Docker tools for agents: ps/images/logs/inspect/exec/manage/health with JSON output, env-configurable CLI path, approval-gated exec and zero runtime dependencies.
Install
# from npm (prebuilt)
dsh plugin --profile web add @stardustlc/dsh-docker
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:STARDUSTLC666/dsh-docker
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
dsh-docker
Your agent can manage containers now: seven tools covering containers, images, logs, inspection, in-container exec, lifecycle management, and health checks.
DSH (DeepSeek Harness) container-management plugin: runs the docker CLI through the official subprocess service with shell-free argv arrays, approval gates on docker_exec and destructive lifecycle actions, and zero runtime dependencies.
Compatibility
Validation host: Harness 0.2.0-rc.1 built from official sources (commit 407e65c8) with Node 24.16.0 on 2026-09-28. All 36 plugin tests pass in an isolated environment; all 18 plugins mount together in one host registering 7 tools, with tool schemas and health-check contracts passing. No live ports or external services were exercised in this round.
2026-09-13 fix: retain the service receiver when calling subprocess.spawn, preventing failures caused by passing the method as an unbound callback. Verified against a real isolated host subprocess service. docker_ps passes through the real host subprocess service with a Node child producing fixed Docker output. A live Docker daemon was not used.
Installation
dsh plugin --profile web add @stardustlc/dsh-docker
Requires Docker installed locally (docker version should work); use dockerPath when it is not on PATH.
Uninstall
dsh plugin --profile web remove @stardustlc/dsh-docker
Then restart the web service. To clean up fully, also remove the plugin entry from your profile cordis.patch.yml if you overrode it.
Configuration
- id: docker
name: '@stardustlc/dsh-docker'
config:
# dockerPath: C:\Program Files\Docker\Docker\resources\bin\docker.exe
dockerPath: docker # optional; or use the DSH_DOCKER_PATH env var
timeoutMs: 60000 # per-operation timeout (default 60s, 5s - 10min)
# execApproval: false # disable the docker_exec approval gate (default true)
# manageApproval: false # disable approval for stop/restart/rm (default true; not recommended)
Tools
| Tool | Purpose | Safety |
|---|---|---|
docker_ps |
List containers (status/image/state, filterable) | — |
docker_images |
List local images (repository/tag/size/created, dangling-only filter) | — |
docker_logs |
Tail container logs (line clamp, short follow) | — |
docker_inspect |
Container details (image/state/ports) | — |
docker_exec |
Run a command inside a container | Approval gate + container-name validation |
docker_manage |
start / stop / restart / rm | Approval gate for stop/restart/rm |
docker_health |
Check Docker daemon and safety settings | — |
Examples
docker_ps {}
docker_ps { all: true, name: web }
docker_images { dangling: true }
docker_logs { container: web, tail: 200 }
docker_inspect { container: web }
docker_exec { container: web, command: 'df -h' }
docker_manage { container: web, action: restart }
Safety
- No shell: every argument is its own argv element — command injection is impossible
- Approval gates: docker_exec and docker_manage stop/restart/rm ask first; headless environments without an approval channel are denied
- Container-name validation: only
[A-Za-z0-9][A-Za-z0-9_.:-]*accepted — no argument injection - Timeout clamps: 5s - 10min per operation; follow mode capped at an extra 30s
- Log clamping: tail 1-2000 lines
Development
pnpm install
pnpm test # build + 35 tests
License
MIT
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 31531
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 3949
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1130
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 499
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 477
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 441
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.