Plugin directory / Developer / dsh-plugin-auditor
dsh-plugin-auditor
Verified · install-tested on dsh HYY-King
What it does
DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. Scans for conflicts before installing new plugins to prevent startup crashes.
Works — verified, early-stage project
DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. Scans for conflicts before installing new plugins to prevent startup crashes. It installs cleanly and boots without issues in our testing. It's early-stage but functional.
“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
dsh-plugin-auditor
Audit your DSH plugin combination before adding a new one 锟斤拷 predict whether it will crash the harness on boot.
DeepSeek Harness loads every bundle in the profile at startup. Third-party plugins that are unconfigured or conflicting (duplicate tool registrations, entry-id collisions, peer version mismatches, missing tokens/app ids) can fail the whole plugin tree. This plugin turns those lessons into a read-only pre-flight check.
Install
# from git
dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor
# or from a local directory (development)
dsh plugin --profile web add D:\path\dsh-plugin-auditor
# restart dsh web to activate
Usage
After restart, ask the agent to call the audit_plugins tool:
- Full audit: call with no arguments to scan every bundle in the current profile.
- New-plugin preview: pass
newPlugins: ["package-name"]for a name-level conflict preview.
Checks
| Check | What it catches |
|---|---|
| Duplicate tool registration | Two plugins registering the same tool name (e.g. two memory plugins both registering memory_forget) |
| Entry-id collision | Multiple bundles mounting the same id in cordis.patch.yml |
| Peer version mismatch | A plugin requiring a @deepseek-ai/* version that differs from the installed one |
| Memory-plugin uniqueness | More than one memory plugin enabled at once 锟斤拷 keep exactly one |
| Channel-plugin credentials | telegram/lark/im-style plugins enabled without token/app id 锟斤拷 disable or configure |
How it works
- Read-only: inspects the profile's
package.json,cordis.patch.yml, and each installed package under node_modules; never executes audited plugin code. - Zero-dependency: a mini YAML parser tailored to the simple
cordis.patch.ymlshape.
Disclaimer
The audit is a static heuristic signal, not a compatibility guarantee. Always review a third-party plugin's source, permissions, and license before installing.
License
MIT
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install dsh-plugin-auditor for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor Headless (CLI) profile:
dsh plugin --profile headless add github:HYY-King/dsh-plugin-auditor Test report
Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.
When to use it
Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.
Who it's for
Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.
For developers — extending it
The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.