DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-catalog

P

dsh-catalog

Discovered

DSH Desktop Market standard catalog source for the PerryLink plugin family: curated summaries, same-origin icons, contract-validated, CI-smoked.

dsh-catalog

License DSH plugin Gitee npm version npm downloads dshfind

A DSH Community Market standard catalog source for the PerryLink DeepSeek Harness plugin family: 42 packages, generated from the npm registry, validated against the public v1 contract schemas.

  • Manifest: catalog-source.json (generated; see Deploy)
  • Provider page: artifacts/v1/plugins.json (generated)
  • Source of truth: data/packages.json (npm name → repo → display name → categories) + data/npm-snapshot.json (npm registry snapshot)
  • Generator / validator: scripts/build-catalog.mjs, scripts/validate.mjs, scripts/check-counts.mjs
  • Deploy: live at https://perrylink-dsh-catalog.perrylink.workers.dev (Cloudflare Workers, automated via deploy.yml; Vercel static alternative in vercel.json; Deno unit deploy/deno-worker.js as manual alternative)

Compliance notes

  • Contract: catalog-provider-contract.md (v1, manifestVersion/schemaVersion 1.0.0). The schemas are vendored nowhere in this repo; scripts/validate.mjs mirrors the structural rules of catalog-source.schema.json and catalog-provider-page.schema.json and the cross-field rules (unique item ids, npm name pattern, no install commands in items, HTTPS repository URLs, page shape).
  • The minimal valid profile is used: query.supported = [], defaultLimit = maxLimit = 50, sorts = []. The endpoint returns the complete bounded page (42 items ≤ 50), so DSH Desktop scans it in one request and runs search/filtering over its local index.
  • Every item carries package.registry = "npm" + package.name and a canonical repository.url; no install commands, shell fragments or executable data are ever emitted.
  • Every item also carries a same-origin media.icon (/icons/<slug>.png, generated deterministically by scripts/build-icons.mjs); the Worker serves the PNGs itself, so the icons stay on the catalog origin as the market media rule requires.
  • The manifest endpoint and the manifest itself must share one HTTPS origin (market rule). The generated placeholder endpoint https://replace-with-deploy-origin.invalid/... is replaced by the real deploy origin at deploy time — do not register the placeholder URL in DSH Desktop.

Build

node scripts/build-catalog.mjs            # placeholder endpoint
node scripts/validate.mjs                 # structural checks
node scripts/build-catalog.mjs https://<your-project>.deno.dev   # real origin

build-catalog.mjs writes the manifest and provider page to the repo root and mirrors both into deploy/, so deploy/deno-worker.js is a self-contained Deno Deploy unit (its ./ imports always resolve).

data/npm-snapshot.json is refreshed UTF-8-safely with:

node scripts/refresh-snapshot.mjs   # re-fetch every package from registry.npmjs.org

Maintaining data/

data/packages.json and data/npm-snapshot.json are one unit: a new or renamed package needs its snapshot row in the same commit. Two consecutive main deploys went red on 2026-09-09 exactly this way — first a missing comma in data/packages.json, then a package listed without its snapshot row (Error: npm snapshot missing for …). Both are caught locally by the pre-push gate; enable it once per clone:

git config core.hooksPath .githooks   # then every push runs node scripts/check-data.mjs

scripts/check-data.mjs is read-only. Do not use node scripts/build-catalog.mjs as a gate: called without an argument it rewrites the committed deploy/ artifacts with the placeholder origin.

The family count is not hand-maintained: scripts/check-counts.mjs derives it from data/packages.json and holds every place that states it — the README summaries (EN + ZH), the manifest description, the shipped page's items/page.total and the deploy live-smoke floor — to that one source. Run it to verify, or node scripts/check-counts.mjs --write to rewrite the README count sites from the source. It exists because the number did drift: the README and the manifest advertised a family one package larger than the page actually shipped (the concrete figures and the commit that fixed them are recorded in the scripts/check-counts.mjs header).

.github/workflows/ci.yml runs scripts/check-data.mjs, scripts/check-counts.mjs and the build/validate pair on every push to main and on every pull request, so the hook above is a convenience rather than the only line of defence. scripts/validate.mjs resolves the committed deploy/ mirrors first — the payload that actually ships, and the only copy a fresh clone has — and holds page.total to items.length. CI then rebuilds to assert that the committed deploy/catalog-source.json still matches, which catches a data/ change that was never mirrored into deploy/. That rebuild is the one place the no-argument form is safe: the runner's checkout is throwaway, and the manifest carries no timestamp, so it is byte-reproducible.

Deploy

Live: https://perrylink-dsh-catalog.perrylink.workers.dev (Cloudflare Workers, deployed automatically by the deploy workflow).

Automated channels — the workflow rebuilds the manifest with the live origin, validates, then deploys; each channel skips gracefully when its token secret is absent:

  • Cloudflare Workers (active): deploy/wrangler.toml + deploy/cloudflare-worker.js. Requires CLOUDFLARE_API_TOKEN + CLOUDFLARE_ACCOUNT_ID secrets. Two-pass deploy: first uploads the placeholder-origin worker, reads the assigned *.workers.dev URL, rebuilds the manifest pinned to that origin, and redeploys. Falls back to Cloudflare Pages (.pages.dev) when workers.dev is unavailable.
  • Vercel: vercel.json rewrite /v1/plugins → artifacts/v1/plugins.json. Requires VERCEL_TOKEN.
  • Deno Deploy (manual): self-contained deploy/deno-worker.js; rebuild with node scripts/build-catalog.mjs https://<your-project>.deno.dev before deploying.

The site serves GET /catalog-source.json and GET /v1/plugins as application/json on one HTTPS origin.

Use in DSH Desktop

Open the built-in Market → Sources → add source → paste the manifest URL https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Browsing is read-only; installation of any listed plugin goes through the Market's own npm-identity verification and user confirmation.

A listing in this catalog is metadata, not a security review. The same plugins also have evidence records in dsh-plugin-certification and MCP access via dsh-cert-mcp.


中文说明

PerryLink 全家桶的 DSH Community Market 标准目录源:42 个 npm 包,由 npm registry 生成,按公开 v1 契约做结构校验。已上线 Cloudflare Workers(perrylink-dsh-catalog.perrylink.workers.dev,deploy workflow 自动部署;Vercel 静态重写与 Deno Deploy 为备选通道)。每个条目还带同源 media.icon 图标(/icons/*.png,由 scripts/build-icons.mjs 确定性生成)。在 DSH Desktop 的 市场 → Sources 里添加 manifest URL 即可浏览(浏览只读;安装仍走市场自身的 npm 身份校验与用户确认)。生成产物中的占位域名 replace-with-deploy-origin.invalid 在部署时替换,请勿直接注册占位地址。维护纪律:data/packages.json 与 data/npm-snapshot.json 必须同一次 commit 成对更新(2026-09-09 连续两次 main 部署红灯即由此而来:先是漏逗号,后是新增包缺 npm 快照行);执行一次 git config core.hooksPath .githooks 后,每次 push 都会跑只读门禁 scripts/check-data.mjs。切勿把不带参数的 node scripts/build-catalog.mjs 当作门禁——它会把已入库的 deploy/ 产物改写成占位域名。CI:.github/workflows/ci.yml 在每次 push 到 main 与每个 PR 上跑 scripts/check-data.mjs、scripts/check-counts.mjs 与 build+validate;scripts/validate.mjs 默认直接读已入库的 deploy/ 产物(真正上线的载荷,干净 clone 里只有它),并把 page.total 锁到 items.length;随后重建断言 deploy/catalog-source.json 未过期,可发现「改了 data/ 却没重建 deploy/」;该重建在 CI 的一次性 checkout 里是安全的,因为 manifest 不含时间戳、可字节复现。计数单一来源:包数一律由 data/packages.json 派生——scripts/check-counts.mjs 校验 README(EN+ZH)/manifest/产物/部署冒烟下限一致,--write 可从该来源重写 README 计数,禁止手写。

License

Apache-2.0. Catalog data derives from the npm registry and the PerryLink plugin repositories.

DSH family line: this repository belongs to the PerryLink DeepSeek Harness plugin family, whose current line is dsh-v0.1.7-rc.2.

PerryLink DSH Plugin Family

This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

PluginOne-liner
dsh-auto-reviewSecond-model auto-review on the approval chain, fail-closed by default
dsh-autotierAutomatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-background-agentsDurable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budgetCost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-catalogDSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcpRead-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-checkpoint-rewindClaude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-moveMigrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-clickCross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-historyTerminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-qualityDataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defendPrompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheckEngineering-discipline guard: requirements grill, test gates, adversary review
dsh-drawUnified static-image generation routing for DeepSeek Harness.
dsh-fastRead-only performance diagnostics for DeepSeek Harness.
dsh-fund-researchDeterministic research reports for Chinese public mutual funds
dsh-githubGitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-researchIndustry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-layaLaya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools
dsh-libraryLocal document knowledge base for DeepSeek Harness.
dsh-local-aiLocal-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actionsLSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-maskPII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panelRead-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-mementoApproval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-observeOpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-stylesClaude Code outputStyles-equivalent runtime style switching
dsh-permission-rulesClaude Code-style declarative allow/deny/ask permission rules with audit
dsh-plugin-certificationCommunity certification registry with repro-checkable grades and badges
dsh-plugin-doctorZero-dependency static + sandbox smoke detector for DSH plugins
dsh-plugin-guidePlugin-development knowledge base as an on-demand agent skill
dsh-plugin-kitShared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-upgradeOne-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card
dsh-plugin-upgrade-015Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-reachMulti-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-reportVerifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-scoreMulti-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pinPin sessions in the Web sidebar with durable ordering
dsh-session-syncCross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-securitySecurity-audit skill pack: secret scan, dependency and supply-chain review
dsh-talkVoice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-team-roomsCross-session team rooms: shared message bus, task board and timeline
dsh-test-driveIsolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktickTickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translateVendor parameter translation and deterministic JSON repair for DeepSeek Harness.

Comments

Loading…

Similar plugins

dsh-plugin-recommend

by 863683348

Plugin recommender for DSH: search and rank plugins from an embedded 1100+ entry marketplace catalog by need description, category and tags, with match reasons and a live catalog refresh from the awes

Tools & CapabilitiesDevelopment & InfrastructureManifest valid

★ 0

MIT

JavaScript

Sep 11, 2026

dsh plugin --profile web add dsh-plugin-recommend

Browse and manage the community plugin catalog from a first-level DeepSeek Harness Settings page, with verified installs and updates, removal, pause and resume, installed-package state, and sanitized

Tools & CapabilitiesTerminal & ClientsManifest valid

★ 0

↓ 116/wk

dsh plugin --profile web add dsh-plugin-console

by AwesomeHou

Plugin marketplace for DeepSeek Harness — live-syncs the GitHub dsh-plugin topic (1800+ repos) into a searchable, paginated settings tab with one-click install and agent tools (market_search / market_

Tools & CapabilitiesManifest valid

★ 32

↓ 1.5k/wk

MIT

JavaScript

Sep 12, 2026

dsh plugin --profile web add dsh-plugin-marketplace

by TheYoungChen

DeepSeek Harness plugin market - browse, search & install dsh-plugin topic plugins (dsh 插件市场:浏览/搜索/安装插件)

Manifest valid

★ 4

↓ 271/wk

MIT

JavaScript

Oct 11, 2026

dsh plugin --profile web add dsh-plugin-market

by dsh-research

The research plugin market for DeepSeek Harness (dsh): a Research plugins page in Settings that installs a curated, hand-read catalog into the profile you are running. Catalog at dsh-research.com.

UI & ExperienceManifest valid

★ 9

↓ 594/wk

MIT

TypeScript

Sep 1, 2026

dsh plugin --profile web add dsh-research

by PerryLink

Shared zero-runtime-dependency toolkit for PerryLink DSH plugins: a pluggable Provider registry seam, fail-closed approval and adaptive session-event gates, mechanical verify scripts, shared sanitize/

Development & InfrastructureManifest valid

★ 1

Apache-2.0

TypeScript

Sep 25, 2026

dsh plugin --profile web add @perrylink/dsh-plugin-kit