DeepSeek Harness (DSH) uses a plugin-based architecture. This makes extending functionality highly flexible, but it also introduces risk: a poorly written plugin may throw an exception at startup, causing the entire Web UI to crash. dsh-plugin-guard is designed to address this. It uses an isolation mechanism to ensure that a failure in a single plugin does not bring down the entire system.

What It Is

dsh-plugin-guard is a security guard plugin for DSH. It provides a dedicated Plugin Guard tab in Settings → Plugins. The plugin monitors user-configured plugins, scans their integrity, and isolates them when corruption or anomalies are detected, ensuring the Web client can always start normally.

Core Features

  • Scan and Isolation: Automatically validates all user-installed plugins. For plugins that cause crashes at startup, it isolates them and marks them as “corrupted” while keeping the Web client running.
  • Plugin Control: Supports enabling, pausing, or uninstalling user plugins. These settings are persisted to the configuration file.
  • Bilingual Interface: The interface supports English and Chinese and automatically follows DSH’s language setting.
  • One-Click Self-Update: Checks for new versions via npm and provides an “Update now” button, allowing the plugin to update itself directly from the plugin interface.
  • Standalone Repair Script: Provides lib/profile-guard.js, which can be run before starting the Web client to repair a corrupted configuration file.

Installation and Enabling

Use the DSH CLI to install:

dsh plugin --profile web add dsh-plugin-guard

If you need to install it manually, edit <dsh-home>/profiles/web/package.json:

{
  "dependencies": {
    "dsh-plugin-guard": "^0.1.0"
  },
  "dsh": {
    "profile": {
      "bundles": ["dsh-plugin-guard"]
    }
  }
}

Then run pnpm install (or npm install) in that profile configuration directory, and finally restart the Web client.

Typical Usage

1. Update the plugin
Open Settings → Plugins → Plugin Guard, click the Update now button, wait for the installation to complete, and then restart the Web client.

2. Repair a corrupted configuration
If the Web client fails to start due to a corrupted plugin, you can run the guard script directly to repair it:

node <dsh-home>/profiles/web/node_modules/dsh-plugin-guard/lib/profile-guard.js

Notes

  • Permissions and Scope: This plugin does not modify the DSH application installation directory; it only maintains user configuration files (such as package.json, cordis.patch.yml).
  • Network Requests: It only sends read-only version check requests to the npm registry, without transmitting any data or performing telemetry.
  • Effective Timing: Disabling or uninstalling this plugin requires restarting DSH to take effect.

Summary

dsh-plugin-guard adds a line of defense to the DSH ecosystem. Through its isolation mechanism and self-updating capability, it solves the pain point of a bad plugin bringing down the system. For developers who rely on a plugin-based architecture, it is an essential tool for ensuring the stability of the development environment.