DeepSeek Harness (DSH) is a Profile-centric Agent runtime, with plugins published as npm packages. Managing the installation, activation, configuration conflicts, and version updates of these plugins requires a control plane. @dsh/plugin-manager provides this control plane. It is independent of the legacy component-hub and focuses on Profile transactions and real Loader validation.

Core Features

1. Plugin Inventory and Classification

The plugin manager reads Profile bundles and can distinguish plugin sources (official / community / unknown origin) as well as their current status (installed / enabled).

2. Conflict Engine

Built-in detection mechanisms covering 7 conflict categories:
* Explicit declarations
* Duplicate Service Providers
* Route conflicts
* Command conflicts
* Port conflicts
* Duplicate plugin IDs
* Missing dependencies
* Node version incompatibilities

3. Transaction Handling

For toggle / install / uninstall operations, the manager executes a standard transaction flow: create snapshot → validate → modify configuration. If validation fails, the system automatically rolls back the changes. This process does not rely on regex-based YAML matching.

4. Layered Validation

Validation is performed in three layers, from syntax checking to real execution:
* Syntax: Uses node --check to verify code syntax.
* Config: Uses dump-config to validate configuration.
* Loader: Starts a real DSH process to perform load validation.

5. Task Persistence

Job state is persisted to jobs.json, ensuring that the frontend can still query the progress of install, uninstall, or update tasks after a process restart.

6. Discovery Marketplace

Supports offline snapshot import and manual entry of candidate plugins, with a transaction-safe entry point for one-click installation.

Installation

Install directly from GitHub using pnpm:

pnpm add github:123twtd/dsh-plugin-manager

Typical Usage

Use the CLI to add a community plugin:

dsh plugin --profile web add @liustack/modlens

Notes

  • This plugin is independent of the legacy component-hub. It does not import code from the legacy project, nor does it treat the component marketplace UI as a manager.
  • Official core modules and core Services are not automatically disabled.
  • Official core packages are protected: @deepseek-ai/* cannot be updated through this interface.