Bundle
dsh-research
The research plugin market inside DeepSeek Harness: browse a curated index of literature, reference, writing and workbench plugins in Settings and install them with one click — 科研插件市场,在设置里浏览并一键安装。
- Source
- dsh-research
- stars
- 4 stars
- License
- MIT
- Updated
- Updated 2 hours ago
Readme
<p align="center"><strong>dsh-research</strong></p>
# Research plugins, inside Settings
English | [中文](README_CN.md)
[](https://www.npmjs.com/package/dsh-research) [](https://github.com/topics/dsh-plugin) 
A curated market for research plugins: a **Research plugins** page in the Settings sidebar, listing hand-picked plugins for literature search, reference management, writing and review — with an Install button that writes straight into the profile you are running.
```sh
dsh plugin --profile web add dsh-research
```
Restart `dsh web`, then open **Settings → Research plugins**.
## dsh-research.com
The catalog behind the panel lives at **[dsh-research.com](https://dsh-research.com)** — the same list, in a browser, at [/plugins](https://dsh-research.com/plugins/). Each entry says what the plugin does and where it stops, and there is a walkthrough that goes from an empty machine to a finished talk. The site is generated from one JSON file; the panel fetches that same file, so the two can never drift apart.
## Why this exists
The official market already installs anything in the community registry, and does it well. What it cannot do is tell a researcher which of its eleven hundred plugins are theirs. That is the part this does.
## What an install actually does
The panel runs `dsh plugin --profile <your profile> add <package>` for you — the same command you would type. Four things fence it:
| | |
|---|---|
| **Allowlist** | The browser may ask for any package name; only a package this catalog lists is ever spawned. The catalog is a static file we publish. |
| **Same-origin** | A state-changing route reachable from any page would let a site you visited install into your profile. |
| **One at a time** | Two concurrent `dsh plugin add` runs race on one `package.json` and can leave a profile half-written. |
| **Your profile, not a guess** | The target comes from the `--profile` this host booted, so running a test profile never mutates your real one. |
Set `allowInstall: false` to keep the panel read-only.
## Configuration
The bundle inserts one row (`id: research-market`). Override it from your profile's `cordis.patch.yml` (a patch replaces the whole `config`, so restate every key you keep):
```yaml
- id: research-market
config:
catalogUrl: https://dsh-research.com/v1/market.json
profile: web # defaults to the profile this host booted
allowInstall: true
cacheSeconds: 900
timeoutMs: 8000
```
`catalogUrl` accepts any endpoint answering the [DSH Community Market provider contract](https://github.com/anywhere-labs/deepseek-harness-desktop/blob/master/dsh-community-market/docs/catalog-provider-contract.md). Point it at your own and the panel lists yours instead.
## Notes
- The panel's list and the one at [dsh-research.com/plugins](https://dsh-research.com/plugins/) are the same list, built from the same `market.json`. Nothing reaches it unread: installing someone else's package from a button we drew makes us the first place their bug gets reported.
- The process layer is adapted from [dsh-market](https://github.com/dsh-market/dsh-market) (MIT), which worked out that `ctx.shell` cannot write to a profile, that a macOS app launched from the Dock has no Homebrew on PATH, that pnpm v10 hangs without a TTY unless `CI` is set, and that Windows `dsh` is a `.cmd` shim.
- A newly installed plugin needs a restart before it loads; the row says so.
## License
MIT
Install
dsh plugin --profile web add github:dsh-research/dsh-research#d098c5a178e9d8da205c4b5793c97124a553e7aa
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-research from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.