DSH Quality

Blog

Notes on the DSH plugin ecosystem: analysis, scoring deep dives, and security findings.

How to Set Up a DSH Plugin Review Process for Your Repo

October 3, 2026

Banning plugins does not work and installing on request is worse. A short review process catches the bad ones without turning every new plugin into a meeting.

Trust in Open Source: The Plugin Middleman Problem

October 2, 2026

Reading the source tells you about the author. It tells you nothing about the registry, mirror, or install script between the author and your machine.

How to Evaluate Plugin Documentation Quality Before You Install

September 21, 2026

A practical checklist for judging whether a plugin's documentation will actually support you - or leave you stranded three months into production.

How to Back Up Your DSH Plugin Configuration

September 17, 2026

Plugin configs die quietly: a bad update, a wiped machine, a repo rename. Here is a backup routine for DSH plugins that survives all three, plus how to restore without guessing.

DSH Plugins vs Homebrew Casks: Comparing Ecosystem Risk

September 15, 2026

Both install third-party code with one command. They carry very different risk profiles, and the difference is worth understanding before you install anything else.

The Case for Quality Gates in Plugin Installation

September 14, 2026

An install-time quality gate is the cheapest place to stop a bad dependency. This post covers what to check and how to roll one out without slowing your team.

Reading a Plugin's README for Red Flags

September 13, 2026

A README is the cheapest security document you will read. Learn to read it as evidence and spot the signals that separate a careless project from a dishonest one.

How to Find Hidden Gem DSH Plugins

September 12, 2026

The best plugins in your setup are probably not in the top ten. Here is how to judge quality yourself, spot underrated DSH plugins, and skip the ones that only look safe.

CI/CD Plugin Scanning: Adding DSH Checks to Your Pipeline

September 11, 2026

A plugin that passes review today can rot by next month. Here is how to wire DSH plugin checks into your pipeline so the gate runs on every commit, not on vibes.

How to Compare Two DSH Plugins Side by Side

September 10, 2026

Choosing between two DSH plugins usually comes down to gut feeling. Here is a five-factor comparison framework, with weights, that turns the guess into a decision.

DSH Plugins vs VS Code Extensions: Security Model Compared

September 9, 2026

VS Code extensions and DSH plugins do similar jobs with very different levels of protection. This is how each security model works, where the risk sits, and how to choose safely.

The Tag-Baiting Problem in Plugin Registries

September 6, 2026

Tag baiting plugins stuff their metadata with popular keywords they don't deliver. Here's how tag manipulation and registry spam distort discovery, and how DSH Quality scores around it.

DSH Plugin Score Trends: What a Dropping Score Means

September 4, 2026

A dsh score trend is your earliest warning. Learn how to read a plugin score decline, build a watchlist plugins habit, and act before a dropping score becomes a broken setup.

How to Update DSH Plugins Without Breaking Your Setup

September 3, 2026

Updating a DSH plugin can break your setup. Follow a 5-minute pre-update check, a snapshot step, a one-at-a-time update, and a concrete rollback so upgrades never become outages.

Setting Up a Plugin Allowlist for Your Dev Team

September 2, 2026

A plugin allowlist turns plugin choice from a personal guess into a team decision. Learn how to build and enforce an approved plugin list without slowing developers down.

Top 10 DSH Plugins by Score This Month

August 29, 2026

We scanned the latest DSH plugin data and ranked the top 10 by quality score this month. See which plugins earned the highest marks and why.

How to Read a DSH Plugin Maintenance Signals

August 27, 2026

A DSH plugin maintenance signal tells you whether it is actively maintained, abandoned, or risky. Learn to read last commit dates, issue activity, and update frequency.

DSH Plugins vs npm Packages: Key Differences and When to Choose

August 26, 2026

DSH plugins and npm packages both extend the deep toolchain, but with different design philosophies. Here is what separates them, when to use each, and how to choose.

How to Avoid Risky DSH Plugins (and What "Risky" Really Means)

August 25, 2026

A practical checklist for spotting high-risk DeepSeek Harness plugins before you install — dangerous install scripts, missing dsh.bundle declarations, and archived repos.

Plugin Supply Chain Security: What Every Team Should Enforce

August 25, 2026

Every DSH plugin you install is a trust decision.

How to Install DSH Plugins Safely on Windows

August 24, 2026

A step-by-step guide to installing DeepSeek Harness plugins on Windows with security scanning enabled.

DSH Quality Score Decoded: How We Compute 0-100

August 23, 2026

How is the DSH quality score from 0-100 calculated?

Why Independent Plugin Scoring Beats Self-Reported Ratings

August 22, 2026

Stars and self-reported ratings can be manipulated. Our independent scoring uses real data — maintenance activity, documentation quality, npm health — to give you an unbiased view of plugin quality.

DSH Vision Plugins Compared: Which One Lets Your Agent See?

August 21, 2026

Pure-text LLMs can now see with DSH vision plugins. We tested the top three: dsh-vision-router, agent-vision-toolkit, and modlens. Here is which one handles screenshots, UI还原, and multi-image Q&A best.

DSH Plugin Security Scanner: Top 10 Plugins Analyzed and Graded

August 21, 2026

We scanned the top 10 DSH plugins by GitHub stars to find which ones pass the security audit. Results: 7 A-grade, 2 B-grade, 1 D-grade — and here is what the D-grade plugin got wrong.

What "Dangerous Install Script" Means in DSH Plugin Scanning

August 21, 2026

When DSH scans a plugin and flags a dangerous install script, what does it mean? Here is what you need to know about postinstall risks.

Landlock Sandboxing: How deepseek-harness Isolates Plugins

August 21, 2026

The landlock-run native sandbox brings Linux Landlock to the dsh runtime. A closer look at why plugin isolation matters and how it changes the security math for installers.

The dsh CLI Journey: v0.1.0-rc.7 and the Road to 1.0

August 20, 2026

Twelve thousand commits later, the dsh CLI sits at v0.1.0-rc.7 with the Web UI as the primary onboarding path. What early adopters should know about the plugin architecture and what changed in August.

DeepSeek Harness 101: Everything Is a Plugin

August 19, 2026

The deepseek-ai/deepseek-harness repository launched on June 10, 2026 with a bold premise: everything is a plugin. Here is how the dsh runtime, Cordis core, and the Python SDK fit together.

How Install Script Scanning Works Inside the DSH Quality Scanner

August 18, 2026

A look inside our dangerous-pattern scanner: what it checks, what it misses, and how to read the results responsibly.

The DSH Plugin Explosion: 4,300 Plugins in Days, and What It Means for You

August 18, 2026

The DeepSeek Harness ecosystem grew past 4,300 plugins within days. We break down the numbers, the tag-baiting problem, and what it means for installers.

DSH Plugin Security Scanner: How to Spot Risky Plugins Before You Install Them

August 18, 2026

A dsh plugin security scanner is the difference between a clean workspace and a compromised build. Learn how the DSH Quality score flags risky plugins before they enter your project.

More articles are on the way — subscribe to DSH Weekly to stay in the loop.