DeepSeek Harness 插件

dsh-skill-market

Skill market in the DSH settings page: search GitHub for skills and install them into ~/.dsh/skills. · DSH 设置页技能市场:从 GitHub 搜索技能并安装到 ~/.dsh/skills。(英文原文)

跳到安装方式

来源信息

GitHub 仓库
QQ-M/dsh-skill-market
最近更新
2026年8月18日
分类
远程与移动
GitHub stars
0
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/QQ-M/dsh-skill-market
插件名:dsh-skill-market
作者:QQ-M

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-skill-market

A DeepSeek Harness plugin that adds a Skill Market to the web UI settings page: search GitHub for skills and install them with one click into ~/.dsh/skills (the user-dsh skill root that the model's skill tool already reads).

  • Host half (index.js): a webServer prefix route /skill-market/api/* doing GitHub repo search, repo inspection, tarball download + extract, and skill install/uninstall.
  • Browser half (client.js): a hand-authored __ModuleLoader__ bundle (no build step) registering a settings.section entry labeled 技能市场 / Skill Market.

Features

  • Search GitHub (dsh-skill topic first, keyword fallback) for skill repos.
  • Inspect a repo's layout (root SKILL.md → one skill; skills/<name>/SKILL.md or skills/<name>.md → several).
  • One-click install: downloads the repo tarball from codeload.github.com, extracts it, copies each skill into the install dir.
  • Installed-skills tab with per-skill uninstall (moved to .trash-*, recoverable).
  • Same-origin POST guard on mutating endpoints.

Install

# from GitHub (pin a commit for production use)
dsh plugin --profile web add "github:QQ-M/dsh-skill-market"

# or from a tarball / local path:
# dsh plugin --profile web add ./dsh-skill-market-0.1.0.tgz

Then restart the web profile (dsh web) — the browser half is picked up from the dsh.client declaration at boot.

Configuration

The bundle patch (cordis.patch.yml) inserts the plugin row; the following config keys are supported:

KeyDefaultMeaning
installDir~/.dsh/skillsWhere installed skills are written
githubToken''GitHub token to lift the 10 req/min anonymous search limit
githubTokenFile''Path to a file containing a GitHub token (e.g. /opt/dsh-work/gh-token)
searchLimit20Max search results

If neither token option is set, GITHUB_TOKEN from the environment is used. Anonymous search works but is rate-limited (~10 req/min), so a token is recommended for heavy browsing.

Example override in your profile cordis.patch.yml (replaces the whole row by id — restate every key):

- insert:
    - id: skill-market
      name: dsh-skill-market
      config:
        installDir: /root/.dsh/skills
        githubTokenFile: /opt/dsh-work/gh-token

API

All endpoints are same-origin JSON under /skill-market/api/:

  • GET /api/search?q=<query>{ ok, items: [{ fullName, owner, repo, description, stars, updatedAt, url, topics }] }
  • GET /api/repo?owner=&repo={ ok, defaultBranch, description, stars, url, skills: [{ name, path }] }
  • POST /api/install { owner, repo, ref? }{ ok, branch, installed: [{ name, path, description }] }
  • GET /api/installed{ ok, installDir, items: [{ name, path, description }] }
  • POST /api/uninstall { name }{ ok, message }

Development

node --check index.js   # syntax check host half
node --check client.js  # syntax check browser bundle

The host half depends only on node:* builtins + @deepseek-ai/schemastery (already present in the profile). The browser half depends only on the module table's react.