Blog
Notes on the DSH plugin ecosystem: analysis, scoring deep dives, and security findings.
How to Set Up a DSH Plugin Review Process for Your Repo
Banning plugins does not work and installing on request is worse. A short review process catches the bad ones without turning every new plugin into a meeting.
Trust in Open Source: The Plugin Middleman Problem
Reading the source tells you about the author. It tells you nothing about the registry, mirror, or install script between the author and your machine.
How to Evaluate Plugin Documentation Quality Before You Install
A practical checklist for judging whether a plugin's documentation will actually support you - or leave you stranded three months into production.
How to Back Up Your DSH Plugin Configuration
Plugin configs die quietly: a bad update, a wiped machine, a repo rename. Here is a backup routine for DSH plugins that survives all three, plus how to restore without guessing.
DSH Plugins vs Homebrew Casks: Comparing Ecosystem Risk
Both install third-party code with one command. They carry very different risk profiles, and the difference is worth understanding before you install anything else.
The Case for Quality Gates in Plugin Installation
An install-time quality gate is the cheapest place to stop a bad dependency. This post covers what to check and how to roll one out without slowing your team.
Reading a Plugin's README for Red Flags
A README is the cheapest security document you will read. Learn to read it as evidence and spot the signals that separate a careless project from a dishonest one.
How to Find Hidden Gem DSH Plugins
The best plugins in your setup are probably not in the top ten. Here is how to judge quality yourself, spot underrated DSH plugins, and skip the ones that only look safe.
CI/CD Plugin Scanning: Adding DSH Checks to Your Pipeline
A plugin that passes review today can rot by next month. Here is how to wire DSH plugin checks into your pipeline so the gate runs on every commit, not on vibes.
How to Compare Two DSH Plugins Side by Side
Choosing between two DSH plugins usually comes down to gut feeling. Here is a five-factor comparison framework, with weights, that turns the guess into a decision.
DSH Plugins vs VS Code Extensions: Security Model Compared
VS Code extensions and DSH plugins do similar jobs with very different levels of protection. This is how each security model works, where the risk sits, and how to choose safely.
The Tag-Baiting Problem in Plugin Registries
Tag baiting plugins stuff their metadata with popular keywords they don't deliver. Here's how tag manipulation and registry spam distort discovery, and how DSH Quality scores around it.
DSH Plugin Score Trends: What a Dropping Score Means
A dsh score trend is your earliest warning. Learn how to read a plugin score decline, build a watchlist plugins habit, and act before a dropping score becomes a broken setup.
How to Update DSH Plugins Without Breaking Your Setup
Updating a DSH plugin can break your setup. Follow a 5-minute pre-update check, a snapshot step, a one-at-a-time update, and a concrete rollback so upgrades never become outages.
Setting Up a Plugin Allowlist for Your Dev Team
A plugin allowlist turns plugin choice from a personal guess into a team decision. Learn how to build and enforce an approved plugin list without slowing developers down.
Top 10 DSH Plugins by Score This Month
We scanned the latest DSH plugin data and ranked the top 10 by quality score this month. See which plugins earned the highest marks and why.
How to Read a DSH Plugin Maintenance Signals
A DSH plugin maintenance signal tells you whether it is actively maintained, abandoned, or risky. Learn to read last commit dates, issue activity, and update frequency.
DSH Plugins vs npm Packages: Key Differences and When to Choose
DSH plugins and npm packages both extend the deep toolchain, but with different design philosophies. Here is what separates them, when to use each, and how to choose.
How to Avoid Risky DSH Plugins (and What "Risky" Really Means)
A practical checklist for spotting high-risk DeepSeek Harness plugins before you install — dangerous install scripts, missing dsh.bundle declarations, and archived repos.
Plugin Supply Chain Security: What Every Team Should Enforce
Every DSH plugin you install is a trust decision.
How to Install DSH Plugins Safely on Windows
A step-by-step guide to installing DeepSeek Harness plugins on Windows with security scanning enabled.
DSH Quality Score Decoded: How We Compute 0-100
How is the DSH quality score from 0-100 calculated?
Why Independent Plugin Scoring Beats Self-Reported Ratings
Stars and self-reported ratings can be manipulated. Our independent scoring uses real data — maintenance activity, documentation quality, npm health — to give you an unbiased view of plugin quality.
DSH Vision Plugins Compared: Which One Lets Your Agent See?
Pure-text LLMs can now see with DSH vision plugins. We tested the top three: dsh-vision-router, agent-vision-toolkit, and modlens. Here is which one handles screenshots, UI还原, and multi-image Q&A best.
DSH Plugin Security Scanner: Top 10 Plugins Analyzed and Graded
We scanned the top 10 DSH plugins by GitHub stars to find which ones pass the security audit. Results: 7 A-grade, 2 B-grade, 1 D-grade — and here is what the D-grade plugin got wrong.
What "Dangerous Install Script" Means in DSH Plugin Scanning
When DSH scans a plugin and flags a dangerous install script, what does it mean? Here is what you need to know about postinstall risks.
Landlock Sandboxing: How deepseek-harness Isolates Plugins
The landlock-run native sandbox brings Linux Landlock to the dsh runtime. A closer look at why plugin isolation matters and how it changes the security math for installers.
The dsh CLI Journey: v0.1.0-rc.7 and the Road to 1.0
Twelve thousand commits later, the dsh CLI sits at v0.1.0-rc.7 with the Web UI as the primary onboarding path. What early adopters should know about the plugin architecture and what changed in August.
DeepSeek Harness 101: Everything Is a Plugin
The deepseek-ai/deepseek-harness repository launched on June 10, 2026 with a bold premise: everything is a plugin. Here is how the dsh runtime, Cordis core, and the Python SDK fit together.
How Install Script Scanning Works Inside the DSH Quality Scanner
A look inside our dangerous-pattern scanner: what it checks, what it misses, and how to read the results responsibly.
The DSH Plugin Explosion: 4,300 Plugins in Days, and What It Means for You
The DeepSeek Harness ecosystem grew past 4,300 plugins within days. We break down the numbers, the tag-baiting problem, and what it means for installers.
DSH Plugin Security Scanner: How to Spot Risky Plugins Before You Install Them
A dsh plugin security scanner is the difference between a clean workspace and a compromised build. Learn how the DSH Quality score flags risky plugins before they enter your project.
More articles are on the way — subscribe to DSH Weekly to stay in the loop.