Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
工具与能力 #cli#cloudflare-workers#deepseek-harness#developer-tools#dsh-plugin#plugin-registry

dsh-plugin-hub

DSH tools for planning and applying reproducible Plugin Hub Profiles through the local dsh-hub CLI

pax-beehive @pax-beehive ⬇ 1 ★ 0 main

安装

dsh plugin --profile web add github:pax-beehive/dsh-plugin-hub
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

DSH tools for planning and applying reproducible Plugin Hub Profiles through the local dsh-hub CLI

该插件未提供要点说明,请参考仓库 README。

clicloudflare-workersdeepseek-harnessdeveloper-toolsdsh-pluginplugin-registry
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/pax-beehive/dsh-plugin-hub
许可证未标注(见仓库)
主要语言main
下载量1
GitHub 星标0
最近推送2026-08-22
收录日期2026-09-19
分类工具与能力

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# DSH Plugin Hub

Community registry, publisher console, and CLI for versioned DeepSeek Harness
plugins and profiles. The project is independent and unofficial.

[Visit DSH Plugin Hub](https://dshpluginhub.ai) ·
[Browse Plugins](https://dshpluginhub.ai/plugins) ·
[Explore Profiles](https://dshpluginhub.ai/profiles) ·
[Install the CLI](https://www.npmjs.com/package/@dsh-plugin-hub/cli)

DSH Plugin Hub lets users discover DSH plugins, share complete version-locked
Profiles, apply them through the `dsh-hub` CLI, and roll back to a recoverable
local revision. Start on [dshpluginhub.ai](https://dshpluginhub.ai).

## Install

Use the CLI directly:

```bash
npm install --global @dsh-plugin-hub/cli
dsh-hub --help
```

Or add the Hub tools to a DSH Profile:

```bash
dsh plugin --profile web add @dsh-plugin-hub/dsh-plugin
```

## What is implemented

- Public plugin search, detail pages, screenshots, compatibility and exact install specs
- Editable Profile Drafts and immutable, content-addressed Profile Releases
- JSON Registry API for packages, versions and profiles
- `dsh-hub` CLI for capture, share, exact apply, portable import and rollback
- DSH plugin tools and an agent Skill for confirmed plan/apply automation
- WorkOS AuthKit publisher accounts
- Automatic npm discovery, manifest validation and version-history sync
- Public one-time package submission and signed-in immediate sync
- Optional GitHub App repository claim and listing management
- Immutable published versions; listing copy may be refreshed independently
- Vinext SSR/RSC web shell on Cloudflare Workers
- Locale-aware public HTML and Hub API edge caching
- Same-origin cached Gravatar plugin icons
- Go Hub backend on Cloud Run with PostgreSQL persistence

## Workspace

```text
app/                 vinext / Next.js routes and publisher UI
components/          shared server and client UI modules
lib/                 Hub adapters, auth, i18n, SEO and edge policy
packages/schemas/    shared Zod wire and manifest schemas
packages/registry/   version and profile-order resolution
packages/cli/        dsh-hub command-line client
examples/             copyable, schema-tested starter bundles
```

The web shell stays on vinext so it deploys as a Cloudflare Worker. Portable
registry logic lives in workspace packages and has no Cloudflare dependency.
See [`docs/adr/0001-retain-vinext-cloudflare-worker.md`](docs/adr/0001-retain-vinext-cloudflare-worker.md).
The current runtime map and ownership rules live in
[`docs/architecture.md`](docs/architecture.md).

## Local development

Requirements: Node.js `>=22.13.0` and pnpm `10.33.0`.

```bash
pnpm install
cp .env.example .env
pnpm dev
```

Run all gates:

```bash
pnpm check
```

The full suite builds the Worker and portable packages and runs web, adapter,
auth, schema, registry and CLI tests.

## Hub API

```text
GET /api/v1/packages?q=vision&limit=20
GET /api/v1/packages/resolve?name=dsh-conversation-exporter
GET /api/v1/profiles?limit=20
GET /api/v1/profiles/{slug}
GET /api/v1/profiles/{slug}/releases/{version}/download
```

Responses include exact source metadata, compatibility, HMR behavior and
ordered profile bundles. Public reads are cacheable for 60 seconds with stale
revalidation. The Go backend owns these endpoints; browser requests use the
web shell's same-origin `/api/*` adapter.

## CLI

```bash
dsh-hub init my-plugin --repository your-name/my-plugin
dsh-hub validate my-plugin
dsh-hub search vision
dsh-hub info dsh-conversation-exporter --version latest
dsh-hub install dsh-conversation-exporter --profile web
dsh-hub profile search team
dsh-hub profile apply  --profile web
dsh-hub profile share  --profile web --version 1.0.0
dsh-hub profile import ./team-profile-1.0.0.dshprofile --profile web
dsh-hub profile history --profile web
dsh-hub profile rollback --profile web
```

Install execution uses argument arrays rather than a shell. A successful apply
keeps the official Profile directory clean and writes Hub state to
`~/.dsh/.hub/installations//current.json`. A Release locks the exact
DSH runtime, Plugin versions, sources, integrity and sequence. Apply builds a
staging Profile, validates its structure and composed config through the pinned
official DSH CLI, then atomically switches the target. Previous complete Profile
directories remain available for rollback.

The `.dshprofile` download is a portable recipe containing Release metadata,
`package.json` and `cordis.patch.yml`. It never embeds Plugin code, credentials,
input values, session data or logs. See [`docs/profile-v1.md`](docs/profile-v1.md)
for the V1 contract and V2 boundary.

`dsh-hub init` creates a three-file, schema-valid bundle starter and refuses to
overwrite existing files. Add `--name @scope/my-plugin` when the npm name
differs from the target directory.

`dsh-hub validate` checks package identity, exact version, listing metadata,
GitHub repository and the local Cordis patch before anything reaches npm.

## Publishing

1. Publish a package containing a valid DSH bundle or profile declaration to npm.
2. Wait for automatic discovery, or paste its package name into the public catalog.
3. Sign in at `/dashboard` and select **立即同步** when you want an immediate result.
4. Connect the package repository through the GitHub App to claim and edit its listing.

The Hub reads every published version, validates each manifest, and records
npm's exact tarball URL and integrity. Keywords only discover candidates; a
valid `dsh.bundle` or `dsh.profile` manifest controls catalog admission. The Hub
keeps historical versions and marks versions missing from npm as withdrawn.
It does not host tarballs.

See [`docs/publishing.md`](docs/publishing.md) for the manifest and security
contract. A complete minimal package is available in
[`examples/example-hello`](examples/example-hello).

New teammates should start with [`docs/architecture.md`](docs/architecture.md).

## Staging

Staging uses the Worker `deepseek-harness-plugin-hub-staging`, the shared Hub
backend origin configured by `HUB_API_ORIGIN`, and
`https://staging.dshpluginhub.ai`.

```bash
pnpm deploy:staging
```

Secret names are documented in `.env.example`. Store them with `wrangler secret
put`; never commit their values.

When using AuthKit Hosted UI, configure `/sign-in` as the WorkOS Sign-in
endpoint (`initiate_login_uri`) and leave the AuthKit external login URI empty.
The external login field is reserved for applications that provide their own
authentication UI and complete the `external_auth_id` flow.

## Security invariants

- WorkOS sessions protect the dashboard and management API.
- The web shell has no database binding; all product persistence belongs to the
  Go Hub backend.
- npm responses are bound to the requested package name and exact manifest version.
- npm search keywords only create candidates; the DSH manifest is the admission gate.
- Public manifests contain only the install-relevant package fields; npm user,
  maintainer and operational metadata are discarded before storage.
- npm tarball sources are HTTPS URLs and retain npm integrity metadata when present.
- Automatically discovered packages start unclaimed.
- Repository access through the GitHub App proves a publisher claim.
- Published package versions are immutable.
- GitHub integration is optional.
- GitHub OAuth state is HMAC-signed, short-lived, user-bound and nonce-bound.
- Callback `installation_id` is accepted only after the current GitHub user can
  list that installation and its repositories.
- GitHub user access tokens and installation tokens are never stored.
- GitHub App private keys and OAuth client secrets are Worker secrets.
- Public publication excludes private repositories.
- Abuse reports use Turnstile and are validated and persisted by the Hub backend.

## License and independence

This repository is an independent community project. It has no affiliation,
authorization, or endorsement from DeepSeek.

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。