Introduction

The plugin ecosystem for DeepSeek Harness (DSH) is expanding rapidly. Finding, verifying, and installing third-party plugins in the current work session usually requires switching context or relying on external directories. The DSH Get plugin provides direct access to a public directory inside the DSH interface, supports offline search and installation auditing, and centralizes the plugin management workflow.

Plugin Positioning

This is a community plugin independently maintained by bobby-sheng and is not an official DeepSeek component. It provides plugin discovery and installation capabilities through the DSH Get directory, and is compatible with DSH 0.1.0-rc.5 or later, as well as Node.js 22.19+ or 24+ environments.

Installation and Activation

Run the following command in the terminal to install the plugin. A DSH restart is required after installation.

dsh plugin --profile web add -w github:bobby-sheng/dshget-plugin

Core Features

The plugin provides a command-line interface and agent tools, covering full-lifecycle plugin management.

  1. Search plugins: Supports discovery by name, owner, category, tags, description, and source.
  2. Check plugin information: Use the info command to retrieve detailed information about a target plugin.
  3. Install plugins: Use the install command to perform installation. The installation process generates six audit evidence items and writes them to a local private record.
  4. Update the snapshot: Run the update command to fetch and validate the latest directory snapshot from the remote.
  5. View status: Use the status command to report the current snapshot state and cache validity.
  6. Offline search: The plugin includes a built-in directory snapshot, so it remains usable without network access or when the website is unavailable.
  7. Agent tools: Provides read-only dshget_search and dshget_plugin_info tools for Agent use.

Typical Usage

/dshget search memory recall
/dshget info volcengine/OpenViking#examples/dsh-memory-plugin
/dshget install example/dsh-plugin
/dshget update
/dshget status

Security and Audit

  1. Installation control: Installation operations are limited to human commands (/dshget install). Agent tools provide only retrieval and information queries, and do not include automatic installation capabilities.
  2. Shell injection protection: The plugin does not execute directory commands through the shell; it allows only secure npm packages or GitHub specifications, and rejects local paths and arbitrary URLs.
  3. Audit evidence: After a successful installation, six reports are output (including package name/version, lifecycle scripts, configuration changes, removal command, etc.), and a local audit record is generated.
  4. Permissions and maintenance: Loaded host plugins inherit the permissions of the dsh process. Before installing any third-party plugin, be sure to review its source code, license, and maintenance status. Inclusion in the directory does not equate to a security review.

Configuration

You can override configuration items in cordis.patch.yml to adjust behavior:

- id: dshget-plugin
  config:
    profile: web
    maxResults: 10
    cacheTtlHours: 24
    allowInstall: true

Summary

The DSH Get plugin integrates external directories into DSH, solving the context-switching problem for plugin discovery and installation. Through built-in snapshots and audit mechanisms, it provides basic assurance for offline use and operational transparency.

  • GitHub repository: https://github.com/bobby-sheng/dshget-plugin
  • Directory page: https://www.skillhub.cn/plugins/bobby-sheng/dshget-plugin