ouyangyipeng/dsh-marketplace

A safe, live plugin marketplace for DeepSeek Harness

dsh-marketplace projects GitHub's live topic:dsh-plugin community into a Settings -> Plugins -> Marketplace surface, keeping discovery, search, inspection, installation, updates and removal inside DeepSeek Harness. The host reads up to ten 100-item pages from GitHub Search into a cached catalog (with ETag) and the client searches names, owners, descriptions and topics locally and sorts by update time, stars or name. Installs first stage the candidate in an isolated temporary project without touching the user profile, and only a candidate with prebuilt entries, a valid bundle patch and contained real paths reaches the profile dependency step; dsh.profile.bundles is edited with atomic replacement, failed installs stay inactive and failed removals restore the previous manifest.

Plugin Markets & Managers ★ 3 updated 2026-09-12 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"

Requires a current DeepSeek Harness, Node.js ^22.19.0 || >=24.0.0, and pnpm on PATH. After installing, restart dsh web and open Settings -> Plugins -> Marketplace. Uninstall/update use the native command with id dsh-marketplace. DS-Harness Desktop bundles a verified offline Marketplace version (desktop-v0.2.0), so Desktop users need not install this plugin separately.

Compatibility

DeepSeek Harness Web profile; Node.js ^22.19.0 || >=24.0.0 and pnpm on PATH. The README's security section is explicit about the boundary: Marketplace stages and installs candidates but does not audit plugin logic or author identity and does not sandbox a plugin after installation.

Details

Recent updates

The README documents the staged-install pipeline (pnpm add --ignore-scripts, manifest/export/path checks, atomic profile edit, restart to apply), strict owner/repository coordinate parsing, and an explicit security-boundary table of what Marketplace does and does not promise.

FAQ

How do I install dsh-marketplace?
Run dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1" (Node ^22.19.0 or >=24.0.0 and pnpm required), restart dsh web, then open Settings -> Plugins -> Marketplace. DS-Harness Desktop bundles its own verified version.
Does installing a plugin through Marketplace sandbox it?
No. The README is explicit that Marketplace parses coordinates, stages and installs with pnpm add --ignore-scripts, and checks manifests and paths, but does not audit plugin logic or author identity and does not sandbox the plugin after installation.
What happens if an install fails?
Per the README the candidate is first staged in an isolated temporary project, dsh.profile.bundles is written atomically, failed installs stay inactive and failed removals restore the previous manifest.

Alternatives

AwesomeHou/dsh-plugin-marketplace · Scorp1o117/dsh-plugin-marketplace · 2768651338/dsh-plugin-manager

More plugins in Plugin Markets & Managers

Browse more in Plugin Markets & Managers

Guides for Plugin Markets & Managers plugins