Nico0713520 / dsh-plugin-guardian

Listed

Read-only plugin doctor for DeepSeek Harness — diagnose before you install, scan cross-plugin conflicts, promote ephemeral plugins to durable assets.

mainOther View source

Installation

npx -y @deepseek-ai/dsh plugin --profile web add github:Nico0713520/dsh-plugin-guardian

This installation command is an unverified starting point generated from the GitHub repository address.

README

Maintainer-authored documentation snapshot.

View on GitHub ↗
Commit da8a81eSynced Aug 18, 2026

dsh-plugin-guardian

Your DeepSeek Harness plugin's whole life — diagnose before you install, promote after you build.

CI License: MIT dsh-plugin

English · 中文

5,905 plugins and counting. Some of them fight each other. Install a skin and another plugin silently breaks. Two plugins register the same tool name and the harness crashes at startup. Your agent writes a plugin in Creator mode and it vanishes on restart.

This plugin makes all of that visible — and fixable — before it bites you.

Why you need it

DeepSeek Harness is "everything is a plugin", and the ecosystem exploded to thousands of plugins within a week. But nobody is keeping watch:

PainWhat actually happensWhat guardian does
"I installed a skin and now X is broken"Plugins silently collideplugin_profile_scan finds tool-name collisions
Two plugins register the same toolHarness crashes at startup (see Pi #7696)Conflict detected before you ship
"Is this random npm plugin safe?"No trust system existsplugin_doctor checks it, with honest confidence tiers
"The plugin my agent just wrote is gone"Creator-mode plugins live only in memoryplugin_promote promotes it to durable disk

Four tools, one lifecycle

陌生/临时插件  →  plugin_doctor 体检  →  通过门禁  →  plugin_promote 转正  →  可信磁盘插件
                        │
                 plugin_profile_scan 扫已装集冲突
                        │
                 plugin_install 引导安装(先审计→再执行)
ToolWhat it doesAnalogy
plugin_doctorHealth-check a single plugin directory门诊 checkup
plugin_profile_scanScan the installed set for cross-plugin conflicts体检 center
plugin_promoteTurn an ephemeral plugin into a durable, versioned asset落户 registration
plugin_installGuided install: audit first, then execute一键安装 one-click install

What makes it honest: three-tier confidence

Every finding is tagged with a confidence tier — borrowed from Pi's pi-extension-doctor:

TierMeaning
confirmedProvable from the files we read (e.g. a missing field)
inferredA static pattern was seen — not proof of runtime behavior
unknownA boundary (remote spec, unreadable file) blocked a conclusion

No fake precision. A static scan result is labeled "inferred", never "definitely a bug".

30-second start

dsh plugin --profile web add github:Nico0713520/dsh-plugin-guardian
# restart dsh web, then ask in a session:
plugin_doctor target="/path/to/my-plugin"
plugin_profile_scan
plugin_promote source="/path/to/my-plugin"
plugin_install spec="npm:some-plugin"      # audit-only by default
plugin_install spec="npm:some-plugin" approve=true

Demo

plugin_doctor against a real DSH plugin:

DSH plugin doctor
target : /path/to/dsh-gh-cli
verdict: WARN  (0 blocker · 1 warn · 3 info)

[info] confirmed — cordis patch file present
[warn] confirmed — Pre-release peer dependencies (9)   → 建议锁版本
[info] inferred  — Spawns subprocesses
[info] inferred  — Detected 2 possible tool name(s): gh_cli_run, gh_auth_status

plugin_promote:

DSH plugin promote
status : PROMOTED
name   : dsh-gh-cli@0.1.0
sha256 : 6cf15989…
install: dsh plugin --profile web add link:…/.guardian-plugins/dsh-gh-cli-6cf15989

Safety boundary

  • plugin_doctor and plugin_profile_scan are read-only. They never install packages, execute source, spawn subprocesses, hit the network, or write a file.
  • plugin_promote writes only to a managed staging directory ($DSH_HOME/.guardian-plugins) with a provenance marker (sha256 / promotedAt / source). It never touches your live profile unless you pass register=true.

Tools

ToolParametersNotes
plugin_doctortarget (path or npm:/github: spec), format (text/json)Three-tier confidence report
plugin_profile_scanprofileDir (defaults to $DSH_HOME/profiles/web)Finds tool-name collisions, dupes, version skew
plugin_promotesource, register (default false), profile, outputDirDoctor-gated, atomic, provenance-marked
plugin_installspec, approve (default false), profileAudit-first guided install; approve=true runs dsh plugin add

FAQ

Is this the same as dsh-plugin-check? — Overlapping but different. plugin-check does 33 read-only checks on a single plugin. guardian adds three things it doesn't: confidence tiers, cross-plugin conflict scanning, and promote (转正) — the last of which is entirely absent from the ecosystem.

Will plugin_promote modify my profile by surprise? — No. It defaults to register=false; it only stages the plugin and prints the exact dsh plugin add command. You opt in to registration explicitly.

What's the Pi reference? — Pi's pi-extension-doctor established the confirmed/inferred/unknown confidence model and a strict read-only boundary. guardian applies the same discipline to DSH's much larger, messier ecosystem.

Development

git clone https://github.com/Nico0713520/dsh-plugin-guardian.git
cd dsh-plugin-guardian
npm install --legacy-peer-deps
npm run typecheck
npm run test
npm run build

Requirements

  • Node.js ≥ 20
  • DeepSeek Harness (@deepseek-ai/dsh, verified on 0.1.0-rc.x)

License

MIT — see LICENSE.

Project files and signals

Shown items are public repository signals detected in the directory snapshot.

Contributing guideDetected
ExamplesDetected

Repository information

Language
TypeScript
License
MIT
Latest release
v0.1.0
Last updated
Aug 17, 2026, 5:12 PM

Install deliberately

Review source code, permissions, lifecycle hooks, dependencies and network access. Test untrusted plugins in an isolated environment.