The DeepSeek Harness Plugin Pipeline: 8 verified plugins in one day

by zoahdev Β· 2026-08-18 Β· every plugin is live on npm/GitHub with green CI

TL;DR

A dsh plugin = one defineTool + one cordis.patch.yml + tests/CI + a bilingual README. Once the quality gate is a repeatable pipeline, going from idea to published plugin takes tens of minutes.

The minimal skeleton

my-plugin/
β”œβ”€β”€ package.json          # name/version/description + dsh.bundle.patch
β”œβ”€β”€ cordis.patch.yml      # - insert: - id: xxx  name: my-plugin
β”œβ”€β”€ src/index.ts          # apply(ctx, config) β†’ ctx.tools.register(defineTool({...}))
β”œβ”€β”€ src/version.ts        # zero-dep peer guard (pnpm can silently link an old RC)
β”œβ”€β”€ tests/*.spec.ts       # vitest, incl. mock-registry / mock-exec end-to-end cases
β”œβ”€β”€ scripts/integration-test.mjs  # pack β†’ fresh install β†’ call the real handler β†’ assert render
β”œβ”€β”€ scripts/dsh-smoke.sh  # fresh profile β†’ plugin add β†’ dump-config β†’ dsh web HTTP 200
└── .github/workflows/ci.yml

Gotchas learned from dsh-tools' typings:

The quality gate (every plugin runs this)

pnpm install && pnpm typecheck && pnpm build && pnpm test
pnpm pack
node scripts/integration-test.mjs ./x-0.1.0.tgz   # real tarball β†’ real handler β†’ real render
bash scripts/dsh-smoke.sh ./x-0.1.0.tgz           # fresh DSH_HOME profile β†’ dsh web boots

CI = 3 jobs: dsh-plugin-doctor preflight (Ubuntu), test-and-load (Ubuntu), and the Windows fresh-profile dsh web boot smoke (the upstream npm CLI lacks the linux-x64 pty prebuild, so boot smoke runs on Windows).

The 8 plugins: each fills a verified registry gap

PluginGap filled
dsh-dep-auditdependency supply-chain hygiene (peer resolvability, dist-tag contradiction, staleness, licenses, drift) β€” live run flags dsh-tools' broken latest=0.0.1-rc.1 (#2763 class)
dsh-llms-forgellms.txt generator (zero hits in the registry)
dsh-cn-bootChina-network bootstrap: probes + mirror/proxy recommendations (zero hits; caught a real HuggingFace timeout locally)
dsh-timesheetwall-clock time tracking from session logs (zero hits; token dashboards were everywhere, time tracking nowhere)
dsh-discussions-radarofficial Discussions radar (the repo is Discussions-only, but nothing surfaced them to agents)
dsh-readme-forgeREADME generator (zero hits; pairs with llms-forge)
dsh-firstrunfirst-run health check (toolchain/profile/API key/workspace/registry + next steps)
dsh-disk-auditdisk-usage audit (session logs grow to hundreds of MB)

Method: scan the 916-plugin registry first, skip anything already taken (e.g. dsh-vault is at v1.8.1 with 393 tests β€” don't compete).

Real pitfalls (all hit, all fixed)

1. npm name collision: dsh-quickstart was taken β†’ full rename to dsh-firstrun (package, repo, docs, CI, scripts β€” miss one and CI breaks).

2. Windows shims: spawnSync('pnpm', args) can't launch pnpm on Windows (it's a .cmd shim) β†’ on win32 build a command string with a shell and a quote helper.

3. CI grep drift: after the rename, the smoke grep still used the old id β†’ red CI β†’ fix and rerun green.

4. 0xsline CATALOG.md is CI-generated: maintainer feedback β€” hand edits get overwritten; the correct place is README.md + README.zh-CN.md.

5. dsh-tools latest dist-tag is broken (0.0.1-rc.1 vs declared ^0.1.0-rc.6) β€” the ecosystem-wide ERESOLVE root cause (#2763); develop against @next/rc.6.

The community loop (publish β‰  done)

1. One Show Your Plugins thread that evolves (#3123) β€” append updates, don't spam new threads.

2. Answer Q&A with evidence: #55 (cordis-plugin-timer missing on global install) β€” verified npm metadata + local require.resolve before replying.

3. Listing PRs: 0xsline (README edits, not the generated CATALOG) + awesome-dsh-plugin (data/plugins yml + generated README, 1-day gate).

4. Keep your own registry/ecosystem in sync: dsh-subscribe (916 plugins / 29 verified) + dsh-ecosystem.

Advice for new plugin authors

Links

Bonus: ecosystem supply-chain health scan (a natural extension)

After shipping the 8 plugins, I used the dsh-dep-audit engine to do something nobody had done: quantify the ecosystem's supply-chain health.

Bonus findings:

Method lesson: a tool that doesn't measure its own ecosystem only fixes individual problems; applying the tool to the ecosystem produces maintenance ROI the maintainers can act on (1 dist-tag change = 89% of the impact gone).