Why pre-install checks are being discussed
Several incompatible community marketplaces and PR-based registries now distribute DSH plugins, and packages with a missing manifest, an absent build artifact, or a wrong peer range can reach users unchanged. Open RFCs in the official repository propose a shared registry contract plus first-class diagnostics along the lines of dsh plugin check and dsh doctor. These are community proposals, not adopted DeepSeek standards, and no official command ships today. A separate community validator now runs published install commands in throwaway containers, which makes the static-versus-execution boundary concrete.
What a static check can establish
These facts are decidable from the public repository alone, so they can be stated without qualification.
- Whether the root package.json declares dsh.bundle and names a patch.
- Whether the referenced patch file actually exists in the default branch.
- Package identity, repository version, and whether a matching npm version is published.
- Which install-time scripts exist: preinstall, install, postinstall, prepare.
- Whether a maintainer-documented install command appears in the README.
- The exact commit the answers were read from.
What a static check cannot establish
Everything below requires executing code or reading intent, so a checker that claims them is overstating its evidence.
| Question | Static answer | What actually settles it |
|---|---|---|
| Is this plugin safe? | No | Source review plus a sandboxed install |
| Does it load on my DSH version? | No | Install into a disposable profile and dump the config |
| Do its tools register at runtime? | No | Start the profile and list the registered tools |
| Are its dependencies free of advisories? | No | A dependency scanner connected to an advisory database |
| Does the published tarball match the repository? | No | Comparing the packed artifact against the tagged commit |
Run the check on any public repository
The registry checker reads public GitHub and npm metadata, executes nothing, and records the commit SHA it inspected so the result can be reproduced later. Results have their own address, so a check can be linked in an issue or a review.
https://dsh-plugin.net/check/<owner>/<repo>Use the JSON if you are building tooling
The same result is available as JSON with permissive CORS, so a marketplace, a CLI plugin finder, or an agent tool can consume it directly instead of scraping the page.
curl https://dsh-plugin.net/api/check/<owner>/<repo>Why an exit code is not install evidence
The public dsh-plugin-validator reports that dsh plugin add can exit successfully without registering a bundle. Its stronger check reads the profile manifest after installation and looks for the expected entry in dsh.profile.bundles. This registry uses the same evidence boundary for its scheduled runner.
| Signal | What it proves | What it does not prove |
|---|---|---|
| Process exited 0 | The command process returned success. | That a dependency landed or a bundle registered. |
| Dependency present | The package manager recorded a package. | That DSH treats it as a profile layer. |
| Bundle row present | DSH registered the package in this profile. | That the profile boots or the capability works. |
| Runtime smoke test passed | One named capability worked in one environment. | Combination compatibility or security. |
Finish the check locally
After the static check passes, the remaining evidence has to come from your own machine. Use a throwaway profile so a failure costs nothing.
- Install into a disposable profile, never your working one.
- Pin a version or commit so the test is repeatable.
- Read any prepare or postinstall script before allowing a Git install to build.
- Confirm the expected tools, services, or interface rows appear.
- Verify the remove command restores the previous state.
dsh --profile plugin-test --dump-configDeepSeek Harness is in developer preview. Recheck official documentation and plugin evidence when the host version changes.
Sources and evidence
Official documentation and community evidence are labeled separately in the source pages and in this article.