DeepSeek Harness (DSH) uses a plugin-based architecture. This makes extending functionality highly flexible, but it also introduces risk: a poorly written plugin may throw an exception at startup, causing the entire Web UI to crash. dsh-plugin-guard is designed to address this. It uses an isolation mechanism to ensure that a failure in a single plugin does not bring down the entire system.
What It Is¶
dsh-plugin-guard is a security guard plugin for DSH. It provides a dedicated Plugin Guard tab in Settings → Plugins. The plugin monitors user-configured plugins, scans their integrity, and isolates them when corruption or anomalies are detected, ensuring the Web client can always start normally.
Core Features¶
- Scan and Isolation: Automatically validates all user-installed plugins. For plugins that cause crashes at startup, it isolates them and marks them as “corrupted” while keeping the Web client running.
- Plugin Control: Supports enabling, pausing, or uninstalling user plugins. These settings are persisted to the configuration file.
- Bilingual Interface: The interface supports English and Chinese and automatically follows DSH’s language setting.
- One-Click Self-Update: Checks for new versions via npm and provides an “Update now” button, allowing the plugin to update itself directly from the plugin interface.
- Standalone Repair Script: Provides
lib/profile-guard.js, which can be run before starting the Web client to repair a corrupted configuration file.
Installation and Enabling¶
Use the DSH CLI to install:
dsh plugin --profile web add dsh-plugin-guard
If you need to install it manually, edit <dsh-home>/profiles/web/package.json:
{
"dependencies": {
"dsh-plugin-guard": "^0.1.0"
},
"dsh": {
"profile": {
"bundles": ["dsh-plugin-guard"]
}
}
}
Then run pnpm install (or npm install) in that profile configuration directory, and finally restart the Web client.
Typical Usage¶
1. Update the plugin
Open Settings → Plugins → Plugin Guard, click the Update now button, wait for the installation to complete, and then restart the Web client.
2. Repair a corrupted configuration
If the Web client fails to start due to a corrupted plugin, you can run the guard script directly to repair it:
node <dsh-home>/profiles/web/node_modules/dsh-plugin-guard/lib/profile-guard.js
Notes¶
- Permissions and Scope: This plugin does not modify the DSH application installation directory; it only maintains user configuration files (such as
package.json,cordis.patch.yml). - Network Requests: It only sends read-only version check requests to the npm registry, without transmitting any data or performing telemetry.
- Effective Timing: Disabling or uninstalling this plugin requires restarting DSH to take effect.
Summary¶
dsh-plugin-guard adds a line of defense to the DSH ecosystem. Through its isolation mechanism and self-updating capability, it solves the pain point of a bad plugin bringing down the system. For developers who rely on a plugin-based architecture, it is an essential tool for ensuring the stability of the development environment.
- Catalog page: dsh-pluginGuard - SkillHub
- Source code: dsh-pluginGuard - GitHub