DeepSeekDSH
Independent community guideNot affiliated with DeepSeek.Official source snapshot

dsh-plugin-install

Install tab in Settings → Plugins: install, update and remove any plugin by npm spec, `github:user/repo` or local path through the same `dsh plugin add` CLI path; update checks against npm latest or GitHub HEAD with a downgrade guard and resolved-version verification, a pnpm 11 release-cooldown bypass on every add/remove, and service restart via the DSH Desktop shell or a relay process under standalone `dsh web`.

Independent editorial review: DeepSeekDSHSource checked: 0.1.5-rc.2 · 2026-09-11
On this page
Third-party

Review info: an independent structural review record is available for install structure, README, lifecycle scripts and runtime-artifact evidence. This is not a full code security audit.

Community signals

Category

Plugin Markets & Managers

GitHub stars

3

npm downloads

1,833

Discovery registry added

2026-08-24

Review information

Scanner status

auto-resolved

Review mode

automatic

Last checked

2026-09-21T12:51:21.444Z

Build approval required

No

Lifecycle scripts

prepare

Runtime artifacts committed

No

Documented profiles

web

Review reasons
  • exact-npm-tarball-verified-for-automatic-install

Why this site does not provide the install command

A third-party DSH plugin is executable local code. Even when structural review evidence exists, registry data, stars and metadata cannot prove the code is non-malicious. Read the current author repository and perform your own review in a disposable environment.

Install and usage source

This site links to the author's source, npm page and community registry instead of redistributing commands. A plugin may add Web UI, Settings, agent tools or background capabilities; follow the author README for the actual entry point.

Minimum checks before install

  1. Confirm package.json, the bundle patch and README belong to the same author repository.
  2. Inspect preinstall/install/postinstall/prepare, child_process, shell, filesystem, network calls and credential access.
  3. First install into a disposable profile/workspace without production credentials or an important repository.
  4. If pnpm asks for allowBuilds/build approval, treat it as permission to execute third-party code during installation; do not approve mechanically.
  5. For reproducibility, pin an exact npm version or Git commit yourself instead of depending on main/latest.
Third-party does not mean unsafe, and review is not a security certification

“Third-party” only means the plugin is not an official DeepSeek plugin. Structural checks improve transparency but cannot prove business logic is non-malicious or fully audit dependencies, future updates or runtime behavior.

Sources

THIRD-PARTY PLUGINSSearch the live registry
Community Plugin Explorer →