anjaymi
dsh-plugin-store
Native plugin store for DeepSeek Harness Web
- Stars
- 0
- Language
- JavaScript
- Created
- Aug 15, 2026
- Updated
- Aug 15, 2026
Introduction
dsh-plugin-store
An in-harness plugin store for the DeepSeek Harness (dsh) Web GUI (dsh web),
surfaced as a compact 插件市场 / Plugin Store tab under Settings → Plugins.
It delivers a curated catalog plus live GitHub discovery, and lets you structurally
verify and install a community plugin into the web profile without leaving the GUI.
What it does
- Curated catalog from the awesome-dsh-plugin ecosystem (bundled snapshot, offline-first) plus
live GitHub
topic:dsh-plugindiscovery (top 30, no forks). - Structural verification: a repo is only installable when its current root
package.jsondeclaresname,versionanddsh.bundle.patch. Catalog/snapshot inclusion is not verification — every entry loadsverified: nulland must pass live re-verification. On refresh, only the boundedtopic:dsh-pluginbatch is verified; curated entries are verified at install time. - Real GitHub star counts: stars shown are the real GitHub counts. Topic entries source
stargazers_count; for curated entries that shipnull, the Host backs them up from the Shields badge (GET /api/dsh-plugin-store?method=stars&repos=...) and the client merges the real count into the first 120 visible cards in batches of 40. There is no local star ledger, no fabricated zero, and no client-side "star" toggle. - Install with a background FIFO op: installs queue single-file (one live child at a time),
and re-fetches the repo's root manifest at the queue head to re-verify
dsh.bundleimmediately before the real profile is touched. If it fails, the profile is left untouched. - Restart hint after a successful install: the plugin layer loads on the next
dsh webrestart. - Same-origin + per-process token gate: all mutating POSTs must be same-origin and carry a
per-process random token issued once via
GET ?method=bootstrap. Body size is capped at 8 KB.
Install
From a terminal, point DSH at this package and add it to the web profile:
# from a git checkout of this repo
dsh plugin --profile web add github:anjaymi/dsh-plugin-store
or directly by the GitHub spec after pushing this repository:
dsh plugin --profile web add github:anjaymi/dsh-plugin-store
Then restart the Web GUI:
dsh web
The 插件市场 / Plugin Store tab appears under Settings → Plugins.
dshforwardsaddto pnpm in the profile directory and mounts the bundle automatically when the package declaresdsh.bundle.patch. If pnpm asks to build a git source, add the printed key underallowBuildsinprofiles/web/pnpm-workspace.yamland re-run.
Using the store
| Control | Effect |
|---|---|
| Search | filters by repo or description |
| 全部 / 精选 / 新发现 / 结构已验证 / 已安装 | filter tabs (All / Curated / Newly discovered / Structurally verified / Installed) |
| 分类 (category) | filter by category |
| ☆ (star count) | real GitHub star count — curated entries with null are back-filled from the Shields badge in batches of 40 (never a fabricated 0) |
| GitHub | open the repository |
| 校验并安装 / 安装 | verify-and-install (unverified) or install (verified); the Host performs the final gate |
| task panel | live status/output of the running/pending install op; kill or dismiss |
- A card labelled 校验并安装 means the entry is not yet structurally verified — install is
still allowed, and the Host will refuse it at the queue head if the live root manifest lacks
dsh.bundle. The button is not disabled: the Host is the authority. - Uninstalling is out of scope for v0.1.
Configuration
GITHUB_TOKEN(optional, recommended): set in the environment before launchingdsh webto raise the GitHub search rate limit and avoid 403s during刷新目录(Refresh).- Profile: installs always target the
webprofile ($DSH_HOME/profiles/web). - Cache: refreshed catalogs are cached for 2 hours (
catalog.jsonunder your DSH home); a failed refresh keeps the previous catalog rather than dropping it.
Security model
- The HTTP route binds over the existing loopback web server (
127.0.0.1);--host 0.0.0.0is blocked by DSH unlessDSH_PKG_ALLOW_LAN=1is explicitly set. - Same-origin: POSTs require
Originhost to equal the requestHost. - Per-process token:
GET ?method=bootstrapissues a random token; every mutating POST must send it in thex-dsh-plugin-store-tokenheader. Reads (list/stars) are safe without it. - Strict install spec: only
owner/repo(optionallyowner/repo#subpath) git specs are accepted — never a binary or local path. The store refuses its own package. - Registry authority: a repo must already be present in the current catalog to be installable.
- Head re-verification: install re-fetches the root manifest and requires
name/version/dsh.bundlebefore touching the profile. Nothing is ever written to the profile unless that gate passes. - Atomic writes for store-owned files: the store owns the on-disk catalog cache and the
pre-install profile backup; those go through
@deepseek-ai/dsh-atomic-write(writeFileAtomic/withFileLock). The real profilepackage.jsonis not written by the store — it is reconciled by the officialdsh pluginCLI which forwards to pnpm in the profile directory. The store never rewrites yourcordis.ymlor profile manifest directly. - No hardcoded install paths:
$DSH_HOMEis resolved via@deepseek-ai/dsh-home-paths(resolveDshHome); the CLI is located from the launcher entry (process.argv[1]+process.execArgv) or the deployment's ownbin, never from the client.
Development
npm install
npm test # node:test — see tests/*.test.mjs
npm run pack:check # npm pack --dry-run
Layout
lib/host.js # ESM Host: /api/dsh-plugin-store route, catalog, verify, install queue
lib/client.js # browser bundle: window.__ModuleLoader__.load({id, factory(require)})
data/registry.snapshot.json # bundled curated + discovery snapshot (offline-first)
tests/*.test.mjs # node:test suite
cordis.patch.yml # bundle patch mounting the store
PRODUCT.md # product register, users, personality, anti-goals, WCAG AA
DESIGN.md # actual DSH tokens + the 18/14/12/11 type scale, 36/32, 8px, 138, no shadow
The client is a hand-written window.__ModuleLoader__.load CommonJS factory (no bundler is
required); the Host composes it at /plugins/dsh-plugin-store/client.js. Its styling uses only
DSH CSS tokens and inline SVG icons — see DESIGN.md.
License
MIT