Agent skill

Plugin Upgrade

by NanmiCoder in NanmiCoder/dsh-auto-mode

A skill your agent uses for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary…

MITAuto-check: warnings

Install Plugin Upgrade

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add NanmiCoder/dsh-auto-mode --skill plugin-upgrade -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NanmiCoder/dsh-auto-mode plugin-upgrade --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NanmiCoder/dsh-auto-mode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/plugin-upgrade .claude/skills/plugin-upgrade && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
plugin-upgrade
GitHub stars
165
Used in
1 other repo
Token cost
~4.5k tokens
SKILL.md length
2,129 words
Files
64 (incl. scripts, references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary…

  • Works in 3 steps: fully stop every dsh process (a running… → from an EXTERNAL terminal, run the… → restart dsh web, hard-refresh the…
  • DSH plugin compatibility
  • SKILL.md covers Step 0: choose a mode, Global DSH host upgrades…, Shared read-only preparation and Mode A · inspect (read-only), plus 5 more sections
  • Calls npm, git and cursor

What it does

Plugin Upgrade is an agent skill from NanmiCoder/dsh-auto-mode. Use for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary, API, dependency, activation, or runtime compatibility problems. Inspection and diagnosis stay read-only; show a plan and obtain confirmation before any configuration, dependency, or source write.

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 65 other files, including scripts and reference files (for example `SKILL.zh-CN.md`, `evals/evals.json` and `examples/01-simple-client-plugin.en.md`).

It works with DeepSeek and npm. The repository describes itself as: Safe automatic permissions for DeepSeek Harness. The licence is MIT.

When your agent uses it

  • DSH plugin compatibility
  • Post-upgrade diagnosis
  • Including read-only review of already-migrated plugin source and version-boundary
  • Runtime compatibility problems

Example prompts

  • “/plugin-upgrade”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. fully stop every dsh process (a running host holds native-module file locks → EBUSY;
  2. from an EXTERNAL terminal, run the pinned install
  3. restart dsh web, hard-refresh the browser, verify version markers and plugins.

What it can do on your machine

Read from SKILL.md and the folder at commit 907d663. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • git
    • cursor

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Plugin Upgrade loads about 4.5k tokens when it runs, and up to ~93k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 2,129 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~93k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:55
    . Never read, print, or commit tokens, `.npmrc` contents, credentials, or session logs.
  • NoteMentions a .env fileSKILL.md:125
    ap install (`dsh-http-proxy`, `$DSH_HOME/.env` home layer), session persistence `SessionHandle` + async `agentLoop.creat

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from NanmiCoder/dsh-auto-mode at commit 907d663, republished under its MIT licence (© NanmiCoder). 2,129 words, ~4,499 tokens.

Download SKILL.mdSave it as .claude/skills/plugin-upgrade/SKILL.md (or your agent's skills folder). This skill also uses 63 other files; get the full folder from GitHub.
name
plugin-upgrade
description
Use for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary, API, dependency, activation, or runtime compatibility problems. Inspection and diagnosis stay read-only; show a plan and obtain confirmation before any configuration, dependency, or source write.

English | 简体中文

plugin-upgrade

Safely handle three task types: read-only update inspection, installed-plugin upgrades, and DSH host version compatibility migration. If user intent is unclear, confirm the mode first; never let "help me check for updates" slide into installing or changing code.

Note: the version cards and reference docs under references/ are in English; card IDs and cited commands are language-neutral.

Step 0: choose a mode

ModeUser intentDefault allowed action
A · inspectCheck for updates or assess impact from a DSH releaseRead-only investigation and report; then stop
B · updateUpgrade an installed plugin to an explicit versionPlan and confirm before changing composition or dependencies
C · author-migrateUpgrade a plugin author's source repository for a newer DSH hostBaseline, build the version corridor and touchpoint inventory, then implement the approved migration

This skill does not handle "upgrade DSH core only and leave the plugins alone," and it must not modify DSH core to conceal plugin incompatibility.

Global DSH host upgrades (agent discipline)

Upgrading the dsh host itself (npm install -g @deepseek-ai/dsh@…) is not Mode B/C plugin work — and when the requesting agent runs INSIDE a dsh session it is structurally fatal: the session IS the host process, npm removes/replaces the very package tree it executes from, the host dies mid-install (the tool call never returns), and the interrupted install leaves package content present WITHOUT regenerated shims — the dsh command itself is gone until an external pinned re-install repairs it. Never execute the global host upgrade from inside a session on that host; hand the user the external procedure:

  1. fully stop every dsh process (a running host holds native-module file locks → EBUSY; a browser refresh is not a host stop);
  2. from an EXTERNAL terminal, run the pinned install npm install -g @deepseek-ai/dsh@<exact-version> (a bare package name resolves to the latest dist-tag and can silently downgrade to an older line);
  3. restart dsh web, hard-refresh the browser, verify version markers and plugins.

Because the host is fully stopped before npm runs, nothing crashes mid-install — a crash during the upgrade is a signature of doing it wrong, not a risk to tolerate. If an install was already interrupted: repair from an external shell by re-running the pinned formal install (never hand-copy package directories or hand-write shims).

Shared read-only preparation

  1. Read the target repository's rules such as AGENTS.md / CLAUDE.md; check branch, HEAD, working tree, and submodules. Stop and report unfamiliar changes or untracked files; never auto-stash, reset, clean, or checkout.
  2. Record source identity and installation identity separately: registry package, Git checkout, workspace/junction, or copied install; record the source repository/URL, Git SHA, actual package name, the plugin's own version, the declared/resolved DSH dependency cohort, and current DSH/Node versions. A plugin release version (for example 0.6.4 → 0.7.0-alpha.0) is not the DSH host corridor (0.1.0-rc.6 → 0.1.2-alpha.4). GitHub owner/repo and registry scope/package are independent coordinates — do not derive or rewrite one from the other.
  3. Preserve file ownership boundaries:
    • package.json / lockfile: package and dependencies;
    • dsh-plugin.json: community-standard manifest (if adopted);
    • cordis.patch.yml / agent.cordis.yml / legacy cordis.yml: profile composition;
    • resolved config: runtime composition result, used for verification only; never write the whole object back.
  4. Verify the target version's source, tag/package name, compatibility range, release notes, install scripts, and known breaking changes. Never read, print, or commit tokens, .npmrc contents, credentials, or session logs.
  5. Record the rollback baseline: current HEAD/package version, lockfile, and hashes/paths for configuration that may change. Describe recovery only for the explicit paths owned by this task; do not promise rollback of arbitrary third-party script side effects.

Mode A · inspect (read-only)

Report: current/available versions, source, compatibility range, breaking changes, recommended target, risks, and a validation plan. Do not edit files, install dependencies, run lifecycle scripts, git pull, or switch versions. If the user decides to proceed, enter Mode B or C with separate confirmation.

Mode B · update (upgrade an installed plugin)

  1. Choose the single update mechanism that matches the resolved package identity and installation track; when a lockfile exists, use only its package manager — do not mix npm/pnpm/bun, and do not rewrite a registry package name to match a GitHub owner.
  2. Produce a change plan: exact target version, commands to run, files that will change, lifecycle scripts that may run, configuration migration, and rollback steps.
  3. Obtain explicit user confirmation before any write or install, even when no breaking change is known.
  4. Make minimal changes in a dedicated branch/worktree; patch configuration by path and preserve unknown fields. For Git sources, fetch and compare an explicit tag or commit first; never git pull a dirty worktree.
  5. Successful dependency installation does not mean DSH has enabled the plugin; verify the target profile's composition actually resolves to the target package, remove old source lines owned by this upgrade if any exist, and confirm the runtime entry is active.
  6. Run "Validation and reporting"; on failure, restore only the paths owned by this task and report residual side effects.

Mode C · author-migrate (migrate a plugin source repository with a DSH upgrade)

  1. Run the baseline first: in the repository's own dependency state (no target pin, no target env) run the mechanical suite (build / typecheck / tests; these run package scripts, so first show the commands to be executed per the safety boundaries and obtain confirmation), and record pre-existing failures as an exemption list (see R-06 in references/rollup-0.1.2.md; later corridors follow the same pattern). The migration must not add or worsen failures; pre-existing failures are exempted per the baseline.
  2. Confirm exact from/to tags; connect version corridors by the from → to metadata in references/README.md — never by filename lexicographic order. If the source is older than the earliest card, mark that segment as an unsupported gap and derive it from exact-tag source, packed declarations, and reproducible tests; do not pretend a later card covers it.
  3. Read the full corridor first and compute the final net state. When a field is removed in an intermediate version and restored in the target, do not delete and re-add it.
  4. Scan the seven touchpoint classes per pre-flight.md: source patches, events, services/Remote, host filesystem, UI/commands/tools, custom channels, subprocess/output. You may first run the read-only migration planner to generate paths/line numbers and candidate cards, but its results remain heuristic; zero hits still require checking dependencies/imports and running build plus a real mount.
  5. Keep only cards that intersect the hit touchpoints and the actual face (Host / Web Client / ordinary plugin). Cards are a curated list, not a complete API diff; when corridor edges or API coordinates are missing, mark them unsupported/pending instead of changing things from memory.
  6. Produce a source-migration plan grouped by Host/Web Client seam, listing hit files, cards, target behavior, and tests; obtain confirmation before implementing in a dedicated branch/worktree. Keep the DSH cohort exact and coherent in package.json and the lockfile; a successful install with mixed old/new peers is not a migration. If a selector or callback unexpectedly becomes any, run one diagnostic typecheck with skipLibCheck: false and declare the packages that own the consumed declarations directly. capability cards are suggestions only — never adopt them automatically.
  7. After compatibility changes pass, choose and apply the plugin's own SemVer bump separately. Verify the packed filename and packed manifest both carry that plugin version; never use the DSH host version as the plugin release version by accident. For the removed dsh-client-runtime, keyed chat snapshots, command execution signature, or Workspace navigation (connectWorkspace / pickDirectory), use the alpha.2 API ledger and DSH-0.1.2-A1-32.
Show full SKILL.md (897 more words)Show less

Safety boundaries

  • Show the plan and obtain confirmation before any file write, install, version fetch/switch, or package script run;
  • Never auto-stash/reset/clean/force-update, and never overwrite user or other agents' work;
  • Never expose credentials; diagnostics may report only whether something is configured and non-sensitive versions/sources;
  • Do not retry unknown gateway/internal or other failures by default; retry only when the error is retryable, the operation is idempotent, and policy allows;
  • When a migration approach cannot be determined with high confidence from primary sources or reproducible behavior, stop automatic changes and mark it "pending review";
  • When local observation conflicts with a primary source, record both, reproduce, and report — do not silently pick one side.

Validation and reporting

Validate at least the applicable layers:

  1. Dependency resolution: the package manager, lockfile, and dependency graph change only as expected; scan the full lockfile for the old DSH cohort and removed packages, not only top-level dependencies;
  2. Enablement resolution: the target profile's composition points to the expected package identity, with no old source or duplicate rows;
  3. Static: build, typecheck, and plugin tests; for the alpha.2 corridor, close out references/precision-checklist.md, keeping type declarations separate from runtime module/service activation and preserving existing channel protocols when applying the Connection auth gate;
  4. Runtime: cold-start a real DSH profile; verify entry activation and that required/provided Cordis services do not remain pending — verify-runtime.mjs runs this layer end-to-end in an isolated profile and reports failure attribution (plugin-code / dependency-resolution / profile-config / dsh-runtime). For a Web Client plugin, exchange the printed token URL for its cookie, read the host boot manifest, request the advertised client artifact, and prove registration/mount rather than accepting a bare HTTP 200;
  5. Behavior: execute one core plugin path; host migrations must complete at least one message → tool → response flow, or an equivalent dedicated flow;
  6. Wrapper: verify exit code, stdout, stderr, cancellation, and teardown.

Structure the report as:

  • pre-existing (Mode C with the baseline run; other modes note "not collected"): the list of failures from the baseline (untouched, not attributed to this migration);
  • Completed: versions, files, cards, and validation;
  • Skipped: non-hits or inapplicable items with evidence;
  • Pending/residual risk: missing sources, untested platforms, lifecycle-script side effects;
  • Rollback: recorded baseline and recoverable paths;
  • Recommendations: optional capabilities and follow-up work migrating to public seams.

References

FilePurpose
references/README.mdVersion corridors, card schema, and maintenance rules
references/pre-flight.mdSeven-class touchpoint self-check and summary template
references/troubleshooting.mdPost-migration symptom → root cause → card lookup
references/v0.1.1-rc.1.mdrc.8→rc.1 draft cards: repository-plugins mechanism removal, dshClient→dsh.client manifest merge, client-modules scan → bundle dsh.client, strict injection + weak ctx.get, session event contract, self-rendering client session aggregation, tasks.peek removal, 0812 service renames (vlln plugin migrations; corridor is the closest published-tag alignment for the internal 0810–0812 snapshot window)
references/v0.1.1-rc.2.mdrc.1→rc.2 reviewed cards (3, DSH-0.1.1-R2)
references/v0.1.2-alpha.1.mdrc.2→alpha.1 curated cards
references/v0.1.2-alpha.2.mdalpha.1→alpha.2 curated cards
references/v0.1.2-alpha.3.mdalpha.2→alpha.3 curated cards (2): optional SQLite Session-persistence provider removed (opt-in databases need an older build to export, DSH-0.1.2-A3-02) and additive settings.plugin.item keyed-slot settings card capability (DSH-0.1.2-A3-01); carries the verification record
references/v0.1.2-alpha.4.mdalpha.3→alpha.4 curated cards (6): report tool package removed in favour of send_message, Python code-runtime package renamed, Session.events replaced by seq/eventAt/snapshotEvents, branded SessionSeq/SessionLogOffset + seedLength→isSeeded, PTC preset drops workflow, base bundle enables web_fetch; carries a three-host verification record
references/v0.1.2-alpha.5.mdalpha.4→alpha.5 curated cards (3): storage domains gain optional compatibleVersions read tolerance and invalidRecords: 'backup-and-skip' salvage; host fix for rc.2/alpha.3-era homes that refused to boot or dropped session titles on alpha.4; carries a storage-layer reproduction record
references/v0.1.2-rc.1.mdalpha.5→rc.1, the first release candidate of the 0.1.2 series (zero cards: pure version bump, no plugin-facing changes; verification record plus a release-notes coverage matrix mapping the rc.1 summary onto the corridor cards, with backfill candidates)
references/v0.1.3-alpha.1.md0.1.2-rc.1→0.1.3-alpha.1 cards (5): A1-01/A1-02 session-log corridor measured on the release-tarball build 0.1.3-alpha.1-9523542 (the v0→v1 session migrator refuses 0.1.2-alpha.x-writer logs — top-level replayState.kind/version: 1, all pre-alpha.4-writer history unloadable, fail-closed with the source artifact untouched; cross-version resume reports cursor behind the last applied entry, tag alignment pending); A1-04…A1-06 git-tag anchored: outbound HTTP(S)/ALL_PROXY bootstrap install (dsh-http-proxy, $DSH_HOME/.env home layer), session persistence SessionHandle + async agentLoop.create() + per-session lock, Session log format v2 + released migration catalog
references/v0.1.3-alpha.2.md0.1.3-alpha.1→0.1.3-alpha.2 curated cards (5): persona splits into prefix + suffix (text/persona keys and PERSONA_SECTION removed), SubprocessHandle.pid removed, base bundle drops the tool-str-replace-editor default row, launcher runCli()/import.meta.main gate, pi-ai ^0.84.2→^0.85.1; first 0.1.3 build on npm (alpha.1 items debut for npm upgrades)
references/api-migration-0.1.2-alpha.2.mdExact rc.2→alpha.2 interface ledger; read when API, Remote, Settings, events, Headless, packaging, or composition surfaces are hit; includes the removed client runtime and keyed chat snapshots (API-10)
references/rollup-0.1.2.md0.1.1 → 0.1.2 corridor (rollup): cross-cohort coexistence, unpublished-cohort installation, RemoteResult error flow, pre-migration baseline attribution, bounded retry for boot race, base-only preset precondition, type-surface export drift, host-self safety boundary, install-channel pitfalls (mirror lag, pnpm 11 supply-chain rules, peer-floor prerelease semantics), and the layered validation checklist; based on rc.1 and subject to final-release review
references/precision-checklist.mdAlpha.2 static-migration precision checklist: peer floors, runtime module composition versus type declarations, locale pairing, channel authentication with protocol preservation, landing discipline and citations; pair with scripts/inject-lint.mjs for residue/peer checks and manual route-review candidates
scripts/README.mdExecutable helper scripts: plan-migration (read-only migration planner), verify-runtime (offline runtime contract checker), and ghost-host-check (ghost-host classifier for pre-flight step 1.5)
examples/legacy-plugin/Static fixture for the seven touchpoint classes (never execute)
examples/08-real-web-client-alpha2-migration.mdReal Host + Web Client source migration from an older unsupported corridor segment

Normative background: dsh-community-standard owns manifests, contract coordinates, and negotiation conventions; this skill handles practical upgrades of existing plugins, reusing that classification without redefining it. The official call for contributions is deepseek-harness discussion #5120.

© NanmiCoder, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 63 other files (scripts, references) in skills/plugin-upgrade of NanmiCoder/dsh-auto-mode.

  • SKILL.md
  • SKILL.zh-CN.md
  • evals/evals.json
  • examples/01-simple-client-plugin.en.md
  • examples/01-simple-client-plugin.md
  • examples/02-host-side-plugin.en.md
  • examples/02-host-side-plugin.md
  • examples/03-client-remote-plugin.en.md
  • examples/03-client-remote-plugin.md
  • examples/04-dual-cohort-plugin.en.md
  • examples/04-dual-cohort-plugin.md
  • examples/06-real-world-batch-migration.en.md
  • examples/06-real-world-batch-migration.md
  • examples/07-multi-repo-batch-migration.en.md
  • examples/07-multi-repo-batch-migration.md
  • examples/08-real-web-client-alpha2-migration.en.md
  • examples/08-real-web-client-alpha2-migration.md
  • examples/README.en.md
  • examples/README.md
  • … and 45 more

Open the folder on GitHubat commit 907d663

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in NanmiCoder/dsh-auto-mode, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Plugin Upgrade next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Plugin Upgrade compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Plugin Upgrade this skillNanmiCoder/dsh-auto-mode1651 repos~4.5kAutomated safety check: WarnMIT
OpenGUI Installer for DSHCore-Mate/OpenGUI1.8k—~1.1kAutomated safety check: PassCustom licence
Studyalaliqing/claude-paper344—~2.5kAutomated safety check: NotesMIT
Daily Briefleiting-eric/DailyBrief364—~3kAutomated safety check: NotesMIT
Skin Developerningbainb/deepseek-harness-desktop776—~1.4kAutomated safety check: PassBSD-3-Clause
Find PluginsNagi-ovo/dsh-find-plugins177—~645Automated safety check: NotesBSD-3-Clause

Similar skills

  • OpenGUI Installer for DSH

    Core-Mate/OpenGUI

    Installs and verifies the latest stable OpenGUI release in a DeepSeek Harness web profile on macOS without disturbing existing plugins or settings.

    1.8k GitHub stars~1.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Study

    alaliqing/claude-paper

    A skill your agent uses when the user wants to read, study, analyze, or deeply understand a research paper (PDF).

    344 GitHub stars~2.5k tokensUpdated 1 mo ago
    Research & ScienceAuto-check: notes
  • Daily Brief

    leiting-eric/DailyBrief

    Operational knowledge for the daily-brief digest pipeline (this project).

    364 GitHub stars~3k tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Skin Developer

    ningbainb/deepseek-harness-desktop

    Build a new skin for the dsh-web-ui skin collection (DSH Web GUI) and publish it into the skin-center plugin — scaffold with scripts/dsh-skin-new, author skin.json plus the apply/dispose +…

    776 GitHub stars~1.4k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Find Plugins

    Nagi-ovo/dsh-find-plugins

    用户想给 DeepSeek Harness 找插件时使用:「有没有插件能……」「帮我装个 XX」 「生态里有什么好玩的」。从全 GitHub 的 dsh-plugin topic 发现跨个人与组织的 公开仓库,筛选候选,等用户拍板,先汇报这个插件要什么权限,再从仓库声明判断 安装方式并验证挂载。只负责找和装;开发新插件转 make-dsh-plugin。

    177 GitHub stars~645 tokensUpdated 1 mo ago
    Auto-check: notes
  • Summary

    alaliqing/claude-paper

    Use this for a quick summary of a research paper's core ideas and key points.

    344 GitHub stars~2k tokensUpdated 1 mo ago
    Research & ScienceAuto-check: notes

More from NanmiCoder/dsh-auto-mode

All 10 skills in this repo
  • Dsh Upgrade Audit

    NanmiCoder/dsh-auto-mode

    Audit external compatibility between two DSH (DeepSeek Harness) versions and detect reverts, producing an upgrade-report directory; compares git tags with a source checkout, or published npm…

    165 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Plugin Workflow

    NanmiCoder/dsh-auto-mode

    Coordinate multiple DeepSeek Harness plugin Skills across inspection, migration, runtime debugging, heavy dependencies, testing, naming, and release.

    165 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed
  • Plugin Write

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when creating a DeepSeek Harness plugin, choosing public names for a new external DSH plugin, validating a dsh-plugin.naming.json manifest, checking reviewed central…

    165 GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Plugin Test

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when writing or reviewing tests for DeepSeek Harness plugins, external DSH plugin packages, or package changes in the deepseek-harness repository.

    165 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Dsh Benchmark Case

    NanmiCoder/dsh-auto-mode

    A skill your agent uses when the user hands over a dsh plugin repository (or a real migration commit / version corridor) and wants its upgrade experience extracted into one auto-graded Harbor…

    165 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: warnings
  • Plugin Release

    NanmiCoder/dsh-auto-mode

    Package, publish, and distribute DeepSeek Harness (DSH) plugins — npm pack artifact validation, GitHub/npm/hub release-track selection, tarball overrides installs for the unpublished cohort…

    165 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check: warnings

Works with

Questions about Plugin Upgrade

What does Plugin Upgrade do?

A skill your agent uses for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary…. Plugin Upgrade is an agent skill from NanmiCoder/dsh-auto-mode. Use for DSH plugin compatibility, migration, upgrade, regression, or post-upgrade diagnosis, including read-only review of already-migrated plugin source and version-boundary, API, dependency, activation, or runtime compatibility problems.

When should I use Plugin Upgrade?

Plugin Upgrade fits situations like: DSH plugin compatibility; post-upgrade diagnosis; including read-only review of already-migrated plugin source and version-boundary; runtime compatibility problems.

How do I install Plugin Upgrade in Claude Code?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-upgrade -a claude-code`. Or copy the skill folder (skills/plugin-upgrade in NanmiCoder/dsh-auto-mode) into .claude/skills/plugin-upgrade in your project. Claude Code loads it when a task matches its description.

How do I install Plugin Upgrade in Codex?

Run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-upgrade -a codex`. Or copy the skill folder (skills/plugin-upgrade in NanmiCoder/dsh-auto-mode) into .agents/skills/plugin-upgrade in your project. Codex loads it when a task matches its description.

Can I use Plugin Upgrade in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NanmiCoder/dsh-auto-mode --skill plugin-upgrade -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/plugin-upgrade, .gemini/skills/plugin-upgrade, .github/skills/plugin-upgrade and .opencode/skills/plugin-upgrade in your project.

What does Plugin Upgrade need to run?

Going by SKILL.md and its folder, Plugin Upgrade needs the command-line tools its instructions call (npm, git and cursor). Our summary lists: Node.js.

Does Plugin Upgrade access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Plugin Upgrade safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Plugin Upgrade use?

Plugin Upgrade is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Plugin Upgrade use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 88k tokens, read only when the agent opens those files.

What are the alternatives to Plugin Upgrade?

Skills that share tags, products or a category with Plugin Upgrade: OpenGUI Installer for DSH (Core-Mate/OpenGUI, 1.8k stars), Study (alaliqing/claude-paper, 344 stars), Daily Brief (leiting-eric/DailyBrief, 364 stars) and Skin Developer (ningbainb/deepseek-harness-desktop, 776 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Plugin Upgrade?

NanmiCoder (a GitHub user) maintains it in NanmiCoder/dsh-auto-mode, which has 165 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 29, 2026.

Source: NanmiCoder/dsh-auto-mode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.