证据快照复核于 2026-08-22GitHub 数据核对日期: 2026-08-21
证据已验证Plugin Bundledsh-settings Profiledsh-client-runtime Profiledsh-client-ui Profile

dsh-market

用于浏览和管理 DeepSeek Harness 插件的可视化网页市场。

快速了解

它能做什么

用于浏览和管理 DeepSeek Harness 插件的可视化网页市场。

本站提供的是中文说明,不代表该项目或 Plugin 自身提供中文界面;语言支持请以上游文档为准。

使用场景
plugin-marketplaceplugin-managementweb-uiplugin-discovery
适配技术
deepseek-harnesscordisdsh-settingsdsh-plugins
兼容性

dsh-settings Profile, dsh-client-runtime Profile, dsh-client-ui Profile
@deepseek-ai/cordis ^4.0.1; @deepseek-ai/dsh-settings ^0.1.0-rc.7

可信度与状态

证据已验证
核对日期 2026/8/22 UTC 07:14

有代码证据的贡献

它为 DSH 增加什么

DSH 可视化插件市场

通过网页界面浏览、搜索、安装、更新、诊断和管理社区插件。

机制证据
插件生命周期管理

提供的源码描述了安装、更新、卸载、热启用/禁用、诊断和面向回滚的流程。

机制证据

选择前先看

dsh-market 是一个 DSH 插件 bundle,提供用于发现、安装、更新、禁用、诊断和移除社区插件的网页界面。提供的源码包含 Cordis bundle patch 和客户端注入声明。

适合谁

偏好可视化插件流程的 DeepSeek Harness 用户,以及运行本地网页 Harness 配置的团队。

常见任务

  • 浏览和搜索社区插件
  • 从批准来源安装或更新插件
  • 检查插件加载顺序和配置冲突

权限与数据

源码描述了本地配置、插件、文件系统和 loopback 重启集成;本次审核未执行应用。

权限
  • 确认管理操作后可能写入插件和配置文件
  • 可能访问本地插件和配置状态
数据处理
  • 源码说明导出的日志会被清理
  • 配置备份可能包含凭据
  • 实际运行时数据流未独立测试
外部服务
  • 可能通过 HTTPS 获取精选插件目录
  • 可能使用 npm 或 GitHub 作为插件分发来源
  • 可能连接同源本地服务
凭据
  • 受管理的 Harness 配置中可能存在凭据
  • 本次审核未提供或使用凭据

局限

  • 未执行安装和运行
  • 兼容性是源码声明,未经过运行时测试
  • fixture 包是私有测试证据,不是公开分发包

DSHub 已核对

  • Git 源码 commit 已固定
  • 主 bundle manifest 和 Cordis patch 结构通过检查
  • 已识别 MIT 许可证

DSHub 未核对

  • 安装成功
  • 运行时兼容性
  • 安全认证或性能声明

固定版本安装

安装 dsh-market

这个Plugin Bundle没有 DSH Plugin 安装操作,请根据源码文档使用真实交付方式。

访问源码项目

维护者编写的上游内容原文于 2026/8/22README.md 获取,正文和仓库相对媒体固定到 commit b9323cc85d01,内容哈希为 0ac3cb82f8b8。以下是未经 DSHub 翻译的上游原文,语言可能与当前页面不同;第三方托管的 badge 可能独立更新。
<p align="center"> <img src="assets/logo.svg" width="96" alt="dsh-market logo"> </p>

dsh-market

English | 中文

npm stars

dsh-market is independent of any particular client — it works in any host that speaks the standard DeepSeek Harness protocol. We're currently in discussions with anywhere-labs/deepseek-harness-desktop about future cooperation, and we'll share updates here as they happen. Use dsh-desktop or deepseek-harness-desktop — both ship with this plugin market built in — or another excellent third-party client.

The plugin market inside DeepSeek Harness. Open Settings → Plugin Market → browse, search, one-click install.

dsh-market

One-click themes: install, switch live, no restart.

Install

dsh plugin --profile web add dshmarket

Restart dsh web, then open Settings → Plugin Market.

Requires dsh web 0.1.0-rc.6 or newer. On an older host the market disables itself and says so in the browser console rather than rendering against primitives that are not there — if the Plugin Market entry never appears, that is usually why. Worth checking when a desktop build bundles its own dsh: it may be older than the one npm would give you (#139).

What you get

  • Browse & search the full community catalog (1550+ plugins, growing daily) — category filters, star counts, top/new sorting, bilingual descriptions that follow your UI language

  • Screenshots — AppStore-style screenshots, auto-carousel when there's more than one, click to preview full-size: author-curated shots show right on the card (zero extra requests); plugins without curated shots fall back to automatic README extraction once you open the install dialog. Images load from GitHub hosting only

  • Themes — a dedicated tab for community themes and skins: install → active immediately, switch with one click (themes are mutually exclusive, your choice survives restarts), uninstall to revert

  • One-click install — confirm the source, watch live progress; most plugins go live after a page refresh, no restart

  • Backup & restore — export your profile's plugin list and configuration as readable JSON, import it on another machine, store it on WebDAV with daily auto-backup, or sync through a private GitHub Gist; restores merge (plugins installed after the backup are kept), validate before writing, and roll back on failure

  • Updates — per-plugin update checks (npm version or pinned commit vs HEAD), one-click update, or update everything at once; the market updates itself the same way

  • Uninstall — two-step confirm; plugins installed this session are removed live

  • Hot disable / enable — toggles write - id: … + disabled: true|false into the profile's cordis.patch.yml (the official patch layer, mechanism ported from dsh-plugin-hub): DSH's HMR re-composes within ~1s, no restart, and the loader re-applies the choice on every boot; hand-edited patch rows show as badges, host-infrastructure plugins are protected from toggling, and a malformed patch file is never made worse

  • Restart when needed — changes that cannot hot-load show a one-click restart beside the pending-change banner; the action is restricted to same-origin loopback requests

  • Zero jargon — if a component is missing (pnpm), the market detects it and offers a one-click automatic setup

  • Log export — one click produces a sanitized plain-text log for bug reports (home paths and credential shapes are masked; nothing is ever sent anywhere). The market's version sits next to the page heading, so a screenshot of a problem already carries it

  • Settings card — on dsh 0.1.0-rc.7 and newer the market manages itself from Settings → Plugins → Plugin configuration, next to every other plugin: see the running version, pick a release channel (stable, or beta to try builds still being verified — the market only, never your other plugins; a third dev channel appears once developer mode is switched on, and carries builds published straight off a branch), update, or remove the market — with an opt-in cleanup that also drops the disable rows it wrote, so plugins it switched off start running again rather than staying off with no UI left to switch them back on

  • Diagnostics — the plugin load order and conflict surface, one page: bundle stack with official/community badges, duplicate loader entries, dependency version mismatches, multi-version core packages, overrides and invalid config entries. Plain-language terms, problem blocks highlighted, everything collapsible

  • Load order — drag community bundles into the order you want, or take the suggested one derived from the plugins' own before/after rules. Nothing is written until a trial composition passes, and the panel tells you what the new order would change (overrides, invalid or duplicate entries) before you apply it

  • AI fix — one click copies a diagnostics-driven fix prompt (errors/warnings/order conflicts + conservative scope instructions) to the clipboard; you paste it into a new conversation and decide whether to send

Speed

Installs prefer npm tarballs over full-repo GitHub downloads whenever a plugin publishes to npm (registry-verified against the repo to prevent name squatting). Registry installs are typically seconds; GitHub-only plugins depend on your connection to GitHub.

Security

  • Installs are restricted to sources listed in the curated awesome-dsh-plugin registry — anything else is rejected

  • Build scripts stay blocked by default (pnpm ≥10); allowing one is your explicit per-package choice

  • Terminal/CLI-surface plugins are flagged before you install them into the web profile

  • The install endpoint accepts same-origin POST only; the market never phones home

  • Backups can contain credentials from your profile config — the UI warns before export and upload; WebDAV sync is https-only, refuses private-network targets, and never stores your password in the browser

  • The restart endpoint additionally requires a direct loopback client (forwarded requests are rejected) and relaunches the exact DSH entry, arguments, environment, and working directory

  • One-click restart launches a detached replacement. When this host is systemd's own service process the button is hidden automatically — the market would otherwise kill the takeover process along with the unit's cgroup and the service would not come back. The pending-change notice stays visible and says so. Detection requires both a systemd marker AND being the unit's main process, because INVOCATION_ID is inherited by every descendant of a unit (an ordinary terminal included) and hiding the button for those would be the worse bug. pm2 and launchd are not detected, so those deployments need the explicit setting below. Either flip Allow restart off in Settings → Plugins → Plugin configuration, or write it into the profile patch — where it has to sit under config:, because the loader passes only that sub-object to a plugin and a top-level allowRestart: is silently ignored (#227 by @Fantasymax):

    - id: dsh-market
      name: dshmarket
      config:
        allowRestart: false   # NOT at the top level beside `name:`
    

    GET /dsh-market/status reports "restart": false once it has taken effect.

  • For terminal-attached launches, the detached replacement keeps running after the original terminal closes

  • Listing ≠ endorsement: plugins are third-party code, install sources you trust

Submit your plugin

This repo is the market app, not the catalog. The plugin list comes from the curated awesome-dsh-plugin registry — to get your plugin listed in the market, open a PR there (one entry in the list; the site and this market pick it up automatically, usually within a day). Please don't PR plugin entries against this repo.

Roadmap & feedback

  • Bugs go in issues — attaching the market's "Export log" makes diagnosis roughly ten times faster
  • Feature ideas go on the Roadmap. Issues are kept for things that are broken, so a proposal filed as an issue gets moved there and closed; the discussion stays where you wrote it either way
  • Every roadmap item welcomes community PRs — say so on the item before starting, so two people don't build it twice

Data source

Fetched live on every open from awesome-dsh-plugin.com/plugins.json — curated entries, npm mapping, and star counts refreshed daily by CI, with no stale cache behind it. A failure reports the actual reason and elapsed time, with a Retry button.

There is deliberately no bundled snapshot to fall back on: for a catalog that grows daily, a stale answer is not a degraded one but a wrong one — a plugin published this morning would read as "does not exist".

If that host is unreachable from your network, point the market at a mirror instead. Set DSHM_REGISTRY_URL in the environment dsh runs in, to anything serving the same plugins.json shape:

DSHM_REGISTRY_URL=https://your-mirror.example/plugins.json dsh web

Friends

DSH Desktop (dataelement)

dsh-desktop — a desktop app for DeepSeek Harness: run and manage a local Harness without installing Node.js yourself. Ships with this plugin market preset as the default. dshdesktop.com

DeepSeek Harness Desktop (hairyf)

deepseek-harness-desktop — a native desktop app for DeepSeek Harness built with Tauri (Rust + Web): one-click local install and launch with no Node.js setup required. On first run it offers to install this plugin market as a recommended preset.

DSH Get

DSH Get — a searchable web directory for discovering DeepSeek Harness plugins: category filters, bilingual descriptions, install commands and per-plugin detail pages. Its normalized catalog snapshot is public at bobby-sheng/dshget-data.

modlens

modlens — the first vision plugin for DeepSeek Harness: bolts visual understanding onto text-only models like DeepSeek and GLM. Paste an image, get structured JSON evidence back — OCR, layout, semantics. Available right in this market:

dsh plugin --profile web add @liustack/modlens

License

MIT · dshmarket.com

有意识地管理

安装与管理

前置条件与目标 Profile

目标 dsh-settings Profile, dsh-client-runtime Profile, dsh-client-ui Profile

交付方式 Git Bundle — dsh-market/dsh-market#b9323cc85d0148013384a5aca5215be1922eea36

验证、更新与移除

显示生命周期命令
验证
dsh plugin --profile dsh-settings list

兼容性与访问范围

source-declared @deepseek-ai/cordis ^4.0.1; @deepseek-ai/dsh-settings ^0.1.0-rc.7

检查兼容性证据

风险事实

runtime-verification

Runtime installation was not independently verified

证据
credential-data

Backups may contain profile credentials

证据
third-party-code

Listed plugins are third-party code

证据
证据与编辑审查Manifest、Bundle patch、分发与新鲜度

不可变证据

审查状态与源码活动

AI 已审查

Recommended for deterministic audit because immutable source and bundle structure pass; review credential and third-party-plugin cautions before use.

AI 审查于 2026/8/22 UTC 07:16GitHub 事实核对日期: 2026/8/22 UTC 07:16

自当前证据基线以来,没有记录到重要源码变化。

下一步

按 Plugin 安装流程操作

订阅重要变化: dsh-market