DSH Market
D

Dsh Plugin Template

by bugmaker2 · bugmaker2/dsh-plugin-template

Needs allowlistBundlegit + preparefreshinstall scripts

Template for deepseek-harness plugin development.

Install Dsh Plugin Template

Installs from git, but pnpm >=10 will refuse until you add an `allowBuilds` entry in your profile's pnpm-workspace.yaml. That grants this package permission to execute code on your machine at install time, outside the agent sandbox — pin a commit (github:owner/repo#sha) before allowing it.

The one-line version

dsh plugin --profile my-profile add github:bugmaker2/dsh-plugin-template

This one needs an explicit build approval before it works

Installed from git, this package builds itself with a prepare script. pnpm 10 refuses to run that script until you list the package in pnpm-workspace.yaml. Adding it means you are allowing this package's code to run on your machine, outside the agent sandbox, at install time. The first install prints an allowBuilds hint and fails — that is expected, add the entry and retry.

1. allow the build in pnpm-workspace.yaml

onlyBuiltDependencies:
  - dsh-plugin-template

2. install, pinning a commit so the code you approved is the code you get

# 1. add the bundle to a profile — --profile my-profile points at $DSH_HOME/profiles/my-profile
dsh plugin --profile my-profile add github:bugmaker2/dsh-plugin-template#<commit-sha>

# 2. verify: the bundle should show up as a layer in the resolved config
dsh --profile my-profile --dump-config

# 3. boot the profile
dsh --profile my-profile

Before you run itinstall scripts

  • This package declares prepare — package-manager lifecycle scripts that execute on your machine at install time, outside the agent sandbox, before any tool-approval prompt exists.
  • A plugin runs with your permissions once loaded: it can read your files, use your credentials and reach the network. Tool approvals do not sandbox it.
  • Installing from git resolves a moving branch. Pin a commit — github:bugmaker2/dsh-plugin-template#<commit-sha> — so the code you reviewed is the code you install.

Prerequisites

API key
Not required.
Network access
Not required at runtime.
Build approval
Required — the package must be listed in pnpm-workspace.yaml before it will build.
Language
TypeScript — a git install pulls this source, not build output.

Install check

Every field the verdict was derived from, so you can re-derive it yourself

Field checkedResultWeightWhat the spec says about it
lifecycleScriptsfailwarnruns at install time, outside the agent sandbox: prepare
dsh.bundlepassfatalpackage.json declares a `dsh.bundle` layer
dsh.bundle.patch filepassfatalpatch file present at `cordis.patch.yml`
npm registrymissingwarn`dsh-plugin-template` is not published to npm
prepare scriptpassfatalships a `prepare` script that builds on git install
pnpm allowBuildsfailwarnpnpm >=10 refuses to run a git dependency's prepare script until allowlisted
Verdict reason
git-only with a prepare script — requires an explicit build allowance
package.json read
package.json
Rules applied from
docs/user/develop/basic/publish.md
Checked at
2026-08-15
Install-time scripts
prepare

From the README

Excerpt as published by the author, plain text, unedited

English | [中文](README.zh.md) A minimal TypeScript [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) plugin bundle. It prints `hello world` when Harness loads it.

Topics

GitHub topics on this repository

More in 0 Rc Template Development

Ranked by similarity inside the cluster, not alphabetically