The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When developing compliance-related skills, developers typically need to manually copy skill files into a local directory. The dsh-compliancehub plugin uses the standard ctx.skills mechanism to load skills directly from a remote JSON catalog, eliminating manual file operations.

Core Positioning

This plugin is a remote skill provider maintained by wwumit under the MIT license. It primarily addresses the problem of loading cross-border compliance skills remotely and provides standard list and get interfaces for DSH.

Installation

Install the plugin using npm:

npm install @wwumit/dsh-compliancehub

This installation command depends on peer dependencies: @deepseek-ai/cordis and @deepseek-ai/dsh-skill.

Enabling and Usage

Import and register the plugin in the DSH plugin entry file. The remote catalog URL must be specified:

import { Context } from '@deepseek-ai/cordis'
import * as skillHub from '@wwumit/dsh-compliancehub'

export function apply(ctx: Context) {
  ctx.plugin(skillHub, {
    catalogUrl: 'https://wwumit.github.io/skills-catalog/catalog-compliance.json'
  })
}

After loading, the DSH model session directory will include the skills provided by this provider, and the model can invoke them through the built-in skill tool.

Core Capabilities

  • Skill list (list): Retrieves and validates the skill list from the catalog, then exposes it to ctx.skills.
  • Skill retrieval (get): Fetches SKILL.md on demand from the repository associated with the skill.
  • Fault-tolerant semantics: If the catalog service is unavailable, the plugin retains the last valid state, preventing an empty list and ensuring service availability.

Skill Scope

The plugin provides 9 cross-border compliance skills, covering checks and safeguards in areas such as CCPA/GDPR/HIPAA/COPPA.

Known Limitations

  • Body-only fetch: get() currently only fetches the body of SKILL.md, and does not yet cache scripts or other resource files.
  • Catalog caching: list() re-fetches the catalog on every call; TTL caching is not yet implemented.
  • Auth: Private catalogs or signed URLs are not yet supported.