Awesome DSH Plugins
August 29, 2026 · View on GitHub

Awesome DSH Plugins
Discover installable DeepSeek Harness plugins, inspect the evidence behind each listing, and explore the 2Origin plugin lab.
中文 · Official DeepSeek Harness · Browse verified bundles · Search from the terminal · 2Origin plugin lab
Start here
| I want to… | Go to |
|---|---|
| Find an installable DSH profile bundle | Radar |
| Estimate the work needed to port an Agent Skill | Capability Port Score |
| Search plugins offline from a terminal | CLI search |
| Inspect plugins with reproducible runtime evidence | Runtime compatibility layer |
| Explore evidence-first plugins built in this lab | 2Origin plugin lab |
Normal CLI searches use the committed snapshot and need no GitHub token:
npx github:dongsheng123132/awesome-dsh-plugins search memory
This repository deliberately distinguishes a repository that mentions DSH from an installable DSH profile bundle. A plugin receives the Verified Bundle mark only when the scanner finds both:
- a
package.jsondeclaration atdsh.bundle.patch; and - the declared patch file in the same Git tree.
This is structural verification, not a security audit or a promise that the plugin works with today's DSH main branch. Categories are heuristic navigation aids; manifest and patch evidence, not the category label, determines verification.
Radar
1098 verified bundles / 1003 topic repositories examined / 11490 reported by GitHub
Other: 329 · UI / TUI: 225 · Token & Cost: 68 · Browser: 67 · MCP Bridge: 63 · Security: 61 · Memory: 55 · Model & Routing: 54 · Coding: 34 · Office: 32 · Developer Tools: 28 · Finance: 28 · Long-running: 22 · Writing / Novel: 19 · Research: 12 · Provenance & Lineage: 1
| Plugin | Category | Stars | License | Evidence | Install |
|---|---|---|---|---|---|
| @open-design/dsh-runtime nexu-io/open-design | Office | 91246 | Apache-2.0 | packages/dsh-runtime/package.json → packages/dsh-runtime/cordis.patch.yml | See package docs |
| dsh-plugin-reactive-resume amruthpillai/reactive-resume | MCP Bridge | 41696 | MIT | packages/dsh-plugin/package.json → packages/dsh-plugin/cordis.patch.yml | See package docs |
| @openviking/dsh-memory-plugin volcengine/OpenViking | Memory | 33116 | AGPL-3.0 | examples/dsh-memory-plugin/package.json → examples/dsh-memory-plugin/cordis.patch.yml | See package docs |
| @wxg-prc-cpg/dsh-weknora Tencent/WeKnora | Office | 20577 | NOASSERTION | packages/dsh-weknora/package.json → packages/dsh-weknora/cordis.patch.yml | See package docs |
| dsh-plugin-desktop anywhere-labs/dsh-desktop | Other | 19998 | MIT | dsh-plugin-desktop/package.json → dsh-plugin-desktop/cordis.patch.yml | See package docs |
| @tt-a1i/archify-dsh tt-a1i/archify | Long-running | 15658 | MIT | integrations/deepseek-harness/package.json → integrations/deepseek-harness/cordis.patch.yml | See package docs |
| @memtensor/memos-local-plugin MemTensor/MemOS | Token & Cost | 10966 | Apache-2.0 | apps/memos-local-plugin/package.json → apps/memos-local-plugin/adapters/deepseek-harness/cordis.patch.yml | See package docs |
| @dsh-external/dsh-super-injector yjh051108/dsh-routing-suite | Model & Routing | 6777 | MIT | injector/package.json → injector/cordis.patch.yml | See package docs |
| @dsh-web/files zhu1090093659/dsh-web | Browser | 6005 | Apache-2.0 | market/shell/packages/dsh-web-files/package.json → market/shell/packages/dsh-web-files/cordis.patch.yml | See package docs |
| dsh-ouroboros Q00/ouroboros | Long-running | 5657 | MIT | integrations/dsh-plugin/package.json → integrations/dsh-plugin/cordis.patch.yml | See package docs |
| deepseek-idesign Devin-AXIS/iPolloWork | Other | 4774 | NOASSERTION | external-plugins/deepseek-harness/design-studio/package.json → external-plugins/deepseek-harness/design-studio/cordis.patch.yml | See package docs |
| @petdex/dsh-plugin crafter-station/petdex | Other | 3974 | MIT | packages/petdex-desktop-native/integrations/dsh/package.json → packages/petdex-desktop-native/integrations/dsh/cordis.patch.yml | See package docs |
| @liustack/modlens liustack/modlens | MCP Bridge | 3644 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:liustack/modlens |
| @struktoai/mirage-dsh strukto-ai/mirage | Other | 3563 | Apache-2.0 | typescript/packages/dsh/package.json → typescript/packages/dsh/cordis.patch.yml | See package docs |
| @agentscope-ai/reme agentscope-ai/ReMe | Memory | 3344 | Apache-2.0 | packages/typescript/package.json → packages/typescript/dsh/cordis.patch.yml | See package docs |
| dsh-better-sidebar omdsh-dev/DSH-better-sidebar | UI / TUI | 2861 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:omdsh-dev/DSH-better-sidebar |
| dsh-codex-taskboard chuspeeism/dashi-taskboard | Other | 2541 | Apache-2.0 | integrations/deepseek-harness/package.json → integrations/deepseek-harness/cordis.patch.yml | See package docs |
| @deepseek-harness-tui/dsh-tui ccch1mneyyy/dsh-TUI | UI / TUI | 2511 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:ccch1mneyyy/dsh-TUI |
| @zilliz/memsearch-dsh zilliztech/memsearch | Memory | 2503 | MIT | plugins/dsh/package.json → plugins/dsh/cordis.patch.yml | See package docs |
| dshmarket dsh-market/dsh-market | Finance | 2299 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:dsh-market/dsh-market |
| @dsh-external/dsh-client-ui-skin-maid-atelier Small-tailqwq/dsh-deep-whale | UI / TUI | 1696 | — | maid-atelier/package.json → maid-atelier/cordis.patch.yml | See package docs |
| @wxg-prc-cpg/browser-skill-dsh-plugin Tencent/BrowserSkill | Browser | 1310 | MIT | packages/dsh-plugin-browserskill/package.json → packages/dsh-plugin-browserskill/cordis.patch.yml | See package docs |
| @mem9/dsh-plugin mem9-ai/mem9 | Memory | 1199 | Apache-2.0 | dsh-plugin/package.json → dsh-plugin/cordis.patch.yml | See package docs |
| aegis GanyuanRan/Aegis | Coding | 1129 | MIT | package.json → extensions/dsh/cordis.patch.yml | dsh plugin --profile web add github:GanyuanRan/Aegis |
| @open-pets/dsh alvinunreal/openpets | Coding | 1115 | MIT | packages/dsh/package.json → packages/dsh/cordis.patch.yml | See package docs |
| @agentrq/dsh-plugin-agentrq agentrq/agentrq | Long-running | 1088 | Apache-2.0 | plugins/deepseek-harness/package.json → plugins/deepseek-harness/cordis.patch.yml | See package docs |
| dsh-context bowenliang123/dsh-context | Browser | 1018 | Apache-2.0 | package.json → cordis.patch.yml | dsh plugin --profile web add github:bowenliang123/dsh-context |
| @nanmicoder/dsh-agent-teams NanmiCoder/dsh-agent-teams | Long-running | 980 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:NanmiCoder/dsh-agent-teams |
| dsh-vision-router ysr666/dsh-vision-router | Model & Routing | 969 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:ysr666/dsh-vision-router |
| dsh-whale-widget MeteorNOX/DeepSeek-Balance-Whale-Widget | Other | 934 | MIT | package.json → cordis.patch.yml | dsh plugin --profile web add github:MeteorNOX/DeepSeek-Balance-Whale-Widget |
The homepage shows the top 30 repositories once each; multi-bundle repositories and all records remain in data/plugins.json. Snapshot: 2026-08-25T08:59:38.471Z.
The full machine-readable records live in data/plugins.json. Topic-tagged repositories that do not yet pass bundle verification remain visible in data/candidates.json; they are never silently presented as installable plugins.
Capability Port Score
This second radar finds public SKILL.md candidates from Claude, Codex, shared .agents, OpenClaw, and SkillHub-oriented searches. It does not copy or republish their instructions. Each record pins the repository commit, file path, Git blob, content SHA-256, observed license source, and line-level adaptation signals before assigning one evidence-backed path:
copy: self-contained instructions with no observed runtime, bundled-resource, executable, or permission dependency;wrapper: instructions that need a command, bundled resource, network, secret, write, or shell adapter;bridge: a harness hook, plugin protocol, or runtime-specific configuration must be translated;unclassified: required identity evidence is missing.
49 revision-pinned candidates: Copy 15 · Wrapper 30 · Bridge 2 · Unclassified 2
| Capability | Source | Port path | Score | License | Pinned evidence |
|---|---|---|---|---|---|
| code-conventions iflytek/skillhub:.agents/skills/code-conventions/SKILL.md | agents | copy | 100/100 | Apache-2.0 | d2403bb59119 / 2add2e311e6c |
| fix motiondivision/motion:.agents/skills/fix/SKILL.md | agents | copy | 95/100 | MIT | adaf7a4e5368 / a00ab8442e03 |
| fix-pr questdb/questdb:.codex/skills/fix-pr/SKILL.md | codex | copy | 95/100 | Apache-2.0 | 6610ab113b84 / e2293795c80c |
| pr GetStream/Vision-Agents:.claude/skills/pr/SKILL.md | claude | copy | 95/100 | Apache-2.0 | 3a8eec104f90 / 85f841bbc968 |
| review ailyProject/aily-blockly:.codex/skills/review/SKILL.md | codex | copy | 95/100 | GPL-3.0 | 03989eedeae0 / c417789bb49b |
| seo gridaco/grida:.agents/skills/seo/SKILL.md | agents | copy | 95/100 | Apache-2.0 | 5909675470e8 / 51350f506838 |
| pr meshtastic/Meshtastic-Android:.claude/skills/pr/SKILL.md | claude | copy | 95/100 | GPL-3.0 | 42b07b22d7f2 / 7a332c807d86 |
| qa wp-media/wp-rocket:.claude/skills/qa/SKILL.md | claude | copy | 95/100 | GPL-2.0 | d103284e1931 / dc958f2e1d97 |
| pr woocommerce/woocommerce-ios:.claude/skills/pr/SKILL.md | claude | copy | 95/100 | GPL-2.0 | 8193985dbb9e / f075eba0d630 |
| zod hashintel/hash:.codex/skills/zod/SKILL.md | codex | copy | 90/100 | AGPL-3.0 | 840ac684fbba / a117ffc26060 |
| jna JetBrains/intellij-community:.agents/skills/jna/SKILL.md | agents | copy | 85/100 | — | d698802bc0c0 / a27c2e6d5151 |
| s RyanCodrai/turbovec:.claude/skills/s/SKILL.md | claude | copy | 85/100 | MIT | 8202f194a0cb / 97d5d955a57a |
| pr liferay/liferay-portal:.claude/skills/pr/SKILL.md | claude | copy | 85/100 | — | 4210365ab97e / 3e71624f776d |
| go nevalang/neva:.codex/skills/go/SKILL.md | codex | copy | 85/100 | MIT | bb7b3301b461 / 675bccd70ae5 |
| pr EverMind-AI/EverOS:.claude/skills/pr/SKILL.md | claude | wrapper | 79/100 | Apache-2.0 | b078f72138eb / d24a3217df00 |
Full records, score components, and line-level signals live in data/capabilities.json. Snapshot: 2026-08-13T22:47:12.754Z. The score measures only observed adaptation effort; it is not compatibility, safety, quality, or license clearance.
Search from the terminal
npx github:dongsheng123132/awesome-dsh-plugins search memory
npx github:dongsheng123132/awesome-dsh-plugins trending
npx github:dongsheng123132/awesome-dsh-plugins verified
npx github:dongsheng123132/awesome-dsh-plugins experimental
npx github:dongsheng123132/awesome-dsh-plugins runtime skillport
npx github:dongsheng123132/awesome-dsh-plugins risk process-execution
npx github:dongsheng123132/awesome-dsh-plugins ports cad
The CLI reads the committed snapshot, so normal searches do not require a GitHub token.
Static review signals
The radar also reads each verified bundle's patch and runtime dependencies, flagging review signals for secret-bearing configuration, process execution, filesystem access, network/browser access, MCP external tooling, and Web client extensions. In the first pass, 163 of 488 bundles matched at least one signal. Each signal retains patch or dependencies as its evidence source and exists only to prioritize human review; it is not a vulnerability finding or security certification. Full records live in data/plugins.json, and risk [signal] exposes them from the CLI.
Runtime compatibility layer
Verified Bundle proves only that a repository has both a dsh.bundle.patch declaration and the referenced patch file. Runtime evidence is deliberately separate in data/runtime-compat.json: each report pins the exact DSH commit and Node runtime, installs into a fresh temporary profile, composes the patch stack, then boots the real Web profile until DSH prints its readiness URL.
The first audit already demonstrates why the split matters. @dsh-skillport/bundle was not available from npm at audit time, so the documented registry install failed. The same source commit, after a local build, installed, composed, and reached a real DSH Web readiness URL on Node 24.19.0 against a previously built DSH 47f943859bef checkout. A clean detached DSH checkout installed and composed the plugin but was blocked by missing DSH Web client bundles; rebuilding that checkout then failed earlier in DSH's own build (tsdown could not import unrun). The evidence therefore supports compatibility with the built checkout, not yet a clean-source reproducibility claim. A Node 22.14 attempt is separately retained as blocked-environment because it does not satisfy DSH's declared engine floor.
The next layer is now machine-scheduled: data/runtime-targets.json pins two named DSH baselines (the pre-0.1.1 compatibility anchor and official dsh-v0.1.1-rc.2), four observed community plugin commits and one required 2Origin positive control. The runtime compatibility matrix builds the complete baseline × OS × package product, boots each stock DSH Web baseline first as the instrument's positive control, then installs, composes and boots every tuple in a fresh DSH_HOME. Baseline IDs, immutable revisions, report paths, cache keys and artifact names remain distinct, so evidence from an upgrade cannot overwrite the anchor. Baseline lifecycle scripts are governed by each pinned DSH commit's own fail-closed strictDepBuilds and reviewed allowBuilds policy; plugin lifecycle builds are allowed only for the one pinned package named by the target. Reports also resolve the installed package's declared entrypoint and classify a missing built file as package-artifact-missing, keeping source-packaging gaps separate from Harness boot failures. Each run uploads a create-only, content-addressed report, after removing credential-shaped and CI-control environment variables. A valid negative report from an observe target records ecosystem compatibility without making the instrument itself red; a required target must pass, and missing or malformed evidence always fails. Passing proves only compatibility with the named tuple; it is not a safety certification.
Run a reproducible check:
node scripts/runtime-verify.mjs --spec <package-or-built-checkout> \
--dsh-repo /path/to/deepseek-harness \
--node /path/to/node-24 \
--record data/runtime-compat.json
2Origin plugin lab
| Project | Status | Category | Problem | Evidence |
|---|---|---|---|---|
| dsh-switch | verified | Model & Routing | Evidence-first provider health probes and optimistic-lock model switching for DSH. | Immutable plugin source and smoke commands, Clean GitHub Actions run, DSH revision used for isolated profile install |
| dsh-cost | verified | Token & Cost | Durable usage-cost ledger with explicit evidence gaps, fail-closed budget checks, bounded sanitized MCP rows, a formal Codex manifest, real DSH ToolRuntime calls and stock Web Loader boot proof. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-2origin | verified | Memory | Integrity-checked 2Origin state projection, semantic diff and optimistic-lock immutable freeze with a formal Codex manifest, proof-only MCP, real DSH ToolRuntime calls and stock Web Loader boot proof. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-cad-review | verified | CAD / Engineering | Source-hashed ASCII DXF inspection and deterministic rule review with entity/layer/line/coordinate evidence, redacted drawing text, proof-only MCP and verified stock Web-profile loading. | Immutable plugin source, MCP, DSH runtime and stock Web loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-release-proof | verified | Release Engineering | Reproducible multi-source release evidence with anonymous bounded HTTP checks, deterministic content addressing, a formal Codex manifest, inline proof-only MCP, real DSH ToolRuntime calls and stock Web Loader boot proof. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-benchmark | verified | Benchmarking | Manifest-fixed deterministic command/JSONL benchmarks with revision fingerprints, bounded raw measurements without business output, versioned scoring, proof-only MCP, real DSH ToolRuntime calls and stock Web Loader boot proof. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-lineage | verified | Provenance & Lineage | Append-only content-addressed artifact/fact/action/report lineage with DAG checks, missing/stale disclosure, verified closure reports, proof-only MCP, real DSH ToolRuntime smoke and stock Web Loader boot. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-recovery-proof | verified | Recovery Evidence | Read-only recovery drill evidence for object freshness, exact stages, RTO, failed-apply rollback and stale-plan rejection, with proof-only MCP, real DSH ToolRuntime smoke and stock Web Loader boot. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-action-parity | verified | Action Parity | Content-addressed CLI, MCP and GUI bindings plus deterministic replay evidence for one stable Action ID and action core; formal Codex bundle, proof-only MCP, real DSH ToolRuntime calls and stock Web Loader boot are verified. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-narrative-ledger | verified | Writing / Novel | Content-addressed canon, immutable fact lifecycle, timeline continuity and spoiler-safe knowledge projections; v0.2 adds verified stock Web loading and a proof-only inline MCP surface without manuscript prose. | Immutable plugin source, MCP, DSH runtime and stock Web loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install |
| dsh-capability-receipt | verified | Provenance & Lineage | Content-addressed evidence for the effective skill body and bounded resource closure actually loaded by DSH, with pack-agent lock verification, a proof-only MCP surface, and verified stock Web-profile loading. | Immutable plugin source, MCP, DSH runtime and stock Web loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke, Pinned pack-agent lock and hashing contract |
| dsh-policy-drift-proof | verified | policy-governance | Pinned baseline/observed policy snapshots with value-redacted weakening, tightening, exact and fail-closed unclassified drift evidence; proof-only Codex MCP, real DSH ToolRuntime calls and stock Web Loader boot are verified. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-audit-bundle | verified | audit-evidence | Pinned multi-producer evidence with subject/revision binding, value-hash assertions, control coverage, independence thresholds and a body-free Merkle index; formal proof-only Codex MCP, real DSH ToolRuntime calls and stock Web Loader boot are verified. | Immutable plugin source, proof-only MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for local and fixed-commit GitHub Web profile installs |
| dsh-profile-lock-proof | verified | supply-chain-evidence | Content-addressed closure proof across a DSH profile declaration, pnpm importer, installed package identities and bundle patch hashes, with immutable-source and lifecycle-script checks; v0.2.0 adds host-neutral ToolDefinitions, proof-only inline MCP and real stock Web Loader coverage. | Immutable v0.2.0 source, proof-only MCP, installed-entry ToolRuntime and stock Web Loader smoke, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-surface-contract-proof | verified | contract-evidence | Offline baseline/observed conformance proof that ToolRuntime, MCP JSON-RPC and CLI JSON recordings preserve schema versions, success/error/exit mappings, conflict/confirmation, ordering and result digests; v0.2.0 adds host-neutral ToolDefinitions, proof-only inline MCP and real stock Web Loader coverage. | Immutable v0.2.0 source, proof-only MCP, installed-entry ToolRuntime and stock Web Loader smoke, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-windows-readiness-proof | verified | windows-enterprise-evidence | Pinned sanitized managed-Windows readiness evidence for DSH runtime, policy posture, filesystem/ACL, non-interactive service, storage and opaque connectivity controls; v0.1.1 also proves the namespace plugin through a real stock Web Loader boot without host collection or remediation. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-config-origin-proof | verified | configuration-evidence | Value-redacted configuration-source precedence receipts with winner, shadowed-source and unobserved-higher-priority evidence, plus proof-only MCP and verified stock Web loading. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-schema-migration-proof | verified | migration-evidence | Revision-bound schema migration fixture evidence for idempotence, rollback, required invariants and explicit loss disclosure, with proof-only MCP and verified stock Web loading. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-loader-settlement-proof | verified | runtime-evidence | Revision-bound, body-free DSH Loader settlement receipts for ordered declaration/resolution/loading/activation, injection closure and registered tool schema digests, with proof-only MCP and verified stock Web loading. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated profile install and runtime smoke |
| dsh-decision-effect-proof | verified | authorization-evidence | Body-free, content-addressed reconciliation of recorded DSH authorization decisions and effect envelopes: request/state/policy binding, confirmation, denied-effect absence, settlement, replay and ordering checks without granting authority or executing actions. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH revision used for isolated path and fixed-commit GitHub installs |
| dsh-output-custody-proof | verified | output-evidence | Body-free, content-addressed custody proof across formatted DSH tool results, model-visible or durable-only projections, full spill references and durable events, with byte budgets, exact omission, stage order and upstream-incompleteness disclosure. | Immutable plugin source, MCP, DSH ToolRuntime and stock Web Loader smoke commands, Ubuntu and Windows GitHub Actions run, DSH 0.1.1-rc.1 revision used for source build, isolated path and fixed-commit GitHub installs |
| dsh-attestation-proof | verified | supply-chain-evidence | Offline, content-addressed DSSE/in-toto release evidence with SHA-256-pinned public keys, distinct-signer thresholds, subject/predicate/hashed-claim policy checks, proof-only MCP and real DSH ToolRuntime verification without returning signed payloads. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime smoke commands, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 revision used for isolated path and fixed-commit GitHub installs |
| dsh-retention-settlement-proof | verified | retention-evidence | Body-free, content-addressed proof that an approved deletion request settled into a bound tombstone and remained absent across required DSH persistence, session and workspace projections after restart, with freshness, missing-surface and resurrection disclosure and no destructive actions. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime smoke commands, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 revision used for isolated path and fixed-commit GitHub installs |
| dsh-tool-surface-proof | verified | tool-surface-evidence | Offline, content-addressed conformance proof for explicitly recorded model-visible DSH tool surfaces across deployment revision, agent scope, permission mode and presentation mode, with hashed add/remove/schema/order drift and no schema, description or secret disclosure. | Immutable plugin source, formal Codex manifest, redacted MCP and real DSH ToolRuntime smoke commands, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-windows-settlement-proof | verified | windows-operations-evidence | Offline, content-addressed proof that an approved Windows control-plane change settled across required service, scheduled-task, event and policy surfaces at the required restart epoch, with hash-only drift disclosure and no PowerShell, registry, service or task execution. | Immutable plugin source, formal Codex manifest, redacted MCP and real DSH ToolRuntime settlement smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-principal-binding-proof | verified | identity-binding-evidence | Offline, content-addressed proof that one pseudonymous authority, tenant and target revision remain consistently bound across principal, session, agent, tool-call, runtime and artifact surfaces, with issuer, validity, revocation, key-epoch and unique-chain checks and no authentication or authority grant. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime binding smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-policy-waiver-proof | verified | policy-exception-evidence | Offline, content-addressed proof that a temporary policy waiver stayed within its approved pseudonymous subject, target revision, scope, action allowlist, lifetime and use limit, with fresh compensating-control, revocation and closure checks and no policy change, approval or command execution. | Immutable plugin source, formal Codex manifest, redacted MCP and real DSH ToolRuntime containment smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-reproducible-build-proof | verified | supply-chain-reproducibility-evidence | Offline, content-addressed proof that two or more independently operated allowed builders recorded equivalent source, recipe, build type, parameters, dependency set and environment contract and reproduced the exact byte-identical specified outputs, without running builds, authenticating provenance or claiming complete supply-chain security. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime reproducibility smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-build-hermeticity-proof | verified | supply-chain-hermeticity-evidence | Offline, content-addressed proof that one explicit hash-only build access receipt stayed inside its declared file, environment, deny-network, fixed-clock, fixed-randomness and output closure, without executing or sandboxing a build, authenticating the recorder or proving reproducibility. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime hermeticity smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-artifact-promotion-proof | verified | supply-chain-promotion-evidence | Offline, content-addressed proof that one immutable artifact digest followed an exact ordered build-to-staging-to-production chain with environment bindings, predecessor deployment receipts, required gate types, distinct authorities and fresh chronology, without deploying, granting approval, authenticating receipts or claiming runtime health. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime promotion smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-deployment-rollback-proof | verified | deployment-rollback-settlement-evidence | Offline, content-addressed proof that every explicitly declared deployment target stopped serving one failed artifact and converged within RTO to the same last-known-good digest with exact replica counts, incident and rollback-plan binding, observer diversity and fresh chronology, without executing rollback, authenticating receipts, observing live infrastructure or claiming application correctness. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime rollback-convergence smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-canary-decision-proof | verified | progressive-delivery-decision-evidence | Offline, content-addressed proof that a recorded canary promote, abort or pause decision follows exact hash-bound baseline/canary windows, exposure limits, sample floors, observer diversity, metric regression thresholds and evidence chronology, failing closed to pause when evidence is incomplete, without querying metrics, executing rollout, authenticating receipts or claiming statistical significance. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime canary-decision smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-change-window-proof | verified | change-window-settlement-evidence | Offline, content-addressed proof that one supplied hash-linked change event ledger stayed inside one declared UTC maintenance window and cutoff while remaining bound to the same change receipt, artifact, environment, policy and plan with observer diversity and fresh chronology, without approving, waiving, scheduling or executing change, authenticating receipts, observing live systems or claiming absence of unrecorded actions. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime change-window smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-break-glass-settlement-proof | verified | emergency-access-settlement-evidence | Offline, content-addressed proof that one supplied emergency-access session stayed within its request, activation, termination and expiry bounds, used only explicitly allowlisted action/resource receipts, retained one session/principal binding, revoked every declared grant before a fresh zero-residual closure observation, and met observer diversity, without granting, activating, approving or revoking access, authenticating receipts, querying live identity systems or claiming absence of undeclared actions or grants. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime break-glass settlement smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-access-review-proof | verified | access-recertification-evidence | Offline, content-addressed proof that one supplied access-review campaign covered its complete declared entitlement inventory, met risk-based staged and independent-reviewer policy, closed every final keep/revoke decision into matching active/revoked evidence, and produced an exact fresh post-review snapshot with observer diversity, without approving or changing access, authenticating receipts, querying live identity systems or claiming the supplied inventory is exhaustive. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime access-review smoke, Ubuntu and Windows GitHub Actions run, DSH 0.1.0-rc.7 used for isolated local-path and fixed-commit GitHub installs |
| dsh-duty-separation-proof | verified | duty-separation-evidence | Offline, content-addressed proof that one supplied hash-linked DSH workflow followed its exact request/approval/execution/observation sequence, kept declared conflicting duties on disjoint pseudonymous principals, met approval, principal and observer thresholds, and remained fresh, without granting authority, approving or executing actions, authenticating receipts, observing live systems or claiming the supplied ledger is exhaustive. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime duty-separation smoke, Ubuntu and Windows GitHub Actions run, DSH source checkout 47f943859bef (package 0.1.0-rc.5) used for isolated local-path and fixed-commit GitHub installs |
| dsh-credential-retirement-proof | verified | credential-retirement-evidence | Offline, content-addressed proof that one supplied credential rotation settled across every explicitly declared consumer: the new credential was accepted, the old credential was rejected, overlap stayed bounded, receipt identities remained distinct and a fresh closure observation reported zero residual old bindings, without reading, issuing, rotating or revoking secrets, authenticating receipts, querying live systems or claiming the supplied consumer inventory is exhaustive. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime credential-retirement smoke, Ubuntu and Windows GitHub Actions run, DSH source checkout 47f943859bef (package 0.1.0-rc.5) used for isolated local-path and fixed-commit GitHub installs |
| dsh-vulnerability-remediation-proof | verified | vulnerability-remediation-evidence | Offline, content-addressed proof that one supplied remediation campaign covered every explicitly declared asset, deployed the same fixed artifact, rescanned after deployment, met its deadline and produced a fresh zero-vulnerable closure with observer diversity, without discovering assets, scanning, patching, authenticating receipts, querying live systems or claiming the supplied inventory is exhaustive or that no other vulnerability exists. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime remediation-closure smoke, Ubuntu and Windows GitHub Actions run, DSH source checkout 47f943859bef (package 0.1.0-rc.5) used for isolated local-path and fixed-commit GitHub installs |
| dsh-license-obligation-proof | verified | license-obligation-evidence | Offline, content-addressed proof that every explicitly declared component decision for one supplied release had exact NOTICE, license-text, source-offer, source-bundle or modification-notice obligations matched by delivered artifact digests, distinct receipts, reviewer and observer thresholds and a fresh zero-unresolved closure, without scanning packages, normalizing SPDX, interpreting licenses, providing legal advice, authenticating receipts or claiming legal compliance or exhaustive component coverage. | Immutable plugin source, formal Codex manifest, proof-only MCP and real DSH ToolRuntime obligation-closure smoke, Ubuntu and Windows GitHub Actions run, DSH source checkout 47f943859bef (package 0.1.0-rc.5) used for isolated local-path and fixed-commit GitHub installs |
| dsh-support-lifecycle-proof | verified | support-lifecycle-evidence | Offline, content-addressed proof that a supplied release support declaration has exact component/release bindings, support-window chronology, distinct reviewer and receipt thresholds, explicit retirement notice and migration artifact digests for expired components, freshness, and a zero-unsupported closure. It does not scan compatibility, query deployments, announce or execute end-of-life, authenticate receipt issuers, prove inventory completeness, or provide operational or legal advice. | Immutable plugin source, formal Codex manifest, proof-only MCP and isolated DSH local-path plus fixed-commit GitHub installation evidence, Ubuntu and Windows GitHub Actions run, DSH source checkout 47f943859bef (package 0.1.0-rc.5) used for isolated local-path and fixed-commit GitHub installs |
Lab status is evidence-gated:
planned: problem and acceptance target exist, but there is no runnable repository.experimental: a runnable repository exists; compatibility is not yet demonstrated.verified: installation and a declared smoke test were observed against a named DSH revision.deprecated: the experiment is no longer maintained.
Plugin runtime code stays in separate repositories. This repository owns discovery, evidence, comparison, and experiment status—not a monolithic plugin implementation.
Automation
Every four hours, the scheduled workflow scans the public dsh-plugin topic, inspects package manifests, patch paths, and static review signals, regenerates the radar, runs checks, and opens or updates a reviewable pull request. Expensive runtime verification is triggered only for high-value candidates or changed revisions rather than blindly rerunning the entire matrix every four hours. It does not auto-merge ecosystem claims into main.
Local update:
GITHUB_TOKEN=github_token npm run update-radar
Anonymous API access also works for small scans:
npm run discover -- --limit 25
Contributing
See CONTRIBUTING.md. Adding the dsh-plugin topic helps discovery, but verification still depends on the bundle manifest and patch file.
Disclaimer
This is an independent community project and is not an official DeepSeek endorsement. Installing a third-party plugin executes code and may change the agent's tools, prompts, permissions, UI, or data access. Review source, dependencies, license, permissions, and maintenance state before installation.
MIT © 2026 hfshfg