Reviewed sample signals

12repository records reviewed
1install-time script records
3documented Git source installs
0registry runtime passes published

These numbers cover the reviewed registry sample, not all 16,529 Topic repositories.

Why Git installs need extra review

DeepSeek Harness documents that Git-hosted packages may run a prepare script during installation, outside the agent sandbox. Review the source and pin a commit before allowing a build.

Read the official package and install guidance

What the registry records

Static signalsManifest, dsh.bundle, patch path, package scripts, license, and repository files.
Install provenanceMaintainer command, npm or Git source, pinning status, and install-time scripts.
Verification gapsInstall, runtime, advisory, and dependency evidence remain separate and explicitly Not run until a result exists.

How the discovery number is counted

The 16,529 figure comes from one reproducible GitHub Search query, run daily and committed to this repository so any reading can be replayed.

Querytopic:dsh-plugin
SourceGitHub Search API, total_count
CadenceDaily, committed to the public snapshot
Records with a pinned commit12 of 12

The GitHub Topic web page and the Search API do not agree on a total for the same topic, and the gap moves in both directions as indexing catches up. Rather than pick whichever number looks better, this registry publishes the query, the source, and the date, so the figure can be checked against GitHub at any time.

Either way, the discovery number counts repositories carrying a tag. It is not a count of installable plugins, and the funnel above exists precisely because those two numbers are far apart.

Open data

Every reviewed record, the discovery funnel, and any live repository check are available as JSON under CC BY 4.0, with permissive CORS so other tools can consume them.

/api/plugins.jsonAll reviewed records
/api/check/{owner}/{repo}Live static check of any public repository
/api/compatible/{version}Records documenting a DSH release
/api/compatibility.jsonExact artifact, runtime, surface, observation, and expiry cells
/api/security/{owner}/{repo}Install-time and capability signals
/api/verified.jsonVersioned install and runtime evidence
Open the endpoint list

Important limits

Static signals cannot prove that a plugin is safe, future-compatible, or free from hidden behavior. Always review source, pin Git versions, and test in a disposable profile first.