DSH Marketplace CLI — DeepSeek Harness plugins, built for coding agents

npm version downloads zero dependencies MIT LINUX DO

English · 简体中文

--- Find and install **DeepSeek Harness (DSH) plugins** from the command line. ```bash npx dshmarketplace-cli find memory npx dshmarketplace-cli add Anionex/dsh-vision-toolkit ``` No global install, no dependencies, no account. ## What this does [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) is DeepSeek's open-source agent harness, where every capability is a plugin. There are over a thousand community plugins spread across the `dsh-plugin` GitHub topic and the community registry, which makes finding the right one harder than installing it. This CLI searches the [dshmarketplace.dev](https://dshmarketplace.dev) catalogue, shows you what a plugin reaches before you run it, and hands DSH the correct install command — an npm tarball where the plugin publishes one, a pinned GitHub source otherwise. ## Commands ### `find ` Search by capability rather than product name. ```bash npx dshmarketplace-cli find memory npx dshmarketplace-cli find vision --limit 5 npx dshmarketplace-cli find terminal --category ui ``` ### `info ` Category, language, licence, source, detected risk flags, and every install route for one plugin. ```bash npx dshmarketplace-cli info Anionex/dsh-vision-toolkit ``` ### `add ` Resolves each plugin and runs one install through `dsh`. Accepts a repository name, an npm package name, or a mixture. ```bash npx dshmarketplace-cli add NanmiCoder/dsh-agent-teams npx dshmarketplace-cli add dsh-context dsh-mnemon @liustack/modsearch npx dshmarketplace-cli add some/plugin --dry-run --json ``` Several plugins go into a **single** `dsh plugin add a b c`, so pnpm resolves them together instead of once per plugin. Three things happen that pasting the command yourself does not do. **The profile is read off disk.** Every command the catalogue publishes says `--profile web`, because that is what a default install creates. On a machine whose profile is `tui`, that command succeeds and nothing appears. This reads `$DSH_HOME/profiles` and says which one it picked. **A plugin the sandbox could not install is dropped** before your machine is touched. Only `failed` and `timeout` count — `needs-approval` and `not-a-layer` both installed. `--force` overrides it. **A blocked build script is allowlisted and rebuilt.** pnpm refuses to run a dependency's build script until it is named in the profile's `onlyBuiltDependencies`, and until then the harness may never register the plugin — installed, and inert. The CLI reads what pnpm actually skipped, writes it into the profile's `pnpm-workspace.yaml` and reinstalls. `--no-approve` prints the edit instead of making it. | Option | Effect | | --- | --- | | `--limit ` | Results to show (`find`, default 10) | | `--category ` | Filter by category (`find`) | | `--source github` | Force the GitHub source over npm (`add`) | | `--profile ` | DSH profile to install into (`add`, default: detected) | | `--no-approve` | Report blocked build scripts instead of allowlisting them | | `--force` | Install even where the sandbox recorded a failure | | `--dry-run` | Print the command without running it (`add`) | | `--json` | Machine-readable output, stable schema (all commands) | ### `preset [id]` Curated sets. With no id, lists them; with one, installs the whole set. ```bash npx dshmarketplace-cli preset npx dshmarketplace-cli preset essentials ``` A set is a different claim from a listing. Each listing's verdict comes from installing *that plugin* into an empty profile; a set has to survive its members being installed **together**, which fails in ways the parts do not — incompatible peers, a build script blocked only once another plugin drags in its owner, and cordis refusing a duplicate loader entry id so a plugin installs, reports success and is never registered. So every set carries the date, verdict and the `dsh` and `pnpm` versions of the sandbox run that installed the whole list as one command, and the CLI prints them before it touches anything. Installing a preset goes through the same path as `add`, so it inherits profile detection, the pre-flight and the build-script allowlist. ## Requirements Node 18 or newer, and DeepSeek Harness on your PATH: ```bash npx @deepseek-ai/dsh web ``` ## For coding agents Every command accepts `--json` and emits `{ ok, command, version, ... }`. Resolving an install without executing it is a first-class path: ```bash npx dshmarketplace-cli add --dry-run --json ``` The response carries the exact command that would run, the source repository and any detected risk flags, so the decision to execute stays with the caller. A `SKILL.md` ships inside the package, so agents that read skills route here instead of recalling a plugin name from training data — for an ecosystem this young, a remembered name is usually wrong. ## Safety Plugins are third-party code and run with your agent's permissions. Being listed in this catalogue is **not** a security review. Where they are detectable, listings flag install scripts, terminal surfaces and credential prompts, and `add` prints them before running anything. The source repository is always shown. Read it. Two things make an install fail, and neither is your mistake: - **`--profile` is mandatory.** `dsh plugin` forwards to pnpm inside a profile directory, so without it `dsh` exits without installing anything. Every command this CLI prints already carries it. - **GitHub sources need a build allowlist.** pnpm blocks a git-hosted package's build script until the key it prints is added under `allowBuilds` in the profile's `pnpm-workspace.yaml`. Plugins published to npm install with no extra step, which is why npm is offered first. ## Configuration | Variable | Purpose | | --- | --- | | `DSHM_API` | Point the CLI at a different catalogue endpoint | ## Links - Catalogue — - In-DSH plugin — [`dshmarketplace-plugin`](https://github.com/DshMarketPlace/dsh-plugins-store) - DeepSeek Harness — - `dsh-plugin` topic — ## Contact - **Community** — [LINUX DO](https://linux.do) - **Issues** — [GitHub Issues](https://github.com/DshMarketPlace/dshmarketplace-cli/issues) ## Acknowledgements - [**LINUX DO**](https://linux.do) — where the DSH ecosystem is actually being discussed, and where this project is published and takes its feedback. Plugins whose authors posted them there carry a verified badge in the catalogue. - [awesome-dsh-plugin](https://github.com/awesome-dsh-plugin/awesome-dsh-plugin) (CC0-1.0) — the community registry the catalogue is seeded from. ## License MIT. Independent project, not affiliated with DeepSeek. DeepSeek and DeepSeek Harness are marks of their respective owner, used here only to describe what these plugins are for.