DSH Plugins Marketplace

DSH Plugins

Plugins

/

Development & Infrastructure

/

dsh-stack

w

dsh-stack

Manifest valid

Reproducible DeepSeek Harness environments in one portable, secret-safe Stackfile.

hasBundlePatch

dsh-stack — Ship the environment, not the setup guide

dsh-stack

Make agent environments reproducible.
Capture an entire DeepSeek Harness profile—plugins, order, versions, and portable configuration—in one reviewable Stackfile.

CI DeepSeek Harness 0.1.0-rc.6 Node.js 22.19+ MIT license

中文 · English


A plugin list is not an environment

A working Harness profile depends on more than the packages it contains. Bundle order changes composition. Version drift changes behavior. The profile patch carries the configuration that made the setup useful in the first place.

dsh-stack captures that complete contract:

  • ordered plugin bundles;
  • exact installed registry versions and commit-pinned Git sources;
  • the profile-level Cordis patch, with local paths made portable;
  • secret references instead of credential values;
  • source Harness version and whole-file SHA-256 integrity.

The result is a small JSON Stackfile that can live beside a project, release, benchmark, team handbook, or bug report. Anyone can inspect it before allowing it to touch a profile.

From working profile to verified replica

Install, export, inspect, plan, apply, and verify a dsh-stack profile

# Machine A — capture the environment that already works
dsh-stack export --profile web --name "research-workbench"

# Machine B — inspect before trusting
dsh-stack inspect web.dsh-stack.json
dsh-stack plan web.dsh-stack.json --profile research

# Reproduce, then verify through Harness itself
dsh-stack apply web.dsh-stack.json --profile research --yes

apply does not stop at installing packages. It writes the declared bundle order, hydrates portable configuration, and asks dsh --dump-config to verify the final composition. If verification fails, the profile files are restored from backup.

Stackfiles may also be loaded directly over HTTPS:

dsh-stack plan https://example.com/research.dsh-stack.json --profile research

Install

Install the CLI and add the bundle to a Harness profile:

npm install --global dsh-stack
dsh plugin --profile web add dsh-stack

The package contains prebuilt JavaScript and has no install-time lifecycle script.

Try the published example without cloning this repository:

dsh-stack inspect https://raw.githubusercontent.com/weivwang/dsh-stack/main/examples/web.dsh-stack.json
dsh-stack plan https://raw.githubusercontent.com/weivwang/dsh-stack/main/examples/web.dsh-stack.json --profile web-copy

To install from source instead, clone the repository, run pnpm install --ignore-scripts && pnpm run build, then use npm link and dsh plugin --profile web add "$PWD".

Review first, mutate second

The read path and write path have deliberately different authority:

CommandWrites to a profilePurpose
dsh-stack inspectNoValidate integrity and explain a local or HTTPS Stackfile
dsh-stack planNoCompare the desired stack with a target profile
dsh-stack exportNoCapture an installed profile into a new file
dsh-stack applyYesApply a reviewed plan with locking, backup, verification, and rollback

Before mutation, apply:

  1. validates a closed schema and the whole-file digest;
  2. rejects unsafe package specifiers, local paths, mutable sources, and embedded URL credentials;
  3. prints the exact install, update, ordering, patch, and secret plan;
  4. requires --yes;
  5. requires a second explicit choice before replacing a different non-empty patch.

It never removes target-only plugins. Existing bundles not named by the Stackfile remain after its declared layers.

Secrets stay out of the file

The exporter parses cordis.patch.yml as data and never evaluates !!js. Common credential fields and recognizable token literals become environment-backed placeholders:

apiKey: "{{DSH_STACK_SECRET:API_KEY}}"
cacheDir: "{{DSH_HOME}}/cache"
workspace: "{{HOME}}/code"

inspect lists every required variable. Supply the values only on the receiving machine:

export DSH_STACK_SECRET_API_KEY='...'
dsh-stack apply team.dsh-stack.json --profile web --yes

Automatic detection is defense in depth, not proof that arbitrary configuration is secret-free. Inspect a Stackfile before publishing it, and prefer managed credentials or environment references so raw secrets never enter the profile patch.

What crosses the boundary

IncludedDeliberately excluded
Ordered dsh.profile.bundlesSession history
Exact package versionsCredentials and .env files
Profile-level cordis.patch.ymlGlobal $DSH_HOME/cordis.patch.yml
Portable home-path placeholdersWorkspace files and arbitrary skills
Harness version and integrity digestMachine-wide state

A Stackfile is an environment declaration, not a backup archive.

Harness tool

Installing the bundle registers one read-only model tool: stack_inspect.

  • summary returns bundle counts, portability score, required secrets, and warnings.
  • stack returns the complete integrity-sealed, secret-redacted JSON.

The tool itself never writes a Stackfile. Saving the returned JSON remains subject to Harness's ordinary file permissions.

Compatibility and development

The first release targets DeepSeek Harness 0.1.0-rc.6 and Node.js ^22.19.0 || >=24. Harness is in developer preview; each Stackfile records its source version and warns when the target differs.

pnpm install --ignore-scripts
pnpm run check

The checked-in lib/ directory is the installable artifact. CI runs type checking, 18 tests, a production build, and package inspection across Linux, macOS, and Windows on Node 22.19 and 24.

Read the format and mutation design or the security policy.

MIT

Comments

Loading…

From the same category

awesome-dsh-plugin

by awesome-dsh-plugin

A curated list of plugins for DeepSeek Harness (dsh) · DeepSeek Harness 插件精选列表

Development & Infrastructure

★ 17.7k

CC0-1.0

Python

Oct 1, 2026

Index only — not installable

by 0xsline

DeepSeek Harness (DSH) ecosystem: curated plugins, tools, and infrastructure from dsh-external/hub and the public dsh-plugin topic.

Development & Infrastructure

★ 1.1k

CC0-1.0

Python

Sep 30, 2026

Index only — not installable

by pax-beehive

Open-source CLI, schemas, resolver, and DSH agent tools for DSH Plugin Hub

Development & Infrastructure

★ 457

MIT

TypeScript

Sep 22, 2026

Index only — not installable

by yjh051108

推荐组件(非必须):DeepSeek Harness 运行时注入器;已随 dsh-routing-suite 单仓库化保留,本仓库继续维护/发布。

Development & InfrastructureManifest valid

★ 167

TypeScript

Sep 18, 2026

dsh plugin --profile web add @dsh-external/dsh-super-injector

by xiajiajun516

DeepSeek Harness (DSH) backup & restore plugin — export, import, migrate and sync your complete DSH configuration, plugins, MCP servers, skills and workspace. One-click migration to another machine.

Development & InfrastructureManifest valid

★ 148

MIT

TypeScript

Sep 30, 2026

dsh plugin --profile web add dsh-config-manager

by jigjoy-ai

A CLI that turns a goal into a pull request - and a sandbox for testing concurrent AI coding agents on the Mozaik runtime.

Development & Infrastructure

★ 124

MIT

TypeScript

Oct 2, 2026

Index only — not installable