← Back to home@LJH-snow

dsh-tool-aws

No description

Stars
0
Language
TypeScript
Created
Oct 4, 2026
Updated
Oct 6, 2026

Introduction

dsh-tool-aws

English | 中文

Read-only AWS tools for DeepSeek Harness (dsh) as a Cordis plugin. The agent can verify credentials and inspect EC2, S3, Lambda, and CloudWatch resources. Requests are signed with AWS Signature Version 4 using WebCrypto.

Install

npm install @libai168/dsh-tool-aws

Requires @deepseek-ai/cordis (^4.0.1) and @deepseek-ai/dsh-tools (^0.1.0-rc.6) as peer dependencies.

Configuration

- name: 'github:LJH-snow/dsh-tool-aws'
  config:
    region: 'us-east-1'
    accessKeyId: 'AKIA...'
    secretAccessKey: '...'
    # sessionToken: '...'   # temporary credentials
    # endpoint: '...'       # optional public HTTP(S) root endpoint
    # timeoutMs: 15000

The optional endpoint must be an absolute http:// or https:// root URL (for example, https://aws-api.example.test/). Only publicly reachable hosts are allowed. Localhost, loopback, private, link-local, carrier-grade NAT, multicast, and every IANA special-purpose block — reserved/documentation/benchmark ranges, the 2001::/23 IETF protocol assignments prefix, deprecated site-local, SRv6 SIDs, AS112, and IPv4-mapped/NAT64 forms — are rejected, together with hostnames resolving to any such address. Credentials, query strings, fragments, and non-root paths are not allowed. DNS failures are rejected before any request is sent.

Use an IAM user or role with read-only permissions (ec2:DescribeInstances, s3:ListAllMyBuckets, lambda:ListFunctions, logs:DescribeLogGroups, logs:FilterLogEvents, cloudwatch:ListMetrics, sts:GetCallerIdentity).

Tools

All tools are read-only (kind: 'read' or 'search').

ToolDescription
aws_sts_get_caller_identityVerify credentials and return account/user/ARN
aws_list_ec2_instancesList EC2 instances with filters and pagination
aws_list_s3_bucketsList S3 buckets in the account
aws_list_lambda_functionsList Lambda functions in the region
aws_list_cloudwatch_log_groupsList CloudWatch log groups with prefix filter
aws_get_cloudwatch_log_eventsRead log events with stream/time-range filters
aws_list_cloudwatch_metricsList CloudWatch metrics by namespace/name
aws_ecr_list_repositoriesList ECR repositories in the region
aws_ecr_list_imagesList image tags/digests in one ECR repository
aws_ecr_describe_imagesDescribe ECR images with scan status and severity counts

Error contract

  • Missing credentials: { found: false, reason }.
  • AWS-side errors throw AwsError with the HTTP status and error code; tools surface them as { found: false, reason }.
  • All requests support timeoutMs (default 15s) and propagate the caller's AbortSignal.

Development

npm install
npm run typecheck
npm test
npm run build

License

MIT