by zoahdev Β· 2026-08-18 Β· every plugin is live on npm/GitHub with green CI
A dsh plugin = one
defineTool+ onecordis.patch.yml+ tests/CI + a bilingual README. Once the quality gate is a repeatable pipeline, going from idea to published plugin takes tens of minutes.
my-plugin/
βββ package.json # name/version/description + dsh.bundle.patch
βββ cordis.patch.yml # - insert: - id: xxx name: my-plugin
βββ src/index.ts # apply(ctx, config) β ctx.tools.register(defineTool({...}))
βββ src/version.ts # zero-dep peer guard (pnpm can silently link an old RC)
βββ tests/*.spec.ts # vitest, incl. mock-registry / mock-exec end-to-end cases
βββ scripts/integration-test.mjs # pack β fresh install β call the real handler β assert render
βββ scripts/dsh-smoke.sh # fresh profile β plugin add β dump-config β dsh web HTTP 200
βββ .github/workflows/ci.yml
Gotchas learned from dsh-tools' typings:
defineTool needs parameters, output.schema (do NOT put required in an output object β the value schema DSL rejects it), a pure render, and execute returning canonical JSON while honoring exec.signal.JsonValue must be type aliases, not interfaces (index-signature mismatch).@deepseek-ai/dsh-tools version and throw on mismatch β turn a silent pnpm link error into a loud, actionable one.pnpm install && pnpm typecheck && pnpm build && pnpm test
pnpm pack
node scripts/integration-test.mjs ./x-0.1.0.tgz # real tarball β real handler β real render
bash scripts/dsh-smoke.sh ./x-0.1.0.tgz # fresh DSH_HOME profile β dsh web boots
CI = 3 jobs: dsh-plugin-doctor preflight (Ubuntu), test-and-load (Ubuntu), and the Windows fresh-profile dsh web boot smoke (the upstream npm CLI lacks the linux-x64 pty prebuild, so boot smoke runs on Windows).
| Plugin | Gap filled |
|---|---|
| dsh-dep-audit | dependency supply-chain hygiene (peer resolvability, dist-tag contradiction, staleness, licenses, drift) β live run flags dsh-tools' broken latest=0.0.1-rc.1 (#2763 class) |
| dsh-llms-forge | llms.txt generator (zero hits in the registry) |
| dsh-cn-boot | China-network bootstrap: probes + mirror/proxy recommendations (zero hits; caught a real HuggingFace timeout locally) |
| dsh-timesheet | wall-clock time tracking from session logs (zero hits; token dashboards were everywhere, time tracking nowhere) |
| dsh-discussions-radar | official Discussions radar (the repo is Discussions-only, but nothing surfaced them to agents) |
| dsh-readme-forge | README generator (zero hits; pairs with llms-forge) |
| dsh-firstrun | first-run health check (toolchain/profile/API key/workspace/registry + next steps) |
| dsh-disk-audit | disk-usage audit (session logs grow to hundreds of MB) |
Method: scan the 916-plugin registry first, skip anything already taken (e.g. dsh-vault is at v1.8.1 with 393 tests β don't compete).
1. npm name collision: dsh-quickstart was taken β full rename to dsh-firstrun (package, repo, docs, CI, scripts β miss one and CI breaks).
2. Windows shims: spawnSync('pnpm', args) can't launch pnpm on Windows (it's a .cmd shim) β on win32 build a command string with a shell and a quote helper.
3. CI grep drift: after the rename, the smoke grep still used the old id β red CI β fix and rerun green.
4. 0xsline CATALOG.md is CI-generated: maintainer feedback β hand edits get overwritten; the correct place is README.md + README.zh-CN.md.
5. dsh-tools latest dist-tag is broken (0.0.1-rc.1 vs declared ^0.1.0-rc.6) β the ecosystem-wide ERESOLVE root cause (#2763); develop against @next/rc.6.
1. One Show Your Plugins thread that evolves (#3123) β append updates, don't spam new threads.
2. Answer Q&A with evidence: #55 (cordis-plugin-timer missing on global install) β verified npm metadata + local require.resolve before replying.
3. Listing PRs: 0xsline (README edits, not the generated CATALOG) + awesome-dsh-plugin (data/plugins yml + generated README, 1-day gate).
4. Keep your own registry/ecosystem in sync: dsh-subscribe (916 plugins / 29 verified) + dsh-ecosystem.
After shipping the 8 plugins, I used the dsh-dep-audit engine to do something nobody had done: quantify the ecosystem's supply-chain health.
latest != next (#2763 class), 5 with dead ranges in the latest version (dsh-base has 18 pre-rename 404 package names), 15 plugins whose dsh-tools peer is contradicted by the broken latest0.1.0-rc.6 (authors should loosen to ^)Bonus findings:
<5 / >=1.2), released 0.1.1npm view <huge-package> --json truncates the version list (react returned only 8 versions) β verify with npm view <pkg> versions --jsonMethod lesson: a tool that doesn't measure its own ecosystem only fixes individual problems; applying the tool to the ecosystem produces maintenance ROI the maintainers can act on (1 dist-tag change = 89% of the impact gone).