Jinsong-Zhou/safe-find-dsh-plugins
A DSH plugin (skill) that finds plugins for your task across the entire GitHub dsh-plugin topic, with a security scan before anything gets installed. It pulls every public repository under the topic (skipping archives and forks), ranks them against your request, inspects the best few to work out how each is meant to be installed, and hands you a shortlist of at most three candidates. After you pick one it pins the candidate's exact commit, then runs a static security scan over that source — plugin code is never executed. Clean scan moves ahead; if risks turn up every finding is laid out and the decision is yours; high-risk results, failed scans, or a missing scanner never install. What ends up in your environment is always the exact commit that was scanned.
Install
cp -R skills/safe-find-dsh-plugins "$DSH_HOME/skills/"Skills-based install per README (English): copy the whole skills/safe-find-dsh-plugins/ directory into $DSH_HOME/skills/ (or <project-root>/.agents/skills/ for one project only). No other configuration needed. Forked from Nagi-ovo/dsh-find-plugins; security scanning powered by NVIDIA SkillSpector.
Compatibility
DeepSeek Harness (skills root). Works anywhere skills are loaded.
Details
- Repo: Jinsong-Zhou/safe-find-dsh-plugins
- Category: Other
- Stars: 3
- Version: GitHub source (skills bundle; no npm package)
- Last push: 2026-08-13
- First seen: 2026-08-13
Recent updates
GitHub dsh-plugin topic search + ranking; commit-pinned installs; static security scan via SkillSpector; 3-candidate shortlist.
FAQ
- Does it execute plugin code to scan it?
- No — the scan is static over the pinned source; plugin code is never executed.
- Can it skip the scan?
- Never — even when you name the plugin yourself, the exact commit that gets installed is always the one that was scanned.
- How do I install it?
- Copy skills/safe-find-dsh-plugins/ into $DSH_HOME/skills/ (or the project's .agents/skills/) — it just works, no other configuration.
Alternatives
akira399/dsh-plugin-publisher · 2768651338/dsh-plugin-manager · vlln/plugin-registry