Back to home

xiayuhkust

dsh-shell-kit

Plugins for DeepSeek Harness (dsh): secret-guard blocks reading secret/PII files, script-exec runs scripts via temp file to avoid Windows quoting pitfalls.

Stars
0
Language
JavaScript
Created
Aug 15, 2026
Updated
Aug 15, 2026

Introduction

dsh-shell-kit

English | 中文

Plugins that harden and smooth a DeepSeek Harness (dsh) agent's use of the host's shell and file tools: one governs what it may read (blocking secrets/PII), the other smooths how it runs scripts (writing them to disk to avoid escaping pain). Both are lightweight with no extra runtime dependencies. One repository, one independent npm package per plugin. Targets the dsh 0.1.x developer preview; interfaces may shift with dsh.

Plugins

PackageWhat it does
dsh-plugin-secret-guardBlocks model-facing tools from reading secret/PII files (.env, private keys, credentials, …), denying with a reason via tools/pre-execute.
dsh-plugin-script-execAdds a run_script tool: write the script to disk, then run it — avoiding the quote-escaping problems of inline scripts on Windows (pwsh files get a UTF-8 BOM).

See each package's README for install, config, and tool parameters.

Install

dsh plugin --profile web add -w <package-name>

Mount it in the profile's cordis.patch.yml (use - insert: to add a new row, not a bare - id:):

- insert:
    - id: secret-guard
      name: dsh-plugin-secret-guard

Restart dsh web to take effect. dsh --profile web --dump-config confirms the row is present.

Conventions

  • Each plugin is an independent npm package (dependency weights differ, so install units stay separate); sharing one repo keeps maintenance cheap.
  • Package names are prefixed dsh-plugin-*, and the repo carries the dsh-plugin GitHub topic.
  • Plugins take zero @deepseek-ai/dsh-* imports (the dsh 0.1.x-rc loader does not resolve host internal imports for third-party plugins), constructing the tool object directly when registering.

License

MIT