Definitions first
- Harness: the official runtime and ecosystem core.
- Plugin Bundle: a distributable artifact whose manifest declares a parseable DSH Bundle patch.
- Cordis Plugin: a runtime function, class, or apply object mounted by a Loader row; one Bundle may mount several.
- Skill or Preset: reusable behavior or agent composition that can be delivered by a Bundle without becoming the Bundle itself.
- Integration, App, Library, Resource: useful ecosystem artifacts without a presumed native Plugin install.
How Plugin labels work
- Use case describes the user job: one primary task and up to three secondary tasks.
- Adds to DSH describes code-evidenced contributions such as Model Tools, Web UI, Skills, Agent Presets, or a Terminal UI. A Bundle can have several.
- Works with records external systems, protocols, file formats, or technologies.
- Compatibility records the Profile and Harness baseline.
- Trust & status records qualification, evidence freshness, and source availability without claiming safety.
DSHub does not use a single Plugin type because one Bundle can contribute to several extension surfaces. AI may normalize user scenarios and technology names, but mechanism labels require manifest, patch, export, or source-registration evidence.
Plugin publication gate
- Valid
package.json#dsh.bundle.patch. - The referenced patch exists and parses as data.
- Evidence is fixed to a 40-character source commit.
- An npm tarball or Git commit distribution can be matched.
- Commands are generated from an allowed DSH CLI form, version-pinned, and contain no shell chaining or redirection.
- A recorded review checks purpose, Profile, compatibility, limitations, verification, update, removal, and the evidence behind published contribution labels.
What Evidence-verified means
The structure, distribution, immutable evidence, and review record were checked without running third-party code. It is not a security certification, malware scan, compatibility warranty, or promise that the code will work in every environment.
Failure and freshness policy
Daily discovery and enrichment write only after a successful run. Rate limits, npm timeouts, empty searches, or partial generation preserve the last successful snapshot. Automated publication remains off until AI review confidence, audit, and failure handling are defined.
Public data
Pages, Registry v1, RSS, and sitemap are generated from the same reviewed snapshot. The Registry index publishes SHA-256 digests so downstream users can detect mismatches.