dshmarketplace-py

by DshMarketPlace

0 工作流与自动化github未核验到 manifest收录于 08-17

用 Python 查找并安装 DeepSeek Harness(DSH)插件:零依赖、带类型标注,提供 CLI 与 agent 工具

Find and install DeepSeek Harness (DSH) plugins from Python. Zero dependencies, typed, CLI + agent tools.

安装

dsh plugin --profile web add github:DshMarketPlace/dshmarketplace-py

GitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试

安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗

安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。

README

目录

在 Python 里查找和安装 DeepSeek Harness(DSH)插件。

pip install dshmarketplace
import dshmarketplace as dshm

for plugin in dshm.search("memory", limit=5):
    print(plugin.full_name, "—", plugin.summary_zh)

零依赖,带类型标注。库、CLI、agent 工具三种用法。

为什么做这个

DeepSeek Harness 是 DeepSeek 开源的 agent harness,所有能力都是插件。社区插件已经过千,而这个生态才几周—— 也就是说,模型凭训练记忆报出来的插件名,错的概率比对的高,而报错一个名字的结果 要么是装不上,要么是装了别人的包。

这个包就是让 Python 的 agent 去查,而不是猜。

它读的是和 dshmarketplace.dev、npm 上的 dshmarketplace-cli、以及 DSH 内嵌插件同一份目录,所以同一条记录不会在这里是 一个说法、在浏览器里是另一个说法。

当库用

from dshmarketplace import Client

client = Client()

results = client.search("vision", category="vision", limit=5)
print(results.total)

plugin = client.get("Anionex/dsh-vision-toolkit")
plugin.summary                 # 英文
plugin.summary_zh              # 中文,手写的,不是机翻
plugin.summary_in("zh")        # 按语言拿
plugin.stars, plugin.license, plugin.risk_flags

plan = client.resolve("Anionex/dsh-vision-toolkit")
plan.command                   # 'dsh plugin --profile web add dsh-vision-toolkit'
plan.argv                      # 真正会被执行的那个列表

client.install("Anionex/dsh-vision-toolkit", dry_run=True)

异步版,给不能阻塞事件循环的 agent:

from dshmarketplace import AsyncClient

plugins = await AsyncClient().search("memory")

底层仍然是 urllib,用 asyncio.to_thread 挪出事件循环。这一点明说:它不阻塞 循环,但也不假装自己是原生异步客户端。为了做成原生异步而引入 httpx,代价是 每个用这个包的人都可能撞上依赖冲突——而这里一轮对话也就发一次请求。

当 CLI 用

dshm find memory
dshm find vision --limit 5 --category vision
dshm info Anionex/dsh-vision-toolkit
dshm add NanmiCoder/dsh-agent-teams --dry-run
选项
--json 机器可读输出,结构稳定(所有命令)
--limit <n> 显示多少条(find,默认 10)
--category <id> 按分类过滤(find)
--profile <name> 装进哪个 DSH profile(add,默认 web)
--source github 强制用 GitHub 源而不是 npm(add)
--dry-run 只解析不执行(add)

当 agent 工具用

两个工具,JSON Schema 格式,OpenAI、Anthropic 和大多数框架都认,外加一个 分发函数——接上去两行代码。

from dshmarketplace.tools import TOOLS, dispatch

response = anthropic.messages.create(model="claude-opus-4-6", tools=TOOLS, ...)

for block in response.content:
    if block.type == "tool_use":
        result = dispatch(block.name, block.input)

resolve_dsh_install 不会执行任何东西。它返回确切的命令、源码仓库地址和识别到 的风险标记,跑不跑的决定权留在调用方。

装 DSH 插件要知道的两件事

都不是这个包造成的,但都花了不少时间才搞明白。

--profile 是必填的。 dsh plugin 是把参数转发给 profile 目录里的 pnpm, 所以 dsh plugin add x 会直接报 required option '--profile <name>' not specified,什么都不装。这个包给出的每条命令都带上了。

github:owner/repo#subpath 不可能成立——pnpm 会把 # 后面的东西当 git ref 读。所以那些没发 npm 的 monorepo 子目录插件没有一行安装命令:它们的 plugin.install 是 None,installable 是 False,你不会拿到一条跑不通的命令。

GitHub 源还需要 pnpm 的 allowBuilds 放行构建脚本才能装。这才是 npm 排在前面 的原因,不是因为 tarball 比 clone 好。

安全

插件是第三方代码,跑起来带的是你 agent 的权限。被这个目录收录不代表通过了 安全审计。

安装命令从不由自由文本拼装,也从不经过 shell。目录返回的是已经组装好的命令; plan_from_command 只接受裸 npm 包名或 github:owner/repo,含 .. 的一律 拒绝,argv 以列表传递、shell=False。就算目录哪天被投毒,影响也止步于此—— tests/test_install.py 就是用来守住这条线的。

risk_flags 是自动识别出来的:安装脚本、终端执行、需要密钥。**空列表不能证明 任何事。**源码地址始终会给出,装之前读一眼。

配置

变量
DSHM_API 指向镜像、预发布环境或本地目录
NO_COLOR CLI 输出不带颜色

开发

pip install -e ".[dev]"
pytest
pytest -m live        # 可选,会打真实目录

相关

联系

致谢

  • LINUX DO —— DSH 生态实际上是在这里被讨论的,这个项目 也在这里发布和收反馈。
  • (CC0-1.0)—— 目录最初的收录种子来自这里。

开源协议

MIT。独立项目,与 DeepSeek 官方无隶属关系。DeepSeek 与 DeepSeek Harness 是各自 权利人的标识,此处仅用于说明这些插件是做什么用的。

原始 README: https://github.com/DshMarketPlace/dshmarketplace-py/blob/main/README.zh-CN.md ↗