Skip to content
DSHRadar中文

Official workflow explained

How to install a DeepSeek Harness plugin safely

The DSH CLI manages plugins inside named profiles. A good install flow starts by choosing the profile, verifying the exact package or Git target, and understanding whether the package declares a DSH bundle.

1. Choose the profile before the package

The web alias runs the web profile, while DSH Desktop normally uses the desktop profile. A plugin installed into one profile does not automatically appear in another. Use the profile named by the plugin author and by the application you actually run.

The official CLI forwards plugin-management arguments to pnpm inside that profile directory. After a successful operation, packages that declare a DSH bundle are reconciled into the profile's bundle list. A dependency without a bundle can install yet still provide no mounted DSH feature.

dsh plugin --profile web add <package-or-git-spec>

2. Prefer a precise and reviewable target

  • For npm, use the package name shown by the current source and pin a version when stability matters.
  • For GitHub, prefer a release tag or full commit SHA instead of an unpinned moving branch.
  • For a local checkout, understand that relative paths are resolved from the directory where you invoke the command.
  • Do not reuse a command from an old directory snapshot when the source repository now recommends a different package.

3. Inspect the composed profile and restart

Use the config dump to confirm that the expected bundle joined the profile. A running DSH process keeps the composition it started with, so stop it cleanly and restart after adding or removing a bundle. Desktop users may need to fully exit the tray process rather than only close the window.

dsh --profile web --dump-config
dsh web

4. Treat build-script prompts as a review gate

Git-hosted plugins that build from source can use a prepare script. Modern pnpm versions may block that script until the consumer explicitly allows it. Do not automatically approve the request: inspect the package scripts and source, then decide whether the build is appropriate for the test profile.

5. Remove the exact dependency

Remove the precise dependency name from the same profile, inspect the composed config again, and restart. Removing a package does not necessarily delete data or account configuration that the plugin created outside its dependency directory.

dsh plugin --profile web remove <package-name>