dsh-market/dsh-market
C3The plugin market inside DeepSeek Harness — browse, search, one-click install · DSH 可视化插件市场
★ 5.3k · dsh-market/dsh-market source on GitHub · this plugin in the registry
dsh-market/dsh-market is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, starts a network server.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| executes system commands | exec | ×25 in authored code, e.g. scripts/install-e2e-host.mjs:41, scripts/install-e2e-host.mjs:41 |
| starts a network server | net_server | ×1 in authored code, e.g. src/recovery.ts:889 |
Services it injects
locale slots theme
Hooks it attaches
theme/change
Outbound domains
www.npmjs.com awesome-dsh-plugin.com get.pnpm.io giscus.app avatars.githubusercontent.com images.weserv.nl dav.jianguoyun.com app.koofr.net schema.org dav.example.com
Environment variables it reads
GITHUB_PATH ComSpec ADSENSE_CLIENT RUNNER_TEMP DSHM_REGISTRY_URL DSHM_UPDATES_ORIGIN DSH_MARKET_INSTALL_TIMEOUT_MS PATHEXT DSH_MARKET_HOT_MOUNT_TIMEOUT_MS https_proxy
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.