dshbase

Plugin directory / Developer / dsh-plugin-auditor

dsh-plugin-auditor

Verified · install-tested on dsh HYY-King

✓ Actively maintained Builds on 2 official DSH packages

View on GitHub ↗ ← Back to plugin directory

1Stars
0Forks
0Open issues
JavaScriptLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. Scans for conflicts before installing new plugins to prevent startup crashes.

✅
Our take
Works — verified, early-stage project

DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. Scans for conflicts before installing new plugins to prevent startup crashes. It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

dsh-plugin-auditor

Audit your DSH plugin combination before adding a new one 锟斤拷 predict whether it will crash the harness on boot.

DeepSeek Harness loads every bundle in the profile at startup. Third-party plugins that are unconfigured or conflicting (duplicate tool registrations, entry-id collisions, peer version mismatches, missing tokens/app ids) can fail the whole plugin tree. This plugin turns those lessons into a read-only pre-flight check.

Install

# from git
dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor

# or from a local directory (development)
dsh plugin --profile web add D:\path\dsh-plugin-auditor

# restart dsh web to activate

Usage

After restart, ask the agent to call the audit_plugins tool:

  • Full audit: call with no arguments to scan every bundle in the current profile.
  • New-plugin preview: pass newPlugins: ["package-name"] for a name-level conflict preview.

Checks

Check What it catches
Duplicate tool registration Two plugins registering the same tool name (e.g. two memory plugins both registering memory_forget)
Entry-id collision Multiple bundles mounting the same id in cordis.patch.yml
Peer version mismatch A plugin requiring a @deepseek-ai/* version that differs from the installed one
Memory-plugin uniqueness More than one memory plugin enabled at once 锟斤拷 keep exactly one
Channel-plugin credentials telegram/lark/im-style plugins enabled without token/app id 锟斤拷 disable or configure

How it works

  • Read-only: inspects the profile's package.json, cordis.patch.yml, and each installed package under node_modules; never executes audited plugin code.
  • Zero-dependency: a mini YAML parser tailored to the simple cordis.patch.yml shape.

Disclaimer

The audit is a static heuristic signal, not a compatibility guarantee. Always review a third-party plugin's source, permissions, and license before installing.

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-plugin-auditor for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor

Headless (CLI) profile:

dsh plugin --profile headless add github:HYY-King/dsh-plugin-auditor

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7797 plugins →