Are DSH Plugins Safe? A Practical Guide

Published 2026-09-17 · dshpacks Research

Installing a DeepSeek Harness plugin means running someone else's code inside the harness you trust with your files, your sessions and your keys. This guide covers what an install actually executes, what a plugin can reach once it loads, what dshpacks verifies before a page goes live, and a five-minute check you can run yourself.

Short answer

A DSH plugin is not a theme file or a config snippet. It is code that the harness loads and runs as you. The ecosystem is young and mostly small: across the 2,961 plugins listed in this directory the median repository has 2 GitHub stars and 85% have fewer than ten. That is the same trust profile as any young open-source ecosystem — most of it is fine, a few entries are not worth the risk — and the difference is visible if you read the install line before you paste it.

Nothing in this guide is a security audit, and no plugin on this site has been executed by us. What follows is (a) how the install mechanics actually expose you, and (b) the checks we run — which you can run too.

What an install actually does

Across the 1,651 reviewed plugins, the published install commands fall into a handful of shapes. The counts below are a mechanical classification of the command string each README publishes, and the shapes are not equally exposed:

The practical takeaway: the same plugin can be a one-line package add or a build-from-source exercise, and those are very different amounts of exposure. Read which one you are pasting.

What a plugin can reach once it loads

Once loaded, a plugin runs inside the harness, in your session, with the same reach your session has: the working tree, files the harness can read, network access, and any credential the harness is holding. That is not a defect in DSH's design — every plugin architecture works this way, including the ones you already trust — but it sets the bar clearly: install a plugin the way you would run a script from a stranger, because that is effectively what you are doing.

How we review a plugin before it gets a page

What we do not do

Be clear about the limits of a directory like this one. dshpacks does not execute plugin code, does not run static analysis on it, and does not perform security audits. A runtime-test verdict here means the documentation, package metadata and published artefacts were checked — nothing more. Stars measure popularity, not safety: some of the most-starred plugins are also the most powerful, and power is exactly what you are trusting.

Check a plugin yourself in five minutes

  1. Read the install line first. Is it a package add, a git checkout, or a build from source? If it is a build step, you are running the code you compile — read it.
  2. Compare the owner on both sides. The GitHub owner and the npm package owner should be the same project. When they are not, find out why before you install.
  3. Look at what runs on install. Packages that define pre/post-install scripts, or that ship prebuilt binaries, do more than copy files.
  4. Keep experiments out of your main profile. The commands in this directory target several profiles (web, tui, demo, headless, default). Installing an unfamiliar plugin into a profile you do not use daily keeps it away from the one you do.
  5. Ask what it needs and why. A UI tweak that wants broad filesystem or network access is worth a second look; a plugin's request should match the job its page describes.

If you want to remove one

Installs are per profile, so removal is the inverse of the install. 140 of the reviewed entries document this form upstream:

dsh plugin --profile web remove <package-name>

If you added a plugin from a source path or a local checkout rather than a published package, remove it the same way you added it, using the same identifier. Restart the harness afterwards so the profile reloads without the plugin.

Where to go next

Related: Install guide · Submit a plugin for review

Where to go next

are dsh plugins safedsh plugin securitydeepseek harness plugin safety

Browse the directory by category