DeepSeek Harness plugin

dsh-skill-market

Skill market in the DSH settings page: search GitHub for skills and install them into ~/.dsh/skills. · DSH 设置页技能市场:从 GitHub 搜索技能并安装到 ~/.dsh/skills。

Jump to install

Source facts

Repository
QQ-M/dsh-skill-market
Latest update
Aug 18, 2026
Category
Remote & Mobile
GitHub stars
0
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/QQ-M/dsh-skill-market
Plugin: dsh-skill-market
Author: QQ-M

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-skill-market

A DeepSeek Harness plugin that adds a Skill Market to the web UI settings page: search GitHub for skills and install them with one click into ~/.dsh/skills (the user-dsh skill root that the model's skill tool already reads).

  • Host half (index.js): a webServer prefix route /skill-market/api/* doing GitHub repo search, repo inspection, tarball download + extract, and skill install/uninstall.
  • Browser half (client.js): a hand-authored __ModuleLoader__ bundle (no build step) registering a settings.section entry labeled 技能市场 / Skill Market.

Features

  • Search GitHub (dsh-skill topic first, keyword fallback) for skill repos.
  • Inspect a repo's layout (root SKILL.md → one skill; skills/<name>/SKILL.md or skills/<name>.md → several).
  • One-click install: downloads the repo tarball from codeload.github.com, extracts it, copies each skill into the install dir.
  • Installed-skills tab with per-skill uninstall (moved to .trash-*, recoverable).
  • Same-origin POST guard on mutating endpoints.

Install

# from GitHub (pin a commit for production use)
dsh plugin --profile web add "github:QQ-M/dsh-skill-market"

# or from a tarball / local path:
# dsh plugin --profile web add ./dsh-skill-market-0.1.0.tgz

Then restart the web profile (dsh web) — the browser half is picked up from the dsh.client declaration at boot.

Configuration

The bundle patch (cordis.patch.yml) inserts the plugin row; the following config keys are supported:

KeyDefaultMeaning
installDir~/.dsh/skillsWhere installed skills are written
githubToken''GitHub token to lift the 10 req/min anonymous search limit
githubTokenFile''Path to a file containing a GitHub token (e.g. /opt/dsh-work/gh-token)
searchLimit20Max search results

If neither token option is set, GITHUB_TOKEN from the environment is used. Anonymous search works but is rate-limited (~10 req/min), so a token is recommended for heavy browsing.

Example override in your profile cordis.patch.yml (replaces the whole row by id — restate every key):

- insert:
    - id: skill-market
      name: dsh-skill-market
      config:
        installDir: /root/.dsh/skills
        githubTokenFile: /opt/dsh-work/gh-token

API

All endpoints are same-origin JSON under /skill-market/api/:

  • GET /api/search?q=<query>{ ok, items: [{ fullName, owner, repo, description, stars, updatedAt, url, topics }] }
  • GET /api/repo?owner=&repo={ ok, defaultBranch, description, stars, url, skills: [{ name, path }] }
  • POST /api/install { owner, repo, ref? }{ ok, branch, installed: [{ name, path, description }] }
  • GET /api/installed{ ok, installDir, items: [{ name, path, description }] }
  • POST /api/uninstall { name }{ ok, message }

Development

node --check index.js   # syntax check host half
node --check client.js  # syntax check browser bundle

The host half depends only on node:* builtins + @deepseek-ai/schemastery (already present in the profile). The browser half depends only on the module table's react.