New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

aiko-dsh-market

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

aiko-dsh-market

Visual plugin market inside DeepSeek Harness — browse, search, and one-click install community plugins. · DSH 可视化插件市场:逛一逛,点一下,装好。

latest
npmnpm
Version
1.39.0
Version published
Weekly downloads
62
77.14%
Maintainers
1
Weekly downloads
 
Created
Source

dsh-market logo

dsh-market

English | 中文

npm stars

The plugin market inside DeepSeek Harness. Open Settings → Plugin Market → browse, search, one-click install.

dsh-market

One-click themes: install, switch live, no restart.

npm distribution

Install aiko-dsh-market@1.39.0 through the native plugin manager. The npm package, Bundle patch and client loader all use aiko-dsh-market; dsh-market remains the configuration id. The npm directory lists package names; each plugin supplies its version, compatibility, bilingual help and raster previews. additionalRegistryPackages configures required npm catalogs; additionalRegistryUrls remains available for HTTP catalogs. See installation, source migration and publishing.

GitHub community discovery

The Aiko Bundle enables the organization catalog’s github-topic.json feed. Web and Desktop display GitHub discoveries alongside curated plugins, with source attribution, package-check dates, collection progress and feed timestamps. A static package check is not official certification, a security audit or a host compatibility test.

Only discoveries with a checked npm package or a same-repository GitHub Release archive can be installed. npm installs pin the checked version. Source-only bundles remain browsable. Curated repository URLs, names and npm identities take precedence over discoveries.

Configure optional feeds with discoveryRegistryUrls; use [] to disable them. Required additionalRegistryUrls retain their existing failure behavior. An optional feed failure is shown separately and does not disable required catalogs. Refresh retries it; failed feeds do not contribute cached discoveries. Custom compositions that omit the setting remain unchanged.

The collector runs in aiko-dsh-plugins/dsh-plugin-catalog, so clients need no GitHub token. Publish the feed and collector workflow before releasing the market bundle that enables its URL. See the feed protocol and checks.

Official Electron (1.39.0)

This candidate requires the desktop market bridge v1 on the official DSH 0.1.5-alpha.2 desktop. The bridge is an accompanying host change, not an API in the unmodified official release. Install the published market tarball through the desktop's plugin manager, then open Settings → Plugin Market. Source-development profiles do not support installation.

The desktop market reads community and Aiko organization catalogs through Connection Fetch. It installs dependency-ordered packages in one desktop-owned transaction, with a native confirmation showing the exact npm specifications or GitHub release URLs. Failed activation restores the previous profile; packages required by another installed plugin cannot be removed. Workspaces and local package paths are not installation sources.

An update is offered only for a newer catalog version from the installed distribution source: the same npm package or the same GitHub Release repository. Identical release URLs need no reinstall, even without version metadata; unknown versions do not imply an update. The Installed view matches the source as well as the package name; installed sources absent from the catalog are listed separately. Proposals recheck the current inventory, reject source changes including dependency changes, skip satisfied dependencies, and pin npm versions when the catalog provides them.

The desktop lists exclude aiko-dsh-market and every dshmarket distribution, including the upstream and Aiko records, from browsing, search, counts, and Installed. The header retains the installed market version and repository link. The desktop's native plugin manager remains the place to update, remove, or reinstall the market from the Aiko release source; other plugins remain visible and manageable in the market.

The desktop view uses the upstream catalog search and ranking rules, with Discover, Themes, and Installed tabs, category and publication-date filters, and 24 entries per page by default. Cards show author avatars, stars, npm downloads, category labels, curated screenshots, dependencies, and deprecation notices. Details retain the release date, original catalog command, and published/installed sources. Packaged READMEs open inside the market; public product and feedback links use the catalog presentation addresses. Missing download counts remain absent, and source-only entries explain why Desktop cannot install them. Web-only backup and live theme switching are not available in this view.

Reopening the market immediately displays the previous catalog while a fresh request revalidates every required source. Refreshing and failed-refresh states are explicit, and installation waits for a confirmed catalog. Concurrent readers share one request. Catalog dependency validation visits each plugin and dependency once; pagination and lazy images bound the rendering work without truncating the searchable catalog.

An HTTP(S) proxy origin can be saved as dsh-market-network.httpsProxy in the host's settings.yaml; restart the host to apply it. This setting survives desktop package updates and affects only the market's outbound requests. The dispatcher's connections drain when the plugin stops. An explicit plugin configuration httpsProxy takes precedence; without either setting, the existing proxy environment behavior applies. The Web host branch remains separate and requires the DSH 0.1.5 settings API when that optional service is present.

Web Install

dsh plugin --profile web add aiko-dsh-market@1.39.0

Restart dsh web, then open Settings → Plugin Market.

This release declares compatibility with Aiko DSH 0.1.5-alpha.2. Keep earlier Aiko market releases for older Web hosts that still expose the pre-0.1.5 settings API.

What you get

  • Browse & search the full community catalog (2300+ plugins, growing daily) — category filters, star counts, top/new sorting, bilingual descriptions that follow your UI language

  • Screenshots — AppStore-style screenshots, auto-carousel when there's more than one, click to preview full-size: author-curated shots show right on the card (zero extra requests); plugins without curated shots fall back to automatic README extraction once you open the install dialog. Aiko screenshots are embedded in the npm catalog; other entries retain the allowed GitHub image sources

  • Comments — every card opens the plugin's discussion thread in place. It is the same thread its pages on dshmarket.com and the catalog show, so a plugin has one conversation rather than three. Backed by GitHub Discussions through giscus: it loads when you open it, needs a GitHub account only to post, and the note above it says plainly that opening it contacts giscus.app and GitHub

  • Themes — a dedicated tab for community themes and skins: install → active immediately, switch with one click (themes are mutually exclusive, your choice survives restarts), uninstall to revert

  • One-click install — confirm the source, watch live progress; most plugins go live after a page refresh, no restart

  • Backup & restore — export your profile's plugin list and configuration as readable JSON, import it on another machine, store it on WebDAV with daily auto-backup, or sync through a private GitHub Gist; restores merge (plugins installed after the backup are kept), validate before writing, and roll back on failure

  • Updates — per-plugin update checks (npm version or pinned commit vs HEAD), one-click update, or update everything at once; the market updates itself the same way

  • Public update API — plugin-owned settings pages can use the versioned, capability-gated update API v1 (beta) instead of copying package-manager logic or depending on private Market UI responses

  • Uninstall — two-step confirm; plugins installed this session are removed live

  • Hot disable / enable — toggles write - id: … + disabled: true|false into the profile's cordis.patch.yml (the official patch layer, mechanism ported from dsh-plugin-hub): DSH's HMR re-composes within ~1s, no restart, and the loader re-applies the choice on every boot; hand-edited patch rows show as badges, host-infrastructure plugins are protected from toggling, and a malformed patch file is never made worse

  • Restart when needed — changes that cannot hot-load show a one-click restart beside the pending-change banner; the action is restricted to same-origin loopback requests

  • Zero jargon — if a component is missing (pnpm), the market detects it and offers a one-click automatic setup

  • Log export — one click produces a sanitized plain-text log for bug reports (home paths and credential shapes are masked; nothing is ever sent anywhere). The market's version sits next to the page heading, so a screenshot of a problem already carries it

  • Settings card — on dsh 0.1.0-rc.7 and newer the market manages itself from Settings → Plugins → Plugin configuration, next to every other plugin: see the running version, pick a release channel (stable, or beta to try builds still being verified — the market only, never your other plugins; a third dev channel appears once developer mode is switched on, and carries builds published straight off a branch), update, or remove the market — with an opt-in cleanup that also drops the disable rows it wrote, so plugins it switched off start running again rather than staying off with no UI left to switch them back on

  • Diagnostics — the plugin load order and conflict surface, one page: bundle stack with official/community badges, duplicate loader entries, dependency version mismatches, multi-version core packages, overrides and invalid config entries. Plain-language terms, problem blocks highlighted, everything collapsible

  • Load order — drag community bundles into the order you want, or take the suggested one derived from the plugins' own before/after rules. Nothing is written until a trial composition passes, and the panel tells you what the new order would change (overrides, invalid or duplicate entries) before you apply it

  • AI fix — one click copies a diagnostics-driven fix prompt (errors/warnings/order conflicts + conservative scope instructions) to the clipboard; you paste it into a new conversation and decide whether to send. The prompt first asks the agent to detect whether it is itself the harness running this profile — if so it hard-forbids mutating the live composition, upgrading/restarting the harness or core packages, or reinstalling deps, and instead has it write an idempotent apply script plus a rollback script, have you run them in an external terminal, and paste the output back

Speed

Installs prefer repo-verified npm packages, then author-supplied prebuilt GitHub Release tarballs, before falling back to full-repo GitHub source downloads. Prebuilt installs are typically seconds and do not need local build scripts; source-only plugins depend on your connection to GitHub.

Security

  • Installs are restricted to targets in the loaded catalogs. GitHub discovery entries additionally require a checked release package; source-only entries cannot be installed.

  • Build scripts stay blocked by default (pnpm ≥10); allowing one is your explicit per-package choice

  • Terminal/CLI-surface plugins are flagged before you install them into the web profile

  • The install endpoint accepts same-origin POST only; the market never phones home

  • Backups can contain credentials from your profile config — the UI warns before export and upload; WebDAV sync is https-only, refuses private-network targets, and never stores your password in the browser

  • The restart endpoint additionally requires a direct loopback client (forwarded requests are rejected) and relaunches the exact DSH entry, arguments, environment, and working directory

  • One-click restart launches a detached replacement. When this host is systemd's own service process the button is hidden automatically — the market would otherwise kill the takeover process along with the unit's cgroup and the service would not come back. The pending-change notice stays visible and says so. Detection requires both a systemd marker AND being the unit's main process, because INVOCATION_ID is inherited by every descendant of a unit (an ordinary terminal included) and hiding the button for those would be the worse bug. pm2 and launchd are not detected, so those deployments need the explicit setting below. Either flip Allow restart off in Settings → Plugins → Plugin configuration, or write it into the profile patch — where it has to sit under config:, because the loader passes only that sub-object to a plugin and a top-level allowRestart: is silently ignored (#227 by @Fantasymax):

    - id: dsh-market
      name: aiko-dsh-market
      config:
        allowRestart: false   # NOT at the top level beside `name:`
    

    GET /dsh-market/status reports "restart": false once it has taken effect.

  • For terminal-attached launches, the detached replacement keeps running after the original terminal closes

  • Listing ≠ endorsement: plugins are third-party code, install sources you trust

Submit your plugin

This repo contains the market app. Submit curated entries to awesome-dsh-plugin. Repositories tagged dsh-plugin on GitHub are also candidates for the optional community discovery feed; collection and package checks determine their visibility and installation status. Please submit plugin entries to a catalog rather than this application repository.

Roadmap & feedback

  • Bugs go in issues — attaching the market's "Export log" makes diagnosis roughly ten times faster
  • Feature ideas go on the Roadmap. Issues are kept for things that are broken, so a proposal filed as an issue gets moved there and closed; the discussion stays where you wrote it either way
  • Every roadmap item welcomes community PRs — say so on the item before starting, so two people don't build it twice

Data source

Fetched live on every open from awesome-dsh-plugin.com/plugins.json — curated entries, npm mapping, and star counts refreshed daily by CI, with no stale cache behind it. A failure reports the actual reason and elapsed time, with a Retry button.

There is deliberately no bundled snapshot to fall back on: for a catalog that grows daily, a stale answer is not a degraded one but a wrong one — a plugin published this morning would read as "does not exist".

If that host is unreachable from your network, point the market at a mirror instead. Set DSHM_REGISTRY_URL in the environment dsh runs in, to anything serving the same plugins.json shape:

DSHM_REGISTRY_URL=https://your-mirror.example/plugins.json dsh web

To keep the official catalog and add required organization catalogs, configure the market bundle instead. Catalogs are merged by repository URL; later entries may replace metadata for the same repository, while duplicate names pointing to different repositories are rejected:

- id: dsh-market
  name: aiko-dsh-market
  config:
    additionalRegistryUrls:
      - https://raw.githubusercontent.com/your-org/dsh-plugin-catalog/main/plugins.json

Organization catalogs may declare requires as repository URLs of other catalog entries. The market installs those dependencies before the selected plugin, shows them on the plugin card, and prevents removal while an installed plugin still depends on them.

Friends

DSH Desktop (dataelement)

dsh-desktop — a desktop app for DeepSeek Harness: run and manage a local Harness without installing Node.js yourself. Ships with this plugin market preset as the default. dshdesktop.com

DeepSeek Harness Desktop (hairyf)

deepseek-harness-desktop — a native desktop app for DeepSeek Harness built with Tauri (Rust + Web): one-click local install and launch with no Node.js setup required. On first run it offers to install this plugin market as a recommended preset.

DeepSeek Harness Desktop (anywhere-labs)

deepseek-harness-desktop — an Electron desktop app for DeepSeek Harness built around the idea that everything is a plugin, including the desktop itself: profile switching, a bundled Node and pnpm, and a recoverable install path that snapshots the profile before a change. dshdesktop.cn

DSH App

dsh-app — a DeepSeek Harness desktop client built on Tauri 2 rather than Electron, so it ships a much smaller binary and uses the system webview. AGPL-3.0.

Local DSH

local-dsh — a DeepSeek Harness desktop client that can run the model on your own machine: it bundles llama.cpp next to Node, pnpm and DSH, so a downloaded GGUF model answers without any external API. Built on Tauri; Apple Silicon Macs for now. localdsh.com

DSH Get

DSH Get — a searchable web directory for discovering DeepSeek Harness plugins: category filters, bilingual descriptions, install commands and per-plugin detail pages. Its normalized catalog snapshot is public at bobby-sheng/dshget-data.

modlens

modlens — the first vision plugin for DeepSeek Harness: bolts visual understanding onto text-only models like DeepSeek and GLM. Paste an image, get structured JSON evidence back — OCR, layout, semantics. Available right in this market:

dsh plugin --profile web add @liustack/modlens

Aiko Distribution

Active Aiko development lives in the private aiko-dsh-plugins/dsh-market-source repository. Public npm distributes plugin artifacts and catalog content. New packages include runtime JavaScript and declarations, without TypeScript source or source maps; runtime JavaScript remains inspectable. Publish checked artifacts to npm and keep private source commits in the private repository.

License

MIT · dshmarket.com

Keywords

deepseek

FAQs

Package last updated on 13 Sep 2026

Related posts