DSH Plugins Marketplace

DSH Plugins

Plugins

/

perrylink

P

perrylink

Discovered★ 4

DeepSeek Harness plugin ecosystem: 86 open-source plugins in a 101-repo family, 100 PerryLink-owned - security, workflows, research, bridges, developer experience, and 53 compliance checkers - plus th

Hi, I'm PerryLink 👋

GitHub stars GitHub followers GitHub repos npm names npm downloads 30d actively maintained plugins node
license OpenSSF Scorecard (flagship dsh-auto-review) Glama (flagship MCP server jevcore) MCP Registry awesome-dsh-plugin
DSH Directory plugin index DSH Market Gitee mirror dsh host corridor
dshfind downloads across the family DSH Desktop Market source certified (flagship dsh-auto-review) Zenodo DOI

Open-source developer in Beijing. I build the DeepSeek Harness plugin ecosystem: 86 actively maintained Apache-2.0 plugins in a 101-repo family — security, workflows, research, messaging bridges, developer experience, and since 2026-10-08 a set of 53 compliance checkers that read a register or record set against a versioned rule pack and report the differences — plus the DSH Desktop Market catalog, a plugin-certification registry and the dsh-plugin-doctor CI checker. Every plugin ships CI, a Gitee mirror and five-language docs held to the same section count by a gate in its own CI; the checkers additionally hold every rule quotation to its own verbatim evidence record by a gate in CI.

There is one page per plugin at perrylink.github.io — 111 static pages covering all 96 entries, plus a page for choosing which checker fits a given register. Every page is complete in the served HTML with no JavaScript rendering it, so a reader who arrives from a search result or an assistant's citation sees the text rather than a loading state.

🦭 Phocinae — a 144.3M typed decision model

Separate from the harness: I train small language models. Phocinae-Largha-150M-v1 (Apache-2.0) is a typed decision model — no text generation; one forward pass returns a verdict per question with calibrated confidence. GPU 21.0 ms (RTX 5090) p50 per decision, CPU-only 1.64 s per case; English typed-decisions 0.906 (400 cases / 2,000 decisions, re-measured 2026-10-09), Chinese (machine-translated eval set) 0.848. With a τ=0.6 escalate gate, 55.0% of agent decisions stay local (79.6% at τ=0.5) and kept-subset accuracy moves 0.906 → 0.9936 (+0.0876) — the gate makes the system better, not just cheaper. Weights on Hugging Face and ModelScope; server pip install phocinae-server, DSH bundle npm i dsh-phocinae. Reproduction ships with the repo: seeds, row-set hashes, environment and eval scripts.

▶ Start here

One command installs the core family — dsh-kit:

./install-all.sh web              # Linux / macOS
.\install-all.ps1 -Profile web   # Windows PowerShell
PluginWhat it gives youInstall
dsh-auto-reviewSecond-model auto-review on the approval chain, fail-closed by default (234★)dsh plugin --profile web add dsh-auto-review
dsh-research-reportVerifiable research reports: content-addressed evidence ledger, manifest seal hash, byte-level citation checks, drift detection, disproof ledger (214★)dsh plugin --profile web add dsh-research-report
dsh-industry-researchIndustry/company research: chain-map SVG with bottleneck detection, timeline, company cards, adversarial review (213★)dsh plugin --profile web add dsh-industry-research
dsh-mementoApproval-gated cross-session memory (ctx.memory + SQLite) (139★) · 🧊 frozen — better-adopted alternatives existdsh plugin --profile web add dsh-memento
dsh-permission-rulesClaude Code-style declarative allow/deny/ask rules plus a process-level network policy (119★)dsh plugin --profile web add dsh-permission-rules
dsh-mcp-panelMCP management console: /mcp + Settings tab + trial calls (73★)dsh plugin --profile web add dsh-mcp-panel

🔧 Upstream & community contributions

Every repo below is external to PerryLink/*; every number is measured, merged work only, and open proposals are deliberately not listed. The third column names the project's owner — the account alone does not say whether that is a company, a standards body or one person.

★ 1,000+ — named individually, as the rule requires, each carrying the party that owns the project. Twenty-eight external repos above a thousand stars carry merged work (★ measured 2026-10-09), and the newest of them is koishijs/koishi — merged 2026-10-08T12:13:06Z by its maintainer shigma, who found and fixed a regression in this account's own patch before merging it, and the first koishijs row this table has carried. It is the second row to arrive inside a day: before it NVIDIA/NeMo-Agent-Toolkit merged 2026-10-08T00:10:02Z by NVIDIA's rapids-bot after maintainer willkill07 issued /merge — the first NVIDIA row this table carried — and before that vllm-project/aibrix merged 2026-10-07T11:18:42Z, bytedance/deer-flow 2026-10-07T10:22:16Z and apple/embedding-atlas 2026-10-06T16:30:51Z, and before those Tencent/BrowserSkill had held the position since 2026-10-06T13:45:15Z, awslabs/mcp for the fifteen hours before that and docker/docker-agent for the ten before that; ruvnet/ruflo and walkinglabs/learn-harness-engineering entered the ten days before those, and punkpeye/fastmcp has carried its merge since 2026-09-24 and was missing from the round before. Fourteen of those rows belong to a company or a well-known project organization — Amazon Web Services, Apple, ByteDance, Docker, NVIDIA, Reactive Resume, DeepSeek, cordiverse, koishijs, Tencent, the vLLM project, and the ACP project that Zed and JetBrains jointly govern, the last two of which take two rows each; the other fourteen are catalog repos, small community orgs and one-person projects, and the column says so rather than letting the account name imply a company:

Repository★项目归属方
deer-flow83,547字节跳动 ByteDance — the official bytedance org (deerflow.tech); a one-line portability fix in a blocking-IO test merged 2026-10-07T10:22:16Z by WillemJiang, and now the largest row in this table
ruflo74,154ruvnet (rUv / Reuven Cohen) — individual maintainer; a 74k★ agent harness on a personal account, not a company repo, and the largest row here that is not owned by a company
reactive-resume44,021reactive-resume org — independent open-source project (rxresu.me)
laya31,779NandhaKishorM — individual maintainer; the repo was created 2026-09-18
learn-harness-engineering19,543walkinglabs community org — the harness-engineering tutorial site
awesome-dsh-plugin18,121awesome-dsh-plugin org — community catalog, no company behind it
FlashMLA13,054DeepSeek — the official deepseek-ai org
mcp9,761Amazon Web Services (AWS) — the official awslabs org; a one-file UTF-8 fix merged 2026-10-05T22:49:06Z by maintainer markjschreiber with two approvals
Cordis9,087cordiverse org; its maintainer Shigma is now at DeepSeek, and Cordis is the kernel DeepSeek Harness vendors as @deepseek-ai/cordis
dsh-web8,527zhu1090093659 — individual maintainer
BrowserSkill8,465腾讯 Tencent — the official Tencent org; merged 2026-10-06T13:45:15Z by collaborator iuyo5678 with eight checks green
koishi6,248koishijs org — the cross-platform chatbot framework; merged 2026-10-08T12:13:06Z by its maintainer shigma, who found and fixed a regression in this account's own patch before merging it
ouroboros6,195Q00 — individual maintainer (@zep-us)
dsh-market5,886dsh-market org — the community plugin market behind dshmarket.com, not a DeepSeek repo
teamai-cli5,154腾讯 Tencent — the official Tencent org, opensource.tencent.com
aibrix5,128the vLLM project — the official vllm-project org behind vLLM; two flaky-test fixes merged 2026-10-06T16:23:08Z and 2026-10-07T11:18:42Z, the second by googs1025 and the second of the two flaky-test fixes this account has merged there
embedding-atlas4,972Apple — the official apple org (apple.github.io/embedding-atlas); a line-ending normalization fix in a release script merged 2026-10-06T16:30:51Z by donghaoren
agent-client-protocol4,394agentclientprotocol org — governed jointly by Zed Industries and JetBrains
docker-agent4,251Docker, Inc. — the official docker org; merged 2026-10-05 by maintainer aheritier
fastmcp3,274punkpeye (Frank Fiegel) — individual maintainer at Glama; the TypeScript MCP framework
deepseek-harness-desktop3,115dsh-tauri community org — self-described non-official and non-commercial, not a DeepSeek repo
NeMo-Agent-Toolkit2,662NVIDIA — the official NVIDIA org; three review rounds with maintainer willkill07 on making remove_r1_think_tags actually remove think blocks, merged 2026-10-08T00:10:02Z by NVIDIA's rapids-bot after he issued /merge
claude-agent-acp2,626agentclientprotocol org — the same jointly-governed org as the row above, a separate repository
awesome-jev2,232yibie — individual maintainer, community catalog for Jev; the row the 09-25 round both printed and denied, kept now on the commit the history probe finds
Agents-Anywhere1,512anywhere-labs community org — 3 public repos, created 2026-05, dshdesktop.cn; not a company
dsh-plugin-radar1,465AdamPlatin123 — individual maintainer, catalog is a generated artifact
awesome-deepseek-harness1,1500xsline — individual maintainer, community catalog
awesome-vibecoded-saas1,037Anil Chandra Naidu Matcha — individual maintainer, community catalog

The rest of the contributor set is the community catalog layer rather than upstream projects: 28 further repositories, DSH plugin directories and small community projects (dsh-handbook, imsai-sh's list, which alone took 41 merges, and the Jev gallery, among them) — the catalogs ingest the family and carry no company owner, so they are named here only in aggregate. 56 external repositories carry at least one merged pull request of ours together with a commit attributed to this account, and 332 merges were counted inside them — re-derived 2026-10-09T04:16Z from this account's own merged pull requests, so 332 is exact rather than a floor over a probed subset. Two further repositories took 33 more of our merged pull requests without crediting a commit to this account on their default branches — SihanTeng's list, 32 of them, which is the case the rule at the top of this section was written about, and dsh-better-sidebar, one, which merged 2026-10-04 and carries no commit of ours on main — so neither sizes the contributor set. 332 + 33 = the 365 merged pull requests this account has outside PerryLink/*, concentrated in 58 repositories; a further 102 are open across 65 repositories and are deliberately not counted here.

The round since the last derivation moved the merged count by 8, the credited set by seven repositories and the table by two rows — the previous derivation was dated 2026-10-07 and this one was taken 2026-10-09T04:16Z. All eight merges are upstream work, and two of them clear a thousand stars. koishijs/koishi is the newest of the two: merged 2026-10-08T12:13:06Z by its maintainer shigma, who reviewed the pull request, found that a remainder after $( … ) containing a newline was being dropped, pushed his own fix onto the branch, and merged with it — so the row rests on a squash commit authored by this account and co-authored by him, and the review is recorded rather than hidden. NeMo-Agent-Toolkit merged #2293 on 2026-10-08T00:10:02Z and carries our commit on develop, its default branch; it was the first NVIDIA row this table carried and is now the second-newest row in it. satori took two — #422 on 2026-10-07T14:55:26Z into main, which is what credits the repository, and #421 on 2026-10-07T15:06:01Z into the v4 branch, which is not the default branch and therefore credits nothing by itself — so satori is named here on the merge that reaches main, and #421 is counted in the merged total rather than being allowed to look like a second credited repository. The other four each credit a repository below the thousand-star threshold, so none of them moves the table: koishi-plugin-adapter-onebot#82, merged 2026-10-08T02:12:22Z with an approving review twenty-seven days after it was opened, at 51★; satorijs/boilerplate#2, merged 2026-10-08T07:09:11Z — a one-line CI fix that detects the Windows runner with RUNNER_OS before choosing zip flags, opened 2026-09-19 — at 2★ the smallest repository this account is credited in; koishijs/docs#210, merged 2026-10-08T07:44:12Z at 27★; and OmniJev/awesome-jev-gallery#33, merged 2026-10-08T13:22:47Z at 500★, which is the most recent merge this account has anywhere. The round also closed one proposal and then settled it: satori#420 was closed 2026-10-08T07:26:38Z as superseded by a cherry-pick onto v4, the cherry-pick did not carry the change, the maintainer confirmed that on 2026-10-08T12:34:03Z and re-cut it as 7606a0c3 — so the pull request stays correctly counted as closed while the change does reach v4, under the original author's name rather than this account's. The most recent merge before the window remains aibrix#2931, merged 2026-10-07T11:18:42Z.

laya — NandhaKishorM/laya — 46 merged pull requests of the 50 this account has opened there and second among merged-PR authors, behind aashish254 (126) and ahead of Bruce-Yii (27); the maintainer NandhaKishorM holds one merged PR of his own because he commits to main directly rather than through pull requests, and none of the three leaders is a collaborator. As of 2026-10-08 it reads 0 open and 4 closed unmerged; 45 of the 46 merged inside a nine-day run (2026-09-21 → 2026-09-29), and the maintainer merges in batches — fifteen of them share two timestamps, seven at 19:29:05 on 09-27 and eight at 17:40:36 on 09-29. The complete list is one query away:

laya pull requests by this account — the same 50, always current, in any language.

The 46 merged pull requests, by area
  • Multilingual routing and evaluation — a caller-supplied language hint (#211), a reproducible per-language harness (#210), a re-run of the 51-language sweep in both temperature regimes (#222), the multilingual columns refreshed from that re-run (#389), letters counted for the scripts no range claims (#169), and a Router that no longer picks a checkpoint from a language code naming no language (#368).
  • HTTP serving and containers — inference moved off the event loop (#230), the Compose laya-serve service (#234), the inference failure the client is not allowed to see now reaching the operator's log (#375), a request with no state no longer answered about the literal text null (#427), and a lone surrogate in the body returning 400 instead of 500 (#454).
  • Email disclaimers and names — the request kept when a disclaimer footer shares its paragraph (#94), "confidential" no longer read as a disclaimer (#227), a From: line opening ordinary prose no longer deleting the request (#371), and a name class that excluded lowercase in every script (#503).
  • Correctness across the call surface — three assertions that could not fail (#231), the load-time and budget errors no suite reached (#237), an ECE that binned differently from its siblings (#232), non-ASCII characters kept in non-string instructions (#228), a README link pointing at a heading that does not exist (#236), a choice label with no description that came back as a non-string (#380), a nested choice label reported as a named caller error instead of a bare TypeError (#425), a score legend that echoed the caller's own type instead of level text (#420), hooks_installed removing a hook it did not install (#424), a null choice label that made the answer undecodable (#508), a short temperature list that now fails at load rather than at the first decode (#502), #249, where a noul criteria dict that cannot be read raises instead of silently falling back to defaults — the line the project's 0.3.11 release note calls "stricter noul criteria" — and #299, two parity cells in the benchmark table that did not match the JSON they cite.
  • The test and CI surface — the Windows lane (#212) and #376, six pytest suites that every lane invoked in a way that exited 0 without running a single test, including the only coverage of the HTTP surface.
  • Prediction hooks and batched routing — process-wide default hooks never reaching predict_batch (#379), predict_batch dropping each request's lang, so per-language temperatures never applied (#381), and lang_temperatures crashing on the inputs it exists to reject (#428).
  • The TypeScript front end — the From: header rules the Python side already had, ported rather than re-derived (#422); the Azerbaijani schwa counted as a non-English letter (#423); and a score legend that echoed the caller's own types, unlike the Python backends (#556).
  • CLI, packaging and serving edges — --preset sending the request under a key no question set names (#426); the onnx extra missing its onnxscript dependency (#504); the packaging test scanning .venv for broken links (#500); and two over-budget messages that each named a knob which makes the problem worse rather than the one that fixes it (#455, #501).
  • Documentation — #378, which stopped the README presenting a confidence threshold as permission to act on its own, and the pages the project's docs-structure issue asked contributors to write: the fine-tuning guide (#505), the Questions and answers guide (#418), and the reference entry for answer_confidence, which no page documented (#419).

The nine area headings above are this account's own grouping of its 45 nine-day merges, not the project's taxonomy; the merge counts are the repository's own.

Four closures, and the reason is on the record for each: #370, closed by this account as a duplicate of #362, which opened the same fix four minutes earlier; #416, the Routing guide, closed by the maintainer in favour of another contributor's #461 so the project would not carry two routing pages; and #925, closed unmerged at 2026-10-04T17:54:52Z, four minutes after #924 merged; and #943, closed unmerged at 2026-10-05T17:28:15Z in favour of #936, which had landed the same two lines six minutes earlier and additionally forwards hooksRaise into the routeBatch call, so a per-call hooksRaise: false reaches onRoute as well as each request's predict lifecycle — the maintainer's note says explicitly that it was not closed for being wrong.

Security — published advisory GHSA-j922-p6h6-p255 for dsh-permission-rules (medium, patched in 0.6.16).

Official harness repo — it does not accept external pull requests, so that line runs through issues, Discussions (the Show Your Plugins! post #6104) and the plugin ecosystem instead — while the wider deepseek-ai org is open to fixes, and the account now proposes them at the systems layer rather than only in its catalogs: of the 20 pull requests it has opened across that org, FlashMLA #224 remains the only one merged, and 16 are open, 14 of them code fixes carrying a reproduction across ten repositories — DeepEP three, FlashMLA and deepseek-recipe two each, and one apiece in DeepGEMM, 3FS, TileKernels, DeepSeek-MoE, DeepSeek-Prover-V1.5, DeepJIT and DeepSelect — the other two are catalog additions.

📦 The rest of the family

The rest of the family and the five support repos are one line each below. The roster's source of truth is dsh-kit — its plugins.txt and a parity script hold the family to that file; the machine-readable catalogue is dsh-catalog, which is also the DSH Desktop Market source; and each plugin's own README carries the detail this page only summarises.

The full family — 95 plugins in the roster, 86 of them actively maintained, plus 5 support repos, one line each

Counting note: 86 is the actively maintained set, and it is the figure this page's heading and badge use. It is derived one repository at a time: 95 repositories declare dsh.bundle.patch (re-derived 2026-10-08 by reading each repo's own package.json at its default branch), of which 3 are 🚫 retired and 6 are 🧊 frozen, leaving 86 actively maintained. Measured against the 100 PerryLink-owned repositories this page names: 95 declare the contract and 5 do not — the support trio dsh-catalog, dsh-kit and dsh-plugin-certification (the certification registry, whose MCP server publishes from dsh-cert-mcp instead), plus jevcore (no dsh.bundle; only its jevcore-dsh workspace member is a plugin) and laya-mcp (an MCP sidecar, not a plugin). The third-party pan17/dsh-wechat carries a plugin row but is not one of them: 100 + 1 = the 101 repos this page names. A naive scan of the account finds two more than the 95 — the retired dsh-plugin-upgrade corridor legs dsh-plugin-upgrade-015 (not archived) and dsh-plugin-upgrade-016 (archived), both still carrying the manifest and neither an active plugin: 95 + 2 = the 97 such a scan returns. The ten tables below list 94 rows: 92 of the 95 roster repositories, plus jevcore (which declares no dsh.bundle) and the third-party dsh-wechat — the three left out (dsh-plugin-kit, dsh-cert-mcp, dsh-plugin-doctor) are the toolchain repositories named in the support list above. Retired and frozen rows keep their place with their status rather than being deleted, which is why the roster figure is larger than the active one. The same 95 repositories and the same three states are recorded once, in dsh-plugin-kit/data/repos.json, which the portal renders and the certification registry counts.

The 2026-10-08 addition. 53 compliance checkers joined the roster that day — they declare dsh.bundle.patch like every other entry, so by the rule above they count. They are the ### ✅ Compliance checkers section below, and they keep their own memory file and maintenance rules in a separate workspace. Every figure in this note was raised by exactly 53 except the non-plugin total, which is measured rather than derived.

🔒 Security (4)

PluginOne-linerStatusnpm
dsh-defendInjection/jailbreak/secret detection + destructive-delete gate🧊 FROZEN — broader detector, but frozennpm
dsh-permission-rulesDeclarative allow/deny/ask rules + a local HTTP/CONNECT network policynpm
dsh-maskPII masking/sanitizationnpm
dsh-skill-pack-securitySecurity-audit skill pack + supply-chain gatenpm

🔁 Workflows (8)

PluginOne-linerStatusnpm
dsh-background-agentsDurable background child agents with a Web UI sidebar, messaging and interrupt🚫 RETIRED — native continuable subagentsnpm
dsh-team-roomsCross-session team rooms: shared message bus, task board, approval-gated handoffs and a timeline that survive restarts🚫 RETIRED — native Agent Teamsnpm
dsh-checkpoint-rewindSnapshots, forks, one-shot restorenpm
dsh-githubGitHub PR/issue integration + Action, writes approval-gatednpm
dsh-claude-moveMigrate Claude Code/Codex/OpenCode/Hermes into DSH🧊 FROZEN — dsh-chat-importnpm
dsh-clickDesktop control tools (Windows/macOS)npm
dsh-session-syncGit-backed session synchronizationnpm
dsh-test-driveInstall→smoke→uninstall test driver for pluginsnpm

✨ Experience & UX (4)

PluginOne-linerStatusnpm
dsh-composer-historyTerminal-style input history for the web composernpm
dsh-output-stylesRuntime-switchable model output stylesnpm
dsh-session-pinPin sessions in the Web sidebar🚫 RETIRED — native session pinningnpm
dsh-mementoApproval-gated cross-session memory protocol🧊 FROZEN — @openviking/dsh-memory-pluginnpm

🧪 Evaluation (3)

PluginOne-linerStatusnpm
dsh-auto-reviewSecond-model auto-review on the approval chainnpm
dsh-doublecheckEngineering-discipline guard: grill, gates, adversary reviewnpm
dsh-scorePlugin quality scoring across git/gh/npmnpm

📊 Observability & cost (4)

PluginOne-linerStatusnpm
dsh-autotierAutomatic strong/cheap model-tier routing with deterministic risk guardsnpm
dsh-budgetToken/cost metering, budget caps, carbon estimate, latency benchmarks🧊 FROZEN — dsh-cost-meternpm
dsh-observeOTel/Langfuse telemetry exportnpm
dsh-fastPerformance diagnosticsnpm

🎨 Content & knowledge (5)

PluginOne-linerStatusnpm
dsh-drawImage-generation routing🧊 FROZEN — dsh-image-gennpm
dsh-translateTranslation + JSON repairnpm
dsh-talkSpeech recognition and voice I/Onpm
dsh-libraryLocal knowledge-base RAGnpm
dsh-local-aiOllama LLM provider and routingnpm

🛠️ Developer experience (6)

PluginOne-linerStatusnpm
dsh-lsp-actionsLSP diagnostics/formatting/completion/actionsnpm
dsh-mcp-panelMCP management consolenpm
dsh-plugin-guidePlugin-dev knowledge base + CLI toolchain + release-engineering guidenpm
dsh-plugin-upgradePlugin-author upgrade skill: one package, one corridor index that detects the caller's peer band and routes to the matching closed card (0.1.3-alpha.1 → 0.1.5-rc.1, 0.1.5-rc.2 → 0.1.6-alpha.2), plus a zero-dependency seam scanner (bundle skill + npx CLI)npm
jevcoreTypeSafe Jev as typed decisions instead of prose (noul/choice/score with calibrated probabilities): offline by default, every transmission named before it happens, disabled gates register nothing (the DSH adapter jevcore-dsh, plus jevcore core and jevcore-mcp for non-DSH MCP hosts)npm
dsh-layaLaya typed decisions (noul/choice/score) as a first-class Cordis service (ctx.laya) plus laya_ask/laya_plan tools; a client of a laya-mcp serve sidecar, so it installs and downloads nothing, and reports whether state stays on this machine as a fact rather than a policynpm

Support repos: dsh-plugin-kit (review-rule meta package) · dsh-catalog (DSH Desktop Market catalog source) · dsh-cert-mcp (certification MCP server) · dsh-kit (one-command installer) · dsh-plugin-doctor (plugin health checker). Five of these repos and plugins publish under a @perrylink/ npm name rather than their repo name — the support repos @perrylink/dsh-plugin-kit and @perrylink/dsh-plugin-doctor, and the plugins @perrylink/dsh-github, @perrylink/dsh-ticktick and @perrylink/dsh-skill-pack-security-provider — and a sixth name, @perrylink/dsh-cert-mcp, is the deprecated scoped predecessor of dsh-cert-mcp; the perrylink account therefore holds 52 npm names — more names than the family has repositories, because several repos publish both a plugin and a provider package (measured 2026-10-04).

📱 Messaging & bridges (3)

PluginOne-linerStatusnpm
dsh-wechatWeChat ↔ DSH bridge (Tencent iLink bot): text/image/file/voice, approvals in chat — developed with pan17, who now hosts the repo and publishes the npm package🧊 FROZEN — @xmanrui/dsh-imnpm
dsh-ticktickTickTick/Dida365 task bridge: session-header panel + 11 toolsnpm
dsh-reachMulti-channel approval/question bridge: WeChat/Telegram/Feishu, session console🧊 FROZEN — @xmanrui/dsh-imnpm

🔬 Research (4)

PluginOne-linerStatusnpm
dsh-data-qualityData profiling/cleaning/verificationnpm
dsh-fund-researchMutual-fund research, sealed traceable snapshotsnpm
dsh-industry-researchIndustry/company research domain packnpm
dsh-research-reportVerifiable research-report enginenpm

✅ Compliance checkers (53)

Fifty-three checkers published 2026-10-08, all Apache-2.0, all carrying SLSA provenance on npm. Each reads one register, ledger or record set against a versioned rule pack and returns the differences for a human to review — none of them pronounces on compliance, liability or clinical correctness. Every rule cites the clause it rests on, and a per-repo check:citations gate holds each quotation to its own rules/evidence/ record, so a rule cannot quietly cite something it cannot show.

🧾 Tendering & procurement (7)

PluginOne-linerStatusnpm
dsh-bid-ca-precheckPre-flight check of a bid package against the responsiveness and qualification clauses before submissionnpm
dsh-bid-qual-checkQualification screening: does the bidder's evidence actually answer every qualification the documents demandnpm
dsh-tender-extractPulls the substantive requirements out of tender documents so nothing mandatory is missednpm
dsh-tender-matrixScoring-matrix arithmetic: weights, caps and totals reconciled against the stated evaluation methodnpm
dsh-protest-deadlineChallenge-deadline arithmetic under the procurement regime, with the clause behind each periodnpm
dsh-contract-stanceReads a contract for the positions it actually takes, clause by clause, and reports them without advisingnpm
dsh-rulefile-checkInternal rule-file consistency: no contradictions, no dangling references, no undefined termsnpm

🏗️ Construction & environment (7)

PluginOne-linerStatusnpm
dsh-site-log-checkSupervision-log completeness against the supervision standard and the on-site recording rulesnpm
dsh-hazplan-checkHAZOP worksheet review: nodes, guide words, deviations and actions held to the analysis standardnpm
dsh-safety-brief-checkSafety-briefing records checked for the required topics and the sign-off each one needsnpm
dsh-guard-plan-qcGuard-plan quality: coverage, escalation paths and the shifts the plan claims to covernpm
dsh-soilwater-checkSoil and groundwater survey records — sampling points, analytes and the reported unitsnpm
dsh-eia-guide-checkEnvironmental impact assessment against the published technical guidelinesnpm
dsh-permit-report-checkPermit application reports: the sections required, and whether each is filled rather than templatednpm

🦺 Safety & hazardous materials (7)

PluginOne-linerStatusnpm
dsh-hazchem-checkHazardous-chemical register and major-hazard-source identification, reconciled arithmeticallynpm
dsh-emergency-planEmergency plan structure and the drills, contacts and review dates it must carrynpm
dsh-drill-script-checkDrill scripts: scenario, roles, timeline and the corrective actions a drill has to producenpm
dsh-hidden-risk-mapHidden-risk map: every hazard mapped to the article it is reported under, no gaps and no inventionsnpm
dsh-power-ticket-checkWork permits for electrical isolation — the safety measures each permit class requiresnpm
dsh-power-loss-splitPower-loss event split across causes so the totals reconcile to the reported outagenpm
dsh-aqua-input-checkAquaculture input records: batch, dosage and withdrawal periods against the limits statednpm

🏥 Medical records (3)

PluginOne-linerStatusnpm
dsh-icd-rule-checkICD coding pairs — dagger and asterisk, combination codes — flagged for a coder to resolvenpm
dsh-medrec-qcMedical-record front sheets checked for field completeness and code well-formednessnpm
dsh-nurse-record-checkNursing records: the observations, timings and signatures each entry is required to carrynpm

📄 Official documents & archives (3)

PluginOne-linerStatusnpm
dsh-gongwen-flow-checkOfficial-document handling flow — drafting, review, issue — checked against the regulationnpm
dsh-gongwen-word-checkDocument type and reference number checked against the formatting standardnpm
dsh-archive-checkArchive records: retention periods, catalogue fields and transfer datesnpm

🚢 Customs & trade (8)

PluginOne-linerStatusnpm
dsh-customs-doc-checkCustoms declaration pack — the documents a declaration needs, and the fields each must carrynpm
dsh-hs-classifyHS classification entries: the basis recorded for each code, in the form the tariff regulation requiresnpm
dsh-origin-rvc-checkRegional value content arithmetic for rules of origin, including the de minimis testsnpm
dsh-export-ctl-checkExport-control screening records against the control lists and the licence conditionsnpm
dsh-lc-doc-checkLetter-of-credit documents against the terms — discrepancies listed, not adjudicatednpm
dsh-demurrage-ledgerDemurrage and detention ledger: free days, laytime arithmetic and the tariff appliednpm
dsh-railway-windowRailway freight windows and the cut-off dates each booking has to clearnpm
dsh-forecast-penaltyForecast-versus-actual penalty arithmetic, with the formula the contract statesnpm

⚙️ Quality & manufacturing (8)

PluginOne-linerStatusnpm
dsh-fmea-table-checkFMEA tables — severity, occurrence, detection and the RPN arithmetic that follows from themnpm
dsh-ppap-checkPPAP submission completeness against the level the customer requirednpm
dsh-spc-gbt-adapterControl charts read against the national standard: limits, rules and out-of-control signalsnpm
dsh-pipeline-checkPipeline inspection records: intervals, anomalies and the repairs each anomaly triggerednpm
dsh-warranty-calcAutomotive three-guarantee periods and thresholds, computed from the invoice and delivery datesnpm
dsh-repair-order-qcRepair orders: the settlement list, the completion certificate and the archive a repair must producenpm
dsh-ota-review-checkOver-the-air update review records — scope, rollback plan and the sign-offs requirednpm
dsh-review-reply-checkResponses to review comments: whether every comment received an answer and a changenpm

🔬 Research & academia (5)

PluginOne-linerStatusnpm
dsh-nsfc-form-checkGrant application forms checked for the fields, limits and attachments the call requiresnpm
dsh-paper-doc-adapterManuscript formatting against a venue's own submission requirementsnpm
dsh-essay-rubric-checkRubric-based marking checked for arithmetic and for criteria that went unmarkednpm
dsh-learning-gap-checkLearning-gap analyses: the evidence cited for each gap and the interventions proposednpm
dsh-policy-brief-draftPolicy briefs checked for the structure a brief is expected to carry and for unsourced claimsnpm

⚖️ Evidence & litigation (3)

PluginOne-linerStatusnpm
dsh-evidence-checkEvidence lists against the civil evidence rules — production deadlines, notices and exchangesnpm
dsh-pleading-draftPleadings checked for the elements each claim has to plead and for internal inconsistencynpm
dsh-lawcite-adapterLegal citations resolved to the instrument actually in force, and flagged when they are notnpm

🏛️ Governance (2)

PluginOne-linerStatusnpm
dsh-soe-decision-checkState-owned-enterprise collective-decision records against the "three majors, one large" procedurenpm
dsh-sop-sync-checkStandard operating procedures checked against the versions and cross-references they claimnpm

🪦 Retired & frozen (2026-10-05)

A maintainer review of the whole family against the official harness and the wider plugin ecosystem concluded that three of these plugins duplicate capabilities the official harness now implements natively, and one was reclassified as internal tooling. Retirement here has a precise meaning: compatibility updates stop because the capability is now official, or because a better-adopted alternative exists — these are not abandoned or broken, and they keep working for existing installs.

Retired — the official harness now implements this

PluginWhyUse instead
dsh-background-agentsThe official harness ships native continuable subagents — subagent with backgroundMode: continuable, plus send_message / interrupt_agent / list_agents / job_*, mounted inside dsh-basethe native continuable subagents
dsh-session-pinThe official harness ships session pinning natively — the row menu and hover button in dsh-client-ui-workspace, with the pin set persisted on the Host and mounted in the default Web bundlethe built-in session pin
dsh-team-roomsThe official harness ships the Agent Teams subsystem (dsh-experimental-agent-team): implicit-root roster, durable peer mailbox and a shared task DAG. Well-adopted community alternatives exist toonative Agent Teams, or @nanmicoder/dsh-agent-teams

Reclassified, not retired: dsh-catalog is now treated as family-internal tooling rather than a product. It is live infrastructure feeding the DSH Desktop Community Market, and its job is to inventory this family — so it does not compete with third-party catalogs and needs no retirement.

Frozen — no new features, only real breakages fixed

Frozen because better-adopted alternatives now exist for that capability. Six of the seven carry a ## Maintenance status: 🧊 FROZEN section in their own README with the measured comparison — dsh-wechat is the exception, because it is pan17's repository rather than this account's, so the banner cannot be added there and the row is frozen here instead. Weekly npm downloads, measured 2026-10-05:

Pluginthis repobetter-adopted alternative
dsh-budget1,079dsh-cost-meter — 33,526
dsh-memento1,202@openviking/dsh-memory-plugin — 10,160
dsh-draw973dsh-image-gen — 7,216
dsh-claude-move843dsh-chat-import — 5,111
dsh-reach~600@xmanrui/dsh-im — 17,384
dsh-wechat752@xmanrui/dsh-im — 17,384
dsh-defend937cc-safety-net — 13,087

dsh-defend is the one frozen package that is still the broader detector — an Aho-Corasick engine over the prompt-injection / jailbreak / secret-leaker asset sets, with three-way allow/ask/block interception on user messages, tool arguments and tool results. It is frozen because the field moved, not because the plugin is weaker.


🌍 Where the plugins live

  • GitHub (this profile), Gitee and npm — source, CI and releases here; 46 family repos mirrored to Gitee by a daily job (default branch + all tags), plus this profile repo; the perrylink account holds 52 npm names and 1,069 versions, 44 of them with a non-deprecated latest and 39 of those carrying a SLSA provenance attestation on that version (45 names carry it on at least one version; the seven with none anywhere are jevcore-dsh, jevcore-mcp, dsh-laya, laya-mcp and the three archived layacore names — measured 2026-10-07 against each name's own packument, and the registry search endpoint is not authoritative here, since it returns only 47 names and omits the deprecated ones)
  • npm downloads — 183,886 over the trailing 30 days (npm window 09-07..10-06, summed per name from the downloads point endpoint; dshfind independently tracks 38.5k+ across the 8 family plugins it currently has a download figure for — dshfind reports rounded tiers, so that is a floor rather than a total
  • DSH Desktop Market — add the catalog source https://cdn.jsdelivr.net/gh/PerryLink/dsh-catalog@main/deploy/catalog-source.json under Market → Sources to browse the family in-app (the perrylink-dsh-catalog.perrylink.workers.dev address this used to give answers HTTP 000 on networks that interfere with *.workers.dev, so it now points at the same file over a CDN with mainland nodes); MCP Registry — three servers, all published from their release workflows over GitHub OIDC: dsh-cert-mcp, jevcore-mcp and laya-mcp
  • GitHub Actions — dsh-github and dsh-test-drive also ship composite actions, so they install as uses: PerryLink/dsh-test-drive@vX

Published to a dozen-plus third-party DSH directories and curated lists — awesome-dsh-plugin, DSH Directory, Awesome DeepSeek Harness, walkinglabs' list, Zhiyuan-Fan's list, the AdamPlatin123 radar, dsh-suite, dshfind.com, deepseek1024.com and Glama among them — and scored on OpenSSF Scorecard; the GitHub dsh-plugin topic is what most of them ingest from.

中文介绍

在 DeepSeek Harness 上构建插件生态:86 个活跃维护的开源插件,来自一个 101 仓的家族(其中 100 个由 PerryLink 自己维护) —— 安全、工作流、研究、消息桥接、开发者体验,以及 2026-10-08 起新增的 53 个合规核查插件(每个都是拿一份台账或记录去对版本化规则包,只输出差异供人复核),外加 DSH Desktop Market 目录、插件认证注册表与 dsh-plugin-doctor 这个 CI 检查器。86 个插件全部带 CI、Gitee 镜像与五语文档,文档的段落数、安装命令、配置键由每个仓自己的 CI 闸门守着一致,并声明 dsh.bundle 契约。npm 账号、Gitee 镜像、DSH Desktop Market、MCP Registry 与 GitHub Actions 的入口见上节「Where the plugins live」。我也向上游 Cordis(DeepSeek Harness 所基于的插件内核框架)与 deepseek-ai 项目贡献:该组织下 20 条 PR 里,已合并的仍是 FlashMLA 修复(#224,唯一一条),另有 16 条开放,其中 14 条是带复现的系统层修复。

本页所有实测数字只在英文部分维护一份(外部仓与合并数、千星仓、npm 名称与下载、laya 台账),中文这里不复述,以免两处走样;需要数字请看上方的 Upstream 一节,那里每个数字都带测量日期。

这一家子所依赖的那项研究,现在是一篇有 DOI 的论文 —— 而且它测的很大一部分,正是这份主页上的两个项目:laya-mcp 与 jevcore。《当判定层的自报字段说谎时:三类判断层的成本、延迟与失效边界实测》在一套相同条目上实测三类判定层(Laya、TypeSafe Jev、DeepSeek-V4.1-Flash),四条主张三条成立、一条被自己的数据否定;判定器的接入层自报字段不可信(截断标志报「通过」却静默丢输入、概率字段把结论反号、两个判定词在真实输入下不可达),失效集中在一处 —— 答案被明确陈述时近乎完美(0.9909,n=220),必须注意到「缺席」时塌缩(0.3091,n=220);异种判定器在三个区制上都没有增量覆盖。引其一即可,不要当两篇引(英文原文 · 中文译本 · 制品);两者有出入以英文为准。

laya(NandhaKishorM/laya)是这个账号投入最深的外部项目:提了 49 条 PR,其中 46 条已合并,合并数在该仓排第二;45 条集中在 2026-09-21 至 09-29 这九天里合掉。逐条清单与九个方向见上方英文部分折叠块,或直接看这个筛选列表。

还有一条在别处:一个根本起不来的进程现在能起来了。 claude-agent-acp #1146 让 src/index.ts 里那处没有保护的顶层 await 不再因一次瞬时错误就中断模块求值、在发出任何一条 ACP 消息之前退出。

斑海豹 Phocinae-Largha-150M-v1 (Phocinae org,Apache-2.0)是插件生态之外的另一条线:一个 144.3M 参数的结构化决策模型,不生成文本,一次前向输出判定与校准置信度;GPU 单次判定 p50 21.0ms(RTX 5090)、纯 CPU 约 1.64s,英文 typed-decisions 0.906(400 用例 / 2000 决策,2026-10-09 重测),中文(机译评测集)0.848;官方 en 0.906 / zh 0.848 与独立复现 0.9055 / 0.848 如实并排;τ=0.6 升级门实测让 55% 的 agent 决策留在本地(45.0% 升级、省 55.0% LLM 调用,τ=0.5 档 79.6%)、保留集准确率 0.906→0.9936。权重在 Hugging Face 与魔搭,配套 pip install phocinae-server 与 npm i dsh-phocinae;复现四件套(seed/行集/环境/脚本)随仓库发货。


This page is re-measured, not remembered. Every figure carries the date it was measured, and the round log records what each re-measurement corrected — including three claims of this page's own that did not survive. Round log · How every figure was measured.

Comments

Loading…

Similar plugins

dsh-polymarket-knowhow

by fashionmascherine-svg

DeepSeek Harness plugin (dsh-plugin): complete Polymarket superpowers — 31 verified tools across Gamma/CLOB/Data-API/Perps/RFQ/Bridge, embedded knowhow skill, live WebSocket stream. Read-only by defau

Tools & CapabilitiesManifest valid

★ 3

JavaScript

Aug 23, 2026

dsh plugin --profile web add dsh-polymarket-knowhow

by 863683348

Ecosystem-wide plugin health audit: syncs the dsh-plugin topic into a local scored catalog (maintenance / docs / npm + weekly downloads / ecosystem, 0-100, A-D), static security scan with high-finding

Tools & CapabilitiesTerminal & ClientsDevelopment & InfrastructureSecurity & AuditManifest valid

★ 1

↓ 546/wk

MIT

JavaScript

Sep 11, 2026

dsh plugin --profile web add dsh-audit

by ZSeven-W

DeepSeek Harness (DSH) plugin: a read-only ledger for the plugins you already have installed — a capability inventory with file:line evidence, declared-vs-detected reconciliation, cross-profile versio

Security & AuditManifest valid

★ 24

↓ 58/wk

MIT

JavaScript

Oct 10, 2026

dsh plugin --profile web add @zseven-w/dsh-harbor

by JD579g

DeepSeek Harness (DSH) plugin: one-click MCP deployment + built-in MCP toolkit + doctor. Windows-first, connects without restarting.

Manifest valid

★ 0

MIT

JavaScript

Sep 28, 2026

dsh plugin --profile web add dsh-mcp-hub

Preflight checks for a DeepSeek Harness plugin before submitting it to the community list: verifies the dsh.bundle manifest, cordis.patch.yml wiring, client bundle shape, and peer ranges that silently

Development & InfrastructureTools & CapabilitiesManifest valid

★ 0

dsh plugin --profile web add dsh-plugin-preflight

by PerryLink

Shared zero-runtime-dependency toolkit for PerryLink DSH plugins: a pluggable Provider registry seam, fail-closed approval and adaptive session-event gates, mechanical verify scripts, shared sanitize/

Development & InfrastructureManifest valid

★ 1

Apache-2.0

TypeScript

Sep 25, 2026

dsh plugin --profile web add @perrylink/dsh-plugin-kit