插件目录 / Developer / safe-find-dsh-plugins
safe-find-dsh-plugins
已验证 · 实测可装 Jinsong-Zhou
功能简介
safe-find-dsh-plugins — DSH 插件(工具)
可用 — 实测通过,早期项目
safe-find-dsh-plugins — DSH 插件(工具) 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
safe-find-dsh-plugins
简体中文 | English
A DSH plugin that finds plugins for your task across the entire GitHubdsh-plugin topic, with a security
scan before anything gets installed.
Install
Send this repository link to DSH and say "install this plugin for me".
To install manually, copy the whole skills/safe-find-dsh-plugins/ directory
into $DSH_HOME/skills/, or into <project-root>/.agents/skills/ for one
project only. Once it's in place it just works — no other configuration.
What it does
Given your request, it first pulls every public repository under the topic
(skipping archives and forks), ranks them against what you asked for, takes a
close look at only the best few, works out how each one is meant to be
installed, and hands you a shortlist of at most three candidates.
After you pick one, it doesn't install right away: it pins the candidate's
exact commit, then runs a static security scan over that source — plugin code
is never executed. A clean scan moves ahead; if risks turn up, every finding
is laid out for you and the decision is yours; high-risk results, failed
scans, or a missing scanner never install. What ends up in your environment is
always the exact commit that was scanned — and this step is never skipped,
even when you named the plugin yourself from the start.
The scanner is a separate dependency. Before installing a plugin for you the
first time, it checks whether the scanner is present and hands you the install
command if not.
Acknowledgements
- Forked from Nagi-ovo/dsh-find-plugins.
- Security scanning is powered by
NVIDIA SkillSpector:uv tool install git+https://github.com/NVIDIA/skillspector.git.
License
MIT © 2026 Jinsong Zhou. See LICENSE.
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 safe-find-dsh-plugins」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:Jinsong-Zhou/safe-find-dsh-plugins Headless(CLI)profile:
dsh plugin --profile headless add github:Jinsong-Zhou/safe-find-dsh-plugins 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。
适合谁
想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。
二次开发建议
工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。