Evidence-backed inspector for DSH Web built-in capabilities: runtime/config provenance, compatibility and drift diagnostics, plus fail-closed controls for nine reviewed UI leaves.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-builtin-toggles
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:Starfie1d1272/dsh-builtin-toggles
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
简体中文 | English
An evidence-backed built-in capability Inspector for DeepSeek Harness Web. Its nine reviewed UI controls are a deliberately tiny, fail-closed adjunct—not a general plugin switcher.
Unofficial community plugin. It is not affiliated with or supported by DeepSeek Harness.
Find it under Settings → Plugins → Built-ins. The Host generates the inspection: reviewed evidence, profile overrides, persistence preflight, compatibility, and mutation eligibility are server-computed. Inspection rows are attributed by composition scope: Host/profile composition and per-session Agent Preset composition legitimately share ids (e.g. tool-bash) without being misreported as duplicates.

Captured against published @deepseek-ai/dsh@0.1.0-rc.6 with the standard Agent Preset and the current plugin version; nothing is fabricated. The Host does not expose a stable runtime release identity, so Compatibility honestly shows unverified / runtime identity unavailable. (Two further real captures live in docs/assets/: builtin-toggles-anomalies.png shows the anomalies-only view at zero on the clean rc.6 + standard Agent Preset, and builtin-toggles-agent-preset-scope.png shows the 26 per-session Agent Preset composition rows.)
Install
Prerequisite: an initialized DSH web profile. Later public DSH releases may still install or run, but do not become a supported/reviewed baseline without an explicit review.
With the dsh CLI installed:
dsh plugin --profile web add dsh-builtin-toggles
dsh web
With npx (no global dsh install needed):
npx @deepseek-ai/dsh plugin --profile web add dsh-builtin-toggles
npx @deepseek-ai/dsh web
Restart the DSH web/gateway so it reads the bundle at startup.
What it does
- Capability Inspector / Doctor: inspects every current Web Loader capability, including external, unreviewed, and anomalous rows. It presents runtime state, profile-override tri-state, Agent Preset ownership, composition scope (Host vs Agent Preset composition), review provenance, dependency evidence, compatibility, and server-computed mutation eligibility.
- Filters and diagnostics: filters by ID/package, category, management plane, composition scope, policy, verification, runtime, and anomalies; copied diagnostics redact local paths and configuration contents, and copy feedback appears next to the button.
- Composition-scope modeling: duplicate detection uses the Loader's public
Entry.id(qualified by the owning-tree entry chain). Legal same ids across the Host and the standard Agent Preset belong to different composition scopes and never produceduplicate_runtime_idornew_official_entry; a genuine collision inside one scope still drifts and fails closed. Agent Preset rows are locked server-side by the inspection DTO itself —policy=locked(reasonagent-preset),mutationEligibility=ineligible— so they can never borrow an allowlisted Host row's manageability or become Web-profile manageable items. The v1profileOverride.state/profilePersistence.statusvalue domains stay unchanged (preset rows conservatively projectunavailable/unwritable); the additiveconfiguration.profileApplicabilityfield (applicable/not-applicable) carries the real "not governed by the Web profile" semantics, and that not-applicable projection is never treated as an anomaly. - Agent Preset plane: capabilities such as
tool-*andplan-modeare assembled per session by Agent Presets and are never presented as profile overrides. - Nine reviewed UI controls: only
ui-deliverables,ui-jobs,ui-goal,ui-message-feedback,ui-model-selection,ui-agent-preset,ui-skill,ui-subagent, andui-trajectory. These presentation leaves apply to the Web profile and all its sessions, do not edit Agent Presets, persist force actions, and restore inheritance through DSH profile/HMR recomposition. - Fail closed: core services, Agent capabilities, third-party, and unknown entries remain locked. This package has no generic plugin manager, marketplace, or plugin install/update lifecycle.
- Inspection API v1:
GET /api/builtin-toggles/v1/inspectionis the stable, presentation-free machine interface for inventory, reviewed baseline, configuration state, compatibility, and eligibility. See Inspection API v1.
Security and transport access
Manageability comes solely from the exact MANAGEABLE_IDS allowlist in src/policy.ts. Every POST repeats server-side checks for policy, body, entry, @deepseek-ai/* package identity, self protection, eligibility, and the profile writer; the browser is never an authorization boundary.
Loopback and explicitly trusted hosts can read the API. Configuration mutation additionally requires loopback same-origin access. trustedHosts mitigates DNS rebinding; it is not authentication. v1 access.mutation reports the authoritative request-scoped transport decision, separately from per-capability mutationEligibility. A remote Inspector is read-only.
Compatibility and support policy
- The only reviewed/tested baseline is the published
@deepseek-ai/dsh-base@0.1.0-rc.6and@deepseek-ai/dsh-web-app@0.1.0-rc.6artifacts, not a>= rc.6version-range promise. - Later public releases may still install or run, but are not a supported/reviewed baseline before explicit review. The current-public workflow only produces an observational drift report; it never upgrades support.
- When a live Host lacks a stable public runtime release identity, inspection honestly remains
unverified; it never guesses from module paths, private fields, or a version string.runtime_release_identity_unavailablealone only yieldsunverified, neverdrifted. - Anomalies-only agrees with the compatibility evaluator: legal runtime augmentations the evaluator accepted (Host-generated helper ids, per-session Agent Preset rows) are not anomalies merely for lacking a baseline row; real drift, failed lifecycle, profile unavailable/unwritable, and new official structural changes still show.
- Compatibility and mutation eligibility are distinct: missing identity never fabricates a verified claim, and each mutation still needs independent safe-leaf, structural-drift, and writer checks.
See COMPATIBILITY.md for review boundaries and SECURITY.md for reporting.
For distributions / integrators
- Package identity:
dsh-builtin-toggles; display product: Evidence-backed Built-in Capability Inspector; Web profile only. - Pin exact reviewed versions rather than drifting automatically. The reviewed baseline is the rc.6 artifacts above; the distribution/integrator remains responsible for an explicit baseline and compatibility review.
- The v1 read API is a stable machine interface. Trusted-host inspection is read-only, configuration mutation is loopback-only, and all mutation fails closed.
- This package does not manage third-party plugin lifecycles, provide a marketplace, or edit Agent Presets. Before uninstalling, use Restore inheritance on any item this package forced, which removes only its top-level literal
disabledoverride.
Uninstall
With the dsh CLI installed:
dsh plugin --profile web remove dsh-builtin-toggles
With npx:
npx @deepseek-ai/dsh plugin --profile web remove dsh-builtin-toggles
Restart afterward. The package does not remove arbitrary user profile content.
Development
pnpm install
pnpm typecheck
pnpm test
pnpm build
pnpm pack:check
See Contributing. MIT.
Links
More in this category
yjh051108/dsh-routing-suite★ 7000
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3663
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 165
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 152
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.