DSH ecosystem is plugin-based at its core, but installing plugins directly carries risks: duplicate loaders can cause crashes, tool name conflicts can disable functionality, version mismatches can break the runtime environment, and a manual restart is required after installation. dsh-safe-install encapsulates the “install a plugin” operation into a standard workflow: first perform four-fold security checks, confirm there are no conflicts, take a snapshot, execute the installation, and finally automatically restart DSH.

Plugin Overview

dsh-safe-install is an automation tool maintained by goodaiaiai. It is integrated into the DSH process and avoids installation risks through an automated workflow. Its core value lies in converting manual troubleshooting and operations into reusable instructions, ensuring the stability of the plugin environment.

Core Capabilities

This plugin primarily provides the following capabilities:

  1. Four-fold security checks: Executed in parallel before installation, covering version compatibility, patch conflicts, tool name conflicts, and supply chain security.
  2. Blocking mechanism: Returns block or warn based on the check results. block directly rejects the installation and explains the reason; warn only indicates risks without blocking.
  3. Snapshot and rollback: Automatically invokes dsh-undo-savepoint before installation to create a snapshot, allowing rollback at any time if the installation fails or the configuration is incorrect.
  4. Automatic restart: Automatically restarts the DSH process after installation completes, ensuring the new plugin takes effect immediately.
  5. Status tracking: Records the most recent check, installation, and restart status, which can still be queried after restarting.

Installation

Install it via the official command line:

dsh plugin --profile web add github:goodaiaiai/dsh-safe-install#master

After installation, DSH must be restarted for the changes to take effect.

Typical Usage

The plugin registers three tools that can be invoked directly in a conversation.

  1. Security check
    Run only the four-fold security checks without performing the actual installation.
    safe_install_check { pkg: "dsh-startup-guard" }
  1. Safe installation
    Execute the checks, install the plugin, and automatically restart DSH (default restart: true).
    safe_install { pkg: "dsh-better-sidebar", source: "github:omdsh-dev/DSH-better-sidebar" }
  1. Status query
    Query the last check, installation, and restart status.
    safe_install_status

Four-Fold Security Check Mechanism

The checks are divided into four dimensions, with the following criteria:

  1. Version compatibility: Checks whether the version requirements (minor, patch, rc) for @deepseek-ai/* in a plugin’s peerDependencies are less than or equal to the current DSH version.
  2. Patch conflicts: Checks whether insert id entries in cordis.patch.yml duplicate core reserved IDs (such as storage) or IDs used by installed plugins.
  3. Tool name conflicts: Checks whether the tool names registered by a plugin duplicate those of installed plugins or built-in tools.
  4. Supply chain: Checks whether an npm package has been published, whether maintenance is active (updated within 30 days), and whether the license is clearly defined.

Note: If the source parameter is not provided, checks ② and ③ cannot be fully executed; only warn is returned. It is recommended to always provide the GitHub source.

Notes and Limitations

  • Network and permissions: The plugin runs inside the DSH process. dsh plugin add may report EPERM due to permission issues under the workspace-write sandbox and requires danger-full-access. Network requests include NODE_TLS_REJECT_UNAUTHORIZED=0 (used to address incomplete local CA chain issues) and retry logic (2 attempts).
  • Check dependencies: Checks ② and ③ depend on the GitHub source. If an npm package has not been downloaded, its patch and source code content cannot be read.
  • Manifest refresh: The tool name manifest is a built-in snapshot plus a startup-time scan; after installing a new plugin, a restart is required to refresh the manifest.
  • Runtime dependencies: This plugin only checks version and conflicts at installation time; it does not cover runtime dependency integrity for core modules such as dsh-client-ui-slots (it is recommended to use it together with dsh-startup-guard).

The plugin reduces the complexity and risk of DSH plugin management through an automated workflow. If you need to roll back an accidental installation, you can use dsh-undo-savepoint.