dsh-skills-manager
NPM-installable DSH Web plugin for safely loading and managing skills across DSH and common local Agents.
liushutan
@liushutan
⬇ 1
★ 0
main
安装
dsh plugin --profile web add github:liushutan/dsh-skills-manager
需要可复现安装时,可在仓库后追加 #commit 固定提交。
NPM-installable DSH Web plugin for safely loading and managing skills across DSH and common local Agents.
该插件未提供要点说明,请参考仓库 README。
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/liushutan/dsh-skills-manager |
| 许可证 | Apache-2.0 |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-09-02 |
| 收录日期 | 2026-09-19 |
| 分类 | 工具与能力 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
[图片: DSH Skills Manager] # DSH Skills Manager **Load and safely manage skills from DSH and common local Agents** [简体中文](README.zh-CN.md) · [Changelog](CHANGELOG.md) · [Apache-2.0](LICENSE) [](LICENSE) [](https://www.npmjs.com/package/@liushutan/dsh-skills-manager) [](https://www.npmjs.com/package/@liushutan/dsh-skills-manager) [](https://github.com/liushutan/dsh-skills-manager) [](https://nodejs.org/) > DSH Skills Manager is a community-maintained DeepSeek Harness (DSH) plugin, not an official DeepSeek AI product. ## Features - Discover and load user-level skills from `.agents`, Codex, Claude, Gemini, and OpenCode into DSH. - Persist external source and skill toggles under `$DSH_HOME/skills-manager/state.json` without rewriting shared source files. - Inspect Markdown bodies, frontmatter, load state, duplicate shadowing, and format diagnostics in a source-first UI. - Create a local DSH skill from Settings or conversation; conversational writes require user approval. - Move DSH-local skills to recoverable Trash, then restore or permanently delete them. - Import `.zip` archives, skill folders, or a single `SKILL.md` safely into `$DSH_HOME/skills`. ## Screenshots Browse by source or search in **Settings → Skills**. External Agent sources are loaded through a manager-owned provider while their files stay read-only:  Open any skill to inspect its source path, diagnostics, Markdown body, and parsed frontmatter:  Moving a DSH-local skill to Trash requires confirmation and remains recoverable until it is permanently deleted:  ## DSH product ecosystem This product can be installed independently or used through the desktop app or Web suite. They share the same DSH core but serve different ways of working: | Product | Relationship to this product | | --- | --- | | [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) | The host runtime that provides models, sessions, tools, and the plugin system | | [DSH Doubao Desktop](https://github.com/liushutan/dsh-codex-desktop) | A ready-to-install desktop product with this product and the other five feature products built in | | Six feature products | [Codex UI](https://github.com/liushutan/dsh-doubao-ui) · [IM Connect](https://github.com/liushutan/dsh-im-connect) · [Automation](https://github.com/liushutan/dsh-automation) · [Skills Manager](https://github.com/liushutan/dsh-skills-manager) · [Archive Manager](https://github.com/liushutan/dsh-archive-manager) · [Agency Agents](https://github.com/liushutan/dsh-agency-agents) | ## Prerequisites - A working DeepSeek Harness Web installation with `dsh` available in PowerShell. - Examples use the `web` profile; replace it with the target profile. - Source installation and development require Node.js 20+. npm installation does not require running `npm install` in an arbitrary directory. ## Installation `dsh plugin add` forwards to `pnpm add` in the profile directory. Without a version and official registry, a local mirror or minimum-release-age policy can leave you on an older build. ### Ask another agent to install it This plugin runs inside DeepSeek Harness Web. Copy one of the sentences below into DSH, Codex, or WorkBuddy and let that agent install it into your local `web` profile. From npm: ```text Install the latest DSH plugin @liushutan/dsh-skills-manager into my local web profile using the official npm registry: dsh plugin --profile web add @liushutan/dsh-skills-manager@latest --registry=https://registry.npmjs.org/. Then run dsh --profile web --dump-config, confirm skills-manager is mounted, and remind me to restart DSH Web and hard-refresh the browser. ``` From source: ```text Install the DSH plugin from source at https://github.com/liushutan/dsh-skills-manager: clone it, run npm install and npm test, then run dsh plugin --profile web add . from that directory. Do not copy lib by itself. Then run dsh --profile web --dump-config, confirm skills-manager is mounted, and remind me to restart DSH Web and hard-refresh the browser. ``` | Product | How to use it | | --- | --- | | DSH | Send one of the sentences above to the current session. | | Codex | Send one of the sentences above to Codex and let it install locally. | | WorkBuddy | Send one of the sentences above to WorkBuddy; for a source install you can also paste `https://github.com/liushutan/dsh-skills-manager`. | Codex and WorkBuddy only install the plugin. After that, open DSH Web and use **Settings → Skills**. You can also run the same npm command yourself: ```powershell dsh plugin --profile web add @liushutan/dsh-skills-manager@latest --registry=https://registry.npmjs.org/ ``` If `dsh` is not on PATH, replace the leading `dsh` with `npx --yes @deepseek-ai/dsh`. ### Install the latest package from the official npm registry Run this from any PowerShell directory: ```powershell [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 $OutputEncoding = [System.Text.Encoding]::UTF8 dsh plugin --profile web add @liushutan/dsh-skills-manager@latest --registry=https://registry.npmjs.org/ dsh --profile web --dump-config ``` To pin a release, replace `@latest` with a version such as `@0.1.25`. The configuration output should contain `skills-manager`. Restart DSH Web and hard-refresh the browser. Do not copy client files manually: `dsh plugin add` also applies `cordis.patch.yml`. ### Install from source Use this for debugging or unpublished changes. The cloned directory becomes the plugin source path: ```powershell [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 $OutputEncoding = [System.Text.Encoding]::UTF8 Set-Location D:\Repository\deepseek-harness-plugin git clone https://github.com/liushutan/dsh-skills-manager.git Set-Location .\dsh-skills-manager npm install npm test dsh plugin --profile web add . dsh --profile web --dump-config ``` Restart DSH Web and hard-refresh the browser. `dsh plugin ... add .` reads the package metadata and `cordis.patch.yml`; do not install by copying `lib` directly. ## Usage Open **Settings → Skills**, then use the panel as follows: | Goal | Action | Scope | | --- | --- | --- | | Search or filter | Narrow by source, name, or description. | All sources | | Inspect details | Review body, frontmatter, path, format diagnostics, and duplicate shadowing. | All sources | | Enable or disable | DSH skills update their own invocation policy; external skills update manager-local state only. | All sources | | Create or import | Create in Settings, or import `.zip`, a folder containing `SKILL.md`, or one `SKILL.md`. | `$DSH_HOME/skills` | | Create from conversation | Let an Agent call `create_skill`; DSH asks for approval before writing. | `$DSH_HOME/skills` | | Delete and recover | Move to Trash, restore, or permanently delete in a second step. | DSH-local skills | > Toggling a shared source never changes its files; only DSH-local skills can move to Trash. Escape closes only the frontmost upload or confirmation dialog and leaves Settings open. ## Permissions and safety limits | Directory | View/load | Enable or disable | Create/import | Delete | | --- | --- | --- | --- | --- | | `$DSH_HOME\skills` | Yes | Updates local invocation policy | Yes | Moves to Trash | | `$DSH_AGENTS_HOME\skills` | Yes | Manager state only | No | No | | `~/.codex/skills`, `~/.claude/skills`, `~/.gemini/skills`, `~/.config/opencode/skills` | Yes | Manager state only | No | No | - Enable, disable, and delete accept only one ordinary skill-name path segment. - Replacements copy to a temporary sibling path first and keep the original until that succeeds. - Every endpoint, including GET `/state`, accepts only a loopback `Host` or a canonical `host[:port]` that the DSH Web runtime already trusts through its LAN bind and `--trusted-host`; unknown hosts still receive 403. - Browser requests must also carry a same-origin `Origin` when present and must not be marked cross-site; write endpoints continue to require JSON and the DSH client request marker. - Import accepts the local path selected by the user. The Host trust fence prevents DNS rebinding but is not authentication; reverse-proxy and LAN deployments still need authentication, a VPN, or network access controls. ## Secondary development This repository has no `src` directory. `lib` is directly maintained runtime source, which is its current layout rather than the recommended layout for new plugins. New plugins should prefer `src` built to `lib`. - [lib\index.js](lib/index.js): host service and local skill file operations. - [lib\client.js](lib/client.js): Settings page, upload, and confirmation interactions. - `test\core-test.mjs`: file-operation, permission, and import boundary tests. - `test\locale-test.mjs`: UI locale tests. After changing the runtime source, test, inspect package contents, and install from the local directory: ```powershell [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 $OutputEncoding = [System.Text.Encoding]::UTF8 npm test npm run pack:check dsh plugin --profile web add . ``` Preserve path validation, temporary-copy replacement, and shared-skill read-only behavior when changing file-mutation code. ## Validation ```powershell [Console]::OutputEncoding = [System.Text.Encoding]::UTF8 $OutputEncoding = [System.Text.Encoding]::UTF8 npm test npm run pack:check ``` `prepublishOnly` runs the core tests before publishing. ## Documentation and license Project status, usage boundaries, architecture, and iteration records begin at the [documentation entry point](docs/00-交接入口/00-阅读导航.md). The detailed operational guide is `docs\02-产品与业务\01-使用说明.md`. Licensed under [Apache License 2.0](LICENSE).
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。