directory to install:
dsh plugin --profile web add .\dsh-agent-plugin-research-0.5.1.tgz
If the repository source code is already on the local machine, you can first run the verification script:
.\verify-and-install.cmd
After installation, the plugin does not automatically invoke activation or restart tools; the Agent must perform follow-up actions based on the generated plan.
Typical Usage¶
Using the plugin involves two stages: “review” and “installation.”
-
Review stage: Before making any formal writes, first have the Agent search for and review a plugin suitable for DSH. Example prompt:
> Search for and review a plugin suitable for DSH. Do not install it yet. List its version identity, installation script, bundle patch risks, and the recommended activation method. -
Installation and confirmation stage: After confirming the report content is correct, run installation and request verification. Example prompt:
> Install the version pinned just now. Confirm with me before any permanent writes; after installation, verify the profile registration and provide an activation plan.
Security Boundaries and Notes¶
- Permissions and Confirmation: Installation and removal require explicit confirmation; if an approval channel exists, failed or unavailable approval will reject writes.
- Installation Restrictions: Installation accepts only exact npm versions, fixed GitHub commits, or local
file:paths withinallowedFileRoots. - Verification Scope:
verifyonly proves installation metadata consistency; it does not prove that runtime services, Web client, or original artifacts are working. - Runtime Environment: The plugin runs with the permissions of the current DSH process. Review the source code and license before deciding whether to install.
Activation Paths¶
Depending on the environment, the activation plan includes three paths:
* dsh-super-injector dev_* tools (development mode).
* User cordis.patch.yml (configuration mode).
* dsh-restart-resume (production mode).
The plugin only provides the plan; it does not wrap or silently call other tools.
Summary¶
dsh-agent-plugin-research is a secure and controllable Agent tool bridge. It helps Agents reduce the risks of introducing third-party plugins when extending DeepSeek Harness capabilities by enforcing review, version pinning, and explicit confirmation mechanisms.