Jinsong-Zhou / safe-find-dsh-plugins

已收录

Discover and install the best DeepSeek Harness plugins for a user's task

main技能 查看源代码

安装

npx -y @deepseek-ai/dsh plugin --profile web add github:Jinsong-Zhou/safe-find-dsh-plugins

此安装命令根据 GitHub 仓库地址生成,是未经验证的安装起点。

README

维护者编写的文档快照。

在 GitHub 查看 ↗
提交版本 2456180同步于 2026年8月18日

safe-find-dsh-plugins

简体中文 | English

A DSH plugin that finds plugins for your task across the entire GitHub dsh-plugin topic, with a security scan before anything gets installed.

Install

Send this repository link to DSH and say "install this plugin for me".

To install manually, copy the whole skills/safe-find-dsh-plugins/ directory into $DSH_HOME/skills/, or into <project-root>/.agents/skills/ for one project only. Once it's in place it just works — no other configuration.

What it does

Given your request, it first pulls every public repository under the topic (skipping archives and forks), ranks them against what you asked for, takes a close look at only the best few, works out how each one is meant to be installed, and hands you a shortlist of at most three candidates.

After you pick one, it doesn't install right away: it pins the candidate's exact commit, then runs a static security scan over that source — plugin code is never executed. A clean scan moves ahead; if risks turn up, every finding is laid out for you and the decision is yours; high-risk results, failed scans, or a missing scanner never install. What ends up in your environment is always the exact commit that was scanned — and this step is never skipped, even when you named the plugin yourself from the start.

The scanner is a separate dependency. Before installing a plugin for you the first time, it checks whether the scanner is present and hands you the install command if not.

Acknowledgements

License

MIT © 2026 Jinsong Zhou. See LICENSE.

仓库信息

开发语言
JavaScript
许可证
MIT
最后更新
2026年8月13日 23:36

谨慎安装

请检查源代码、权限、生命周期脚本、依赖与网络访问;不受信任的插件应先在隔离环境中测试。