Preface

DeepSeek Harness adopts an “everything is a plugin” architecture, and its plugin ecosystem has expanded rapidly in a short time. This has also brought plugin conflicts, hidden failures, and the issue where plugins in Creator mode are lost after restart. dsh-plugin-guardian aims to address these operational pain points by providing diagnostics before plugin installation, cross-plugin conflict scanning, and the ability to convert temporary plugins into persistent assets.

Core Features

This plugin provides four core tools that cover the full lifecycle of a plugin, from diagnosis to deployment:

  1. plugin_doctor
    Performs a health check on a single plugin directory. It reads file contents and provides a diagnostic report with confidence levels (confirmed/inferred/unknown), used to evaluate whether the plugin configuration is complete and whether dependencies are compliant.

  2. plugin_profile_scan
    Scans the installed plugin set to detect cross-plugin tool name conflicts, duplicates, or version drift. This helps identify potential system crash risks before plugins are put into use.

  3. plugin_promote
    Promotes a plugin in Creator mode or a temporary state into a persistent, version-controllable asset. This process copies the plugin to a managed staging directory and generates a source address and hash marker.

  4. plugin_install
    A guided installation flow. By default, it operates in “audit-first” mode, performing safety checks before installation and executing the actual install command only after confirmation via approve=true.

Installation and Enablement

Install the plugin under the DeepSeek Harness Web Profile:

dsh plugin --profile web add github:Nico0713520/dsh-plugin-guardian

After installation, restart the Harness service to invoke the tools above in a session.

Typical Usage

The following are basic invocation examples for each tool:

# Diagnose a specified plugin directory
plugin_doctor target="/path/to/my-plugin"

# Scan for conflicts among all installed plugins under the current Profile
plugin_profile_scan

# Promote a temporary plugin to a persistent asset
plugin_promote source="/path/to/my-plugin"

# Audit-only installation (without actually executing)
plugin_install spec="npm:some-plugin"

# Execute installation after auditing passes
plugin_install spec="npm:some-plugin" approve=true

Applicable Scenarios and Notes

  • Intended audience: Harness administrators who need plugin governance, conflict resolution, or persistence for Creator-mode plugins.
  • Security:
    • plugin_doctor and plugin_profile_scan are read-only operations that do not trigger network requests, execute source code, or modify files.
    • plugin_promote only writes to a controlled staging directory ($DSH_HOME/.guardian-plugins) and does not directly modify your Live Profile by default unless explicitly specified via parameters.
  • Runtime environment: Requires Node.js >= 20 and DeepSeek Harness version 0.1.0-rc.x.

Summary

dsh-plugin-guardian provides a basic governance layer for the DeepSeek Harness plugin ecosystem. Through tiered-confidence diagnostics and strict read/write boundary control, it helps developers maintain system stability and controllability while the plugin ecosystem expands rapidly.

  • Plugin directory: https://www.skillhub.cn/plugins/Nico0713520/dsh-plugin-guardian
  • Source repository: https://github.com/Nico0713520/dsh-plugin-guardian