DeepSeek Harness plugin

dsh-plugin-manager-osskn4w7

Manage DeepSeek Harness plugins from the web GUI and CLI: install, enable/disable, uninstall — no manual config-file editing. Writes your profile's cordis.patch.yml for you and applies changes live

Jump to install

Source facts

Repository
OSSKn4w7/dsh-plugin-manager
Latest update
Aug 15, 2026
Category
Plugin Markets & Managers
GitHub stars
1
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/OSSKn4w7/dsh-plugin-manager
Plugin: dsh-plugin-manager-osskn4w7
Author: OSSKn4w7

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-plugin-manager

Manage DeepSeek Harness plugins without editing config files.

The shipped workflow is: drop a package into the profile, hand-edit cordis.patch.yml, restart, repeat. This plugin gives the web GUI a 插件管理 (Manage) tab — right inside Settings → Plugins — where you can:

  • install a plugin by npm package name (with optional JSON config),
  • enable / disable any loader entry with one click (applied live, no restart),
  • uninstall plugins again,
  • see the whole composed Loader tree, the profile's dependencies and bundles,

and which rows the manager itself installed.

It writes your profile's cordis.patch.yml for you (a delimited auto-managed block; your hand-written patches are preserved byte-for-byte) and the running server's user-patch watcher (HMR) applies the change immediately.

It also ships a CLI (dsh-plugin-manager) and a chat command (/plugin).

Components

PieceRole
lib/index.jsHost half: JSON API under /plugin-manager/api + the /plugin chat command
lib/client.jsBrowser half: the 插件管理 tab in Settings → Plugins
lib/core.mjsShared logic: managed-block editing of cordis.patch.yml, pnpm runner, bundle reconcile
bin/dsh-plugin-manager.mjsStandalone CLI (works even while the server is stopped)

Install

npm: @osskn4w7/dsh-plugin-manager

# Option A — standard dsh bundle install:
dsh plugin --profile web add @osskn4w7/dsh-plugin-manager
# then restart dsh web (bundle patch layers load at boot)

# Option B — live install without a restart (from this checkout):
dsh-plugin-manager bootstrap --profile web
# or by hand: pnpm add file:… in the profile dir, then enable the entry,
# then refresh the browser (Settings → Plugins → 插件管理)

Use one option, not both (the row would be inserted twice). bootstrap installs this package into $DSH_HOME/profiles/web via pnpm and wires its Loader entry into cordis.patch.yml. Because the profile patch file is watched live, the host half activates immediately; refresh the browser once so the client bundle is picked up.

To use the CLI standalone (outside a profile checkout):

npm i -g @osskn4w7/dsh-plugin-manager
dsh-plugin-manager list --profile web

Requirements: pnpm on PATH, the web profile (or any profile with the web bundle), and a loopback-bound server (the default).

Publishing (maintainers)

The package lives on npm as @osskn4w7/dsh-plugin-manager and on GitHub as OSSKn4w7/dsh-plugin-manager.

npm version patch          # or minor / major — bumps version + git tag
npm publish --registry=https://registry.npmjs.org/ --access public
git push && git push --tags

Notes:

  • The default npm registry on this machine is an npmmirror mirror — always

pass --registry=https://registry.npmjs.org/ (mirrors are read-only).

  • The account has 2FA enabled (auth-and-writes): publish either with

--otp <code> or with a granular access token that has bypass 2FA enabled (create it at npmjs.com settings; its direct-publish ability is scheduled to end January 2027 in favor of a 2FA-approval flow).

  • The bin entry (dsh-plugin-manager) is included in the published tarball

via the package's files whitelist.

How enabling/disabling works

  • Plain plugin (no dsh.bundle in its manifest): install runs

pnpm add and inserts a live Loader entry into the managed block — enabled immediately.

  • Bundle plugin (declares dsh.bundle): install runs pnpm add and

reconciles the name into dsh.profile.bundles in package.json (same rule as dsh plugin --profile … add). Bundle patch layers are read at boot, so it reports needsRestart; after restart its entries appear and can be toggled.

  • Enable/disable: adds/removes an id-targeted disabled patch in the

managed block. The watcher recomposes the tree live.

CLI

dsh-plugin-manager list [--json] [--profile web]
dsh-plugin-manager enable <entry-id>   # or: disable
dsh-plugin-manager install <pkg> [--config '{"a":1}']
dsh-plugin-manager remove <pkg>
dsh-plugin-manager bootstrap

Chat command

In the web chat, /plugin list, /plugin enable <id>, /plugin disable <id>, /plugin install <pkg>, /plugin remove <pkg>.

Notes

  • The managed block in cordis.patch.yml is delimited by

# >>> dsh-plugin-manager … >>> / # <<< dsh-plugin-manager <<<; edits inside it are overwritten. Everything outside is yours.

  • The HTTP API is loopback-only (matching the server's default bind) and

carries no auth — do not expose the web server to a network you do not trust.

  • A disabled row whose id no longer exists in the composed tree logs a benign

loader warning; the manager drops such patches for packages it uninstalls.

License

MIT