1. Confirm that it is actually a Plugin Bundle
- The listing says Plugin Bundle—not Skill, App, Integration, Library, or Resource.
- A version-pinned package and target Profile are visible before the action.
- The manifest, Bundle patch, registry version, immutable commit, and integrity value are available.
- Risk facts describe observable network, filesystem, credential, shell, native-build, or external-runtime behavior without presenting a security certification.
2. Inspect the target Profile before installing
Open Settings, choose Plugin Configuration for Profile-level controls, and confirm that you are changing the Profile you intend to recover later.
3. Install one pinned Bundle
Use the exact command on the artifact page. This real ModLens example is included to show the required shape; review its evidence page before running it. DSHub did not execute this third-party package while producing the guide.
npx -y @deepseek-ai/dsh plugin --profile web add @liustack/modlens@3.16.64. Verify the inventory before real work
List the Profile’s installed Plugins and then inspect the Plugin list in the Web Profile. Search for the package or the mounted Plugin name; those names may differ.
dsh plugin --profile web list5. Keep update and removal explicit
Read the new manifest and patch before updating. If verification fails, remove the new Bundle, restart the Profile if required, and confirm that the unwanted mounted entry is gone.
dsh plugin --profile web update @liustack/modlens
dsh plugin --profile web remove @liustack/modlensWhat Evidence-verified means
DSHub checked Bundle structure, immutable source, package distribution, lifecycle fields, and the editorial record without executing third-party code. It is not a malware scan, compatibility warranty, or safety certification.