DSH ecosystem is plugin-based at its core, but installing plugins directly carries risks: duplicate loaders can cause crashes, tool name conflicts can disable functionality, version mismatches can break the runtime environment, and a manual restart is required after installation. dsh-safe-install encapsulates the “install a plugin” operation into a standard workflow: first perform four-fold security checks, confirm there are no conflicts, take a snapshot, execute the installation, and finally automatically restart DSH.
Plugin Overview¶
dsh-safe-install is an automation tool maintained by goodaiaiai. It is integrated into the DSH process and avoids installation risks through an automated workflow. Its core value lies in converting manual troubleshooting and operations into reusable instructions, ensuring the stability of the plugin environment.
Core Capabilities¶
This plugin primarily provides the following capabilities:
- Four-fold security checks: Executed in parallel before installation, covering version compatibility, patch conflicts, tool name conflicts, and supply chain security.
- Blocking mechanism: Returns
blockorwarnbased on the check results.blockdirectly rejects the installation and explains the reason;warnonly indicates risks without blocking. - Snapshot and rollback: Automatically invokes
dsh-undo-savepointbefore installation to create a snapshot, allowing rollback at any time if the installation fails or the configuration is incorrect. - Automatic restart: Automatically restarts the DSH process after installation completes, ensuring the new plugin takes effect immediately.
- Status tracking: Records the most recent check, installation, and restart status, which can still be queried after restarting.
Installation¶
Install it via the official command line:
dsh plugin --profile web add github:goodaiaiai/dsh-safe-install#master
After installation, DSH must be restarted for the changes to take effect.
Typical Usage¶
The plugin registers three tools that can be invoked directly in a conversation.
- Security check
Run only the four-fold security checks without performing the actual installation.
safe_install_check { pkg: "dsh-startup-guard" }
- Safe installation
Execute the checks, install the plugin, and automatically restart DSH (defaultrestart: true).
safe_install { pkg: "dsh-better-sidebar", source: "github:omdsh-dev/DSH-better-sidebar" }
- Status query
Query the last check, installation, and restart status.
safe_install_status
Four-Fold Security Check Mechanism¶
The checks are divided into four dimensions, with the following criteria:
- Version compatibility: Checks whether the version requirements (
minor,patch,rc) for@deepseek-ai/*in a plugin’speerDependenciesare less than or equal to the current DSH version. - Patch conflicts: Checks whether
insert identries incordis.patch.ymlduplicate core reserved IDs (such asstorage) or IDs used by installed plugins. - Tool name conflicts: Checks whether the tool names registered by a plugin duplicate those of installed plugins or built-in tools.
- Supply chain: Checks whether an npm package has been published, whether maintenance is active (updated within 30 days), and whether the license is clearly defined.
Note: If the
sourceparameter is not provided, checks ② and ③ cannot be fully executed; onlywarnis returned. It is recommended to always provide the GitHub source.
Notes and Limitations¶
- Network and permissions: The plugin runs inside the DSH process.
dsh plugin addmay reportEPERMdue to permission issues under theworkspace-writesandbox and requiresdanger-full-access. Network requests includeNODE_TLS_REJECT_UNAUTHORIZED=0(used to address incomplete local CA chain issues) and retry logic (2 attempts). - Check dependencies: Checks ② and ③ depend on the GitHub source. If an npm package has not been downloaded, its patch and source code content cannot be read.
- Manifest refresh: The tool name manifest is a built-in snapshot plus a startup-time scan; after installing a new plugin, a restart is required to refresh the manifest.
- Runtime dependencies: This plugin only checks version and conflicts at installation time; it does not cover runtime dependency integrity for core modules such as
dsh-client-ui-slots(it is recommended to use it together withdsh-startup-guard).
The plugin reduces the complexity and risk of DSH plugin management through an automated workflow. If you need to roll back an accidental installation, you can use dsh-undo-savepoint.