DSH Plugins Marketplace

DSH Plugins

Plugins

/

Development & Infrastructure

/

dsh-plugin-skill-manager

m

dsh-plugin-skill-manager

Manifest valid

Skill management for the DeepSeek Harness Web client: scan user-level skill roots, list source and precedence, switch a skill off, edit SKILL.md, and install skills from documents or a GitHub link

UI (client)hasBundlePatch

dsh-plugin-skill-manager

English | 中文

Skill management for the DeepSeek Harness Web client: a Skills page in Settings that lists every skill the deployment can load from its user-level roots, shows the source and precedence that decide a duplicated name, switches one skill off, opens SKILL.md for editing, and installs skills from uploaded documents or a GitHub repository link.

The page is built from the client's own design system — @deepseek-ai/dsh-client-ui-primitives and the shared --dsw-* tokens — and registers into the official settings.section slot, so it sits in the Settings dialog exactly like a shipped section.

Install

# from npm (once published)
dsh plugin --profile web add @majinggui/dsh-plugin-skill-manager@latest

# from this repository
git clone https://github.com/majinggui/dsh-plugin-skill-manager
cd dsh-plugin-skill-manager && pnpm install && pnpm build
dsh plugin --profile web add link:$(pwd)

Then restart the profile (dsh web, pnpm run dev:web, or the desktop app) and open Settings → Skills.

The package declares one bundle patch (cordis.patch.yml) that inserts the single plugin row mounting both halves: the host half owns one authenticated JSON route, and the browser half registers the Settings page.

What the page offers

ActionEffect
CatalogEvery SKILL.md and flat .md document under the scanned roots, with its source, rank, absolute path, and enablement
Scan the shared agents directorySwitches ~/.agents/skills in or out of the scan; off by default, and the choice is remembered
Enable / disableSwitches one name off or back on (see how below)
Edit SKILL.mdReads the document into an inline editor and saves it against the version it was read from
Upload skill documentsReads .md files and/or skill archives (.zip) in the browser and installs them under the install root
Import from GitHubReads a repository link and installs every SKILL.md it exposes
Replace existing skillsPasses overwrite to an installation, which otherwise skips a name that already exists

Documents that cannot be parsed are listed with their parse error instead of disappearing, and a name that two roots define is explained inline because its switch applies to the whole name.

Skill archives

A .zip upload installs every directory that holds a SKILL.md as one skill and keeps the files beside it (scripts, references, assets). The single top-level directory Finder and GitHub's "Download ZIP" wrap archives in is stripped first, and an archive with no SKILL.md falls back to its root-level Markdown documents.

bundle.zip
└── pdf-helper/
    ├── SKILL.md          →  ~/.dsh/skills/pdf-helper/SKILL.md  (normalized frontmatter)
    └── scripts/fill.sh   →  ~/.dsh/skills/pdf-helper/scripts/fill.sh

Entry paths are normalized and refused when absolute or containing .., so extraction cannot escape the install root; encrypted, ZIP64, and unsupported-compression archives are refused with a readable reason.

How enablement works

A standalone plugin has no catalog filter, so disabling writes the two invocation keys the harness already understands into the document's frontmatter:

disable-model-invocation: true
user-invocable: false

That removes the skill from the model catalog, the skill tool, and the / menu. The plugin records the values it replaced in its state file (<dshHome>/skill-manager.json), so enabling restores exactly what the document had before — including removing a key the document never carried. Disabling a document that has no frontmatter is refused rather than guessed at.

Configuration

FieldDefaultMeaning
dshHome$DSH_HOME or ~/.dshHarness config root; its skills child is scanned and imported into
agentsHome$DSH_AGENTS_HOME or ~/.agentsShared agent config root, the one the page's scan switch controls
includeAgentsRootfalseWhether that root is scanned before the user changes the switch; the switch's stored choice wins after that
extraRoots[]Additional managed roots, each with path, source, and rank
stateFile<dshHome>/skill-manager.jsonEnablement ledger
installRoot<dshHome>/skillsDirectory that uploads and GitHub imports write into
githubMaxFiles20Largest number of documents one GitHub import installs
githubMaxDocumentBytes524288Largest accepted GitHub document
githubTimeoutMs30000Deadline for one GitHub import
uploadMaxDocuments20Largest number of documents and archives one upload installs
uploadMaxDocumentBytes524288Largest accepted Markdown document
zipMaxBytes52428800Largest archive one upload may carry, before extraction (50 MB)
zipMaxUncompressedBytes209715200Largest uncompressed size one archive may reach (200 MB)
zipMaxMembers2000Largest number of files one archive may hold
zipMaxEntryBytes67108864Largest uncompressed size of one file inside an archive (64 MB)

Set them where the plugin row is declared:

- insert:
    - id: skill-manager
      name: dsh-plugin-skill-manager
      config:
        extraRoots:
          - path: ~/team-skills
            source: team
            rank: 300

Which roots are scanned

Only $DSH_HOME/skills and any configured extraRoots are scanned by default. The shared agents directory ($DSH_AGENTS_HOME/skills, rank 500) is not scanned until the switch on the page turns it on; turning it off again drops its documents from the catalog on the next read. The choice is stored beside the disable records in the state file, so it survives a restart and overrides includeAgentsRoot.

Path confinement is wider than the scan on purpose: reads and writes stay confined to every configured root, so a skill that was switched off while the agents directory was being scanned can still be switched back on after the scan is turned off.

Safety

  • Every read and write is confined to a configured root; a path outside them is refused with outside-roots.
  • A write carries the content hash it was read from and is refused with conflict when the document changed in between.
  • Every write goes through a temporary sibling and a rename, so a failed write cannot leave a half-written SKILL.md.
  • Installs never replace an existing skill unless the request asks to.
  • GitHub import reads only files named SKILL.md, through the public API, under the configured file, size, and time bounds.

Development

pnpm install
pnpm build        # tsc -b && tsdown: lib/index.js (host) and lib/client.js (browser)
pnpm typecheck

lib/ is committed so dsh plugin add github:<owner>/<repo> works without a build step; rebuild after changing src/.

Source layout:

PathRole
src/index.tsHost plugin: configuration and the one route registration
src/manager.tsRoot resolution, catalog projection, enablement, installation
src/catalog.tsRoot scanning and tolerant frontmatter parsing
src/documents.tsDocument normalization, atomic writes, invocation-key editing
src/github.tsRepository link parsing and bounded download
src/http.tsRequest decoding and response encoding
src/protocol.tsWire vocabulary shared by both halves
src/client/The Settings page, its client, its copy, and its stylesheet

Limitations

  • Enablement edits SKILL.md (see above); a deployment that must not touch skill files cannot use this page.
  • Enablement is per name, not per document: two roots defining one name cannot be switched separately.
  • The catalog is a snapshot: a skill added elsewhere appears after the next refresh.
  • A project-level skill is outside this page; only the user-level and configured roots are scanned.
  • Upload archives are read with the stored and deflate methods only; an encrypted or ZIP64 archive is refused rather than guessed at.

License

MIT

Comments

Loading…

From the same category

awesome-dsh-plugin

by awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Development & Infrastructure

★ 18k

CC0-1.0

Python

Oct 5, 2026

Index only — not installable

by 0xsline

DeepSeek Harness (DSH) ecosystem: curated plugins, tools, and infrastructure from dsh-external/hub and the public dsh-plugin topic.

Development & Infrastructure

★ 1.1k

CC0-1.0

Python

Sep 30, 2026

Index only — not installable

by pax-beehive

Open-source CLI, schemas, resolver, and DSH agent tools for DSH Plugin Hub

Development & Infrastructure

★ 458

MIT

TypeScript

Oct 6, 2026

Index only — not installable

by yjh051108

推荐组件(非必须):DeepSeek Harness 运行时注入器;已随 dsh-routing-suite 单仓库化保留,本仓库继续维护/发布。

Development & InfrastructureManifest valid

★ 165

TypeScript

Sep 18, 2026

dsh plugin --profile web add @dsh-external/dsh-super-injector

by xiajiajun516

DeepSeek Harness (DSH) backup & restore plugin — export, import, migrate and sync your complete DSH configuration, plugins, MCP servers, skills and workspace. One-click migration to another machine.

Development & InfrastructureManifest valid

★ 162

MIT

TypeScript

Oct 6, 2026

dsh plugin --profile web add dsh-config-manager

by jigjoy-ai

A CLI that turns a goal into a pull request - and a sandbox for testing concurrent AI coding agents on the Mozaik runtime.

Development & Infrastructure

★ 124

MIT

TypeScript

Oct 2, 2026

Index only — not installable