ouyangyipeng/dsh-marketplace
A safe, live plugin marketplace for DeepSeek Harness
dsh-marketplace projects GitHub's live topic:dsh-plugin community into a Settings -> Plugins -> Marketplace surface, keeping discovery, search, inspection, installation, updates and removal inside DeepSeek Harness. The host reads up to ten 100-item pages from GitHub Search into a cached catalog (with ETag) and the client searches names, owners, descriptions and topics locally and sorts by update time, stars or name. Installs first stage the candidate in an isolated temporary project without touching the user profile, and only a candidate with prebuilt entries, a valid bundle patch and contained real paths reaches the profile dependency step; dsh.profile.bundles is edited with atomic replacement, failed installs stay inactive and failed removals restore the previous manifest.
Install
dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1"Requires a current DeepSeek Harness, Node.js ^22.19.0 || >=24.0.0, and pnpm on PATH. After installing, restart dsh web and open Settings -> Plugins -> Marketplace. Uninstall/update use the native command with id dsh-marketplace. DS-Harness Desktop bundles a verified offline Marketplace version (desktop-v0.2.0), so Desktop users need not install this plugin separately.
Compatibility
DeepSeek Harness Web profile; Node.js ^22.19.0 || >=24.0.0 and pnpm on PATH. The README's security section is explicit about the boundary: Marketplace stages and installs candidates but does not audit plugin logic or author identity and does not sandbox a plugin after installation.
Details
- Repo: ouyangyipeng/dsh-marketplace
- Category: Plugin Markets & Managers
- Stars: 3
- Version: git spec pinned to github:ouyangyipeng/dsh-marketplace#v0.1.1 (Desktop bundles desktop-v0.2.0)
- Last push: 2026-09-12
- First seen: 2026-08-14
Recent updates
The README documents the staged-install pipeline (pnpm add --ignore-scripts, manifest/export/path checks, atomic profile edit, restart to apply), strict owner/repository coordinate parsing, and an explicit security-boundary table of what Marketplace does and does not promise.
FAQ
- How do I install dsh-marketplace?
- Run dsh plugin --profile web add "github:ouyangyipeng/dsh-marketplace#v0.1.1" (Node ^22.19.0 or >=24.0.0 and pnpm required), restart dsh web, then open Settings -> Plugins -> Marketplace. DS-Harness Desktop bundles its own verified version.
- Does installing a plugin through Marketplace sandbox it?
- No. The README is explicit that Marketplace parses coordinates, stages and installs with pnpm add --ignore-scripts, and checks manifests and paths, but does not audit plugin logic or author identity and does not sandbox the plugin after installation.
- What happens if an install fails?
- Per the README the candidate is first staged in an isolated temporary project, dsh.profile.bundles is written atomically, failed installs stay inactive and failed removals restore the previous manifest.
Alternatives
AwesomeHou/dsh-plugin-marketplace · Scorp1o117/dsh-plugin-marketplace · 2768651338/dsh-plugin-manager