Submit a Plugin
Getting your plugin into the registry validates dsh.so's whole purpose: the moment a developer actively submits their plugin, dsh.so becomes an ecosystem hub rather than a content site. Paste your repository URL below — the checker pulls it, validates the format, runs a security scan, and prepares a schema-valid registry entry for you.
Acceptance criteria
- ✔ DSH compatibility signal (at least one):
- •a
dshfield inpackage.json - •a
cordis/agent.cordismanifest - •a
dsh.plugin.*manifest - •a DSH topic:
dsh-plugin
- •a
- ✔ README with install instructions
- ✔ Open-source license with a recognizable SPDX identifier
- ✔ Valid plugin id — the repository name must slug to
^[a-z0-9]+(-[a-z0-9]+)*$ - ✔ Scannable source — the repo contains source files (JS/TS, scripts, …) the security scanner can analyze; docs-only or empty repos cannot be scanned
- ✔ Security scan passes — no blocking findings (hardcoded secrets, exfiltration endpoints, destructive operations, mining); warning-level findings need manual review before submitting
Scan coverage: vet runs AST analysis on JS/TS (plus shell/PowerShell download-and-exec patterns); other languages are covered by the dsh heuristic scanner.
Check your repository
What happens next
- When the checks pass, click Submit to dsh.so — the registry entry and scan report are filed as an issue in the dsh.so backend for review. Maintainers merge schema-valid entries into the registry.
- Every submission is re-fetched and re-scanned server-side at submit time — the source is analyzed fresh, never from cache. Submissions are rate-limited per address and per repository (a few per 10 minutes) to prevent abuse.
- Your plugin is listed with Declared compatibility only — never Verified until independently tested.
- Metadata (stars, forks, last commit) syncs automatically from the hosting platform.
- Tip: adding the dsh-plugin topic lets the registry auto-index your repository.
Report a compatibility check
You ran a plugin on a specific dsh version and it worked (or didn't)? That is exactly the data the ecosystem needs — and dsh.so is honest about it: no plugin is Verified yet, and the only way to change that is real reports. Copy the template below, paste it into the official Discussions, and dsh.so will fold the result into the version compatibility matrix.
Questions?
Ask in the official DSH Discussions or open a regular issue in the dsh.so repository.
