In the DeepSeek Harness (DSH) ecosystem, plugins are mainly divided into two types: one type gives the model new capabilities (such as tools and skills), while the other applies rules and guardrails (such as system prompt injection). Constraint-oriented plugins can ensure compliance, but they may also reduce task performance due to rule overload and even become limitations after model upgrades. The value of a plugin is not a fixed attribute, but a dual relationship between the plugin and the current model. dsh-plugin-judge aims to solve this problem by evaluating the compatibility between a plugin and a specific model.

This is a plugin-value judge tool. It is maintained by pengxuding. It provides pre-installation review (source-code static scanning + LLM judging), post-installation audit, and model-switch re-review reminders.

Core Features

  • Pre-Installation Review: Before installation, enter a repository address through a command or the settings panel. The plugin source code is statically scanned, and the LLM is used to determine whether it is worth installing.
  • Post-Installation Audit: Installed plugins are scanned and classified (capability-oriented, constraint-oriented, hybrid, etc.), a constraint risk score is calculated, and a report is generated in the settings panel.
  • Model-Switch Re-Review Reminder: Changes to the default model are monitored. If a plugin’s historical judgment depends on the old model, a reminder is displayed asking for re-audit.

Installation and Enablement

Before installing, ensure that the environment meets the dependency requirements (Node >= 18, and a dependency on @deepseek-ai/cordis ^4.0.1). The installation command is as follows:

dsh plugin --profile web add dsh-plugin-judge

After installation and restarting Harness, the features become active.

Typical Usage

  • Pre-Installation Review: Enter the following command in the conversation for a preliminary check:
    /plugin-audit github:some/repo
  • Post-Installation View: Go to the “Plugin Judge” page in the settings panel to view audit reports and history for all installed plugins.
  • Tool Invocation: Ask the model to directly call the judge_plugin tool for judgment.

Applicable Scenarios and Notes

  • Applicable Scenarios: Strictly manage the constraint risks introduced by DSH plugins and ensure that a plugin does not harm the model’s performance on the current task due to rule restrictions.
  • Note: The judgment results are advisory opinions generated based on heuristic rules and model judgment, and are not a formal security audit. Installing any plugin will run third-party code on your machine. Be sure to check the source code and license before installation.

Through this mechanism, developers can evaluate the benefits and risks before introducing a new plugin and re-review plugin impacts after model upgrades, thereby maintaining the flexibility and controllability of Harness. For plugin details and source code, visit: GitHub.