nanshan1995/DSH-Plugin-Market

Alternative plugin market for DSH: curated catalog plus live GitHub browsing, zh/en cross-language search, a fail-closed pre-install static security audit with an install-hook block, and per-plugin README viewing with garbled-encoding repair.

A plugin market inside DeepSeek Harness that browses, searches and one-click installs community plugins — with every install/update passing a static security audit gate first. It offers live community browse of the GitHub dsh-plugin topic (ranked by stars / latest, paginated) plus a personal My Favorites list, cross-language search (Chinese queries find English plugins and vice versa, via a built-in thesaurus plus real-time LLM translation through the host model), a pre-install audit of the exact published artifact (dynamic exec, credential access and install scripts are hard-blocked, with side-by-side "Install anyway" and "Cancel" when blocked), in-flight operations pinned to the top with live progress, update checks, one-click audited updates, uninstall with arm/confirm on the same button, hot mounting, log export and self-service pnpm setup.

Tools & Capabilities ★ 0 updated 2026-08-16
View on GitHub ↗

Install

dsh plugin --profile web add github:nanshan1995/DSH-Plugin-Market

README Option 1 (recommended): install from GitHub with the github: form. Option 2 is a local link for development (git clone then add the local path). Prerequisites: DeepSeek Harness (dsh web) running and pnpm available (the market detects and offers to install it); Windows needs 10 1803+ for the bundled bsdtar used by the audit step.

Compatibility

DSH web profile; cross-platform macOS / Windows / Linux with a per-platform toolchain auto-detected (fnm / Volta / Homebrew / scoop / %APPDATA%\npm; Windows uses tar.exe / curl.exe / cmd-compatible spawns). Network-adaptive: README and audit downloads auto-detect the local proxy (env vars → parallel probe of common local proxy ports → direct fallback).

Details

Recent updates

README details the in-market README viewer: HTML tables/images render, relative image links point to raw, language links switch the file in place, a ↻ button force-refreshes, and READMEs shipped double-encoded (UTF-8 mis-decoded as GB18030) are detected and restored with an "encoding repaired" badge. Installed rows resolve their repository from package.json (repository / GitHub homepage), the github: spec or a README scan, exposing the spec text and a Source button.

FAQ

How do I install DSH-Plugin-Market?
Run dsh plugin --profile web add github:nanshan1995/DSH-Plugin-Market (the README's recommended option), or add a local clone path for development. Requires DSH web running and pnpm available.
Is there a security check before installing a plugin?
Yes — every install/update passes a static security audit gate first. Dynamic exec, credential access and install scripts are hard-blocked; when blocked, the audit card offers "Install anyway" (forced download, at your own risk) and "Cancel" side by side.
Does search work across languages?
Yes — Chinese queries find English plugins and vice versa, using a built-in thesaurus plus real-time LLM translation through the host model.

More plugins in Tools & Capabilities

Browse more in Tools & Capabilities

Guides for Tools & Capabilities plugins