설치
npx -y @deepseek-ai/dsh plugin --profile web add github:Jinsong-Zhou/safe-find-dsh-plugins이 설치 명령은 GitHub 저장소 주소에서 생성된 확인되지 않은 시작점입니다.
README
유지 관리자가 작성한 문서 스냅샷입니다.
safe-find-dsh-plugins
简体中文 | English
A DSH plugin that finds plugins for your task across the entire GitHub
dsh-plugin topic, with a security
scan before anything gets installed.
Install
Send this repository link to DSH and say "install this plugin for me".
To install manually, copy the whole skills/safe-find-dsh-plugins/ directory
into $DSH_HOME/skills/, or into <project-root>/.agents/skills/ for one
project only. Once it's in place it just works — no other configuration.
What it does
Given your request, it first pulls every public repository under the topic (skipping archives and forks), ranks them against what you asked for, takes a close look at only the best few, works out how each one is meant to be installed, and hands you a shortlist of at most three candidates.
After you pick one, it doesn't install right away: it pins the candidate's exact commit, then runs a static security scan over that source — plugin code is never executed. A clean scan moves ahead; if risks turn up, every finding is laid out for you and the decision is yours; high-risk results, failed scans, or a missing scanner never install. What ends up in your environment is always the exact commit that was scanned — and this step is never skipped, even when you named the plugin yourself from the start.
The scanner is a separate dependency. Before installing a plugin for you the first time, it checks whether the scanner is present and hands you the install command if not.
Acknowledgements
- Forked from Nagi-ovo/dsh-find-plugins.
- Security scanning is powered by
NVIDIA SkillSpector:
uv tool install git+https://github.com/NVIDIA/skillspector.git.
License
MIT © 2026 Jinsong Zhou. See LICENSE.
저장소 정보
- 언어
- JavaScript
- 라이선스
- MIT
- 마지막 업데이트
- 2026. 8. 13. 오후 11:36
신중하게 설치하기
소스 코드, 권한, 수명 주기 스크립트, 의존성 및 네트워크 접근을 검토하고 신뢰하지 않는 플러그인은 격리 환경에서 테스트하세요.