Enhanced SSH ops: connectivity testing, remote ls, ssh-config import, known_hosts fingerprint checks and multi-host exec.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:WODE25500/dsh-ssh-pro
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Enhanced SSH ops for DeepSeek Harness — fills the easy-to-overlook gaps of
the base dsh-ssh plugin: connectivity testing, remote directory listing,
~/.ssh/config import, known_hosts fingerprint checks, and one-shot exec
across many hosts.
Independent community project. Reuses the host store of @linxin666/dsh-ssh (Apache-2.0) but has no runtime dependency on it — only the
ssh2library. Coexists with any SSH plugin.
Why
The base dsh-ssh ships ssh_list/exec/upload/download/tunnel/cluster plus a
full GUI, but leaves five engine capabilities unexposed to the agent — the
classic "exists but easy to overlook" gap:
| Missing capability | Base plugin | This plugin |
|---|---|---|
| connectivity test | engine test(), no tool |
✅ ssh_test |
| remote dir listing | engine ls(), no tool |
✅ ssh_ls |
| ssh-config import | store has importFromSshConfig, no tool |
✅ ssh_import |
| fingerprint check | none | ✅ ssh_keyscan |
| multi-host batch | cluster tied to GUI panel | ✅ ssh_multi_exec (standalone) |
Features
- 5 native tools:
ssh_test/ssh_ls/ssh_import/ssh_keyscan/ssh_multi_exec - Reads
~/.dsh/dsh-ssh.jsondirectly (interops with dsh-ssh GUI config) ssh_multi_execfilters by alias/environment/tags with concurrency control- Bundled
SKILL.md, Schemastery config, bundle patch layer - Security model mirrors dsh-ssh: 0600 host store, verbatim output, no key leakage
Prerequisites
- DeepSeek Harness (dsh)
ssh2npm package (plugin dependency)- Hosts configured via the dsh-ssh GUI or
~/.dsh/dsh-ssh.json(ssh_importcan populate from~/.ssh/config)
Install
# in a profile's cordis.patch.yml
- insert:
- id: ssh-pro
name: './src/index.js'
config:
storePath: ~/.dsh/dsh-ssh.json
sshConfigPath: ~/.ssh/config
timeoutMs: 30000
# or local dev
pnpm dsh web --patch ./dsh-ssh-pro/cordis.patch.yml
Tools
| Tool | Behavior |
|---|---|
ssh_test |
connect, run true, report latency/error |
ssh_ls |
SFTP directory listing (name/type/size/mtime) |
ssh_import |
parse ~/.ssh/config into the host store (skips existing/wildcards) |
ssh_keyscan |
check whether a host is in known_hosts |
ssh_multi_exec |
concurrent exec across hosts (alias/env/tag filters) |
Config
| Key | Default | Purpose |
|---|---|---|
storePath |
~/.dsh/dsh-ssh.json |
host store path |
sshConfigPath |
~/.ssh/config |
import source |
knownHostsPath |
~/.ssh/known_hosts |
fingerprint check |
timeoutMs |
30000 |
default per-host timeout |
Security
- Passwords/passphrases live in the 0600 host store; tools never emit keys
ssh_multi_execreturns output verbatim (envetc. may bring back remote env vars)ssh_keyscanis read-only; a "new host" notice means confirm the fingerprint with the user
Layout
dsh-ssh-pro/
src/index.js # plugin entry: 5 tools + ssh2 engine + config
skills/ssh-pro/SKILL.md # agent skill
docs/ # docs
cordis.patch.yml # bundle patch layer
License
Apache-2.0.
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8370
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
zhu1090093659/dsh-web#packages/dsh-ssh★ 8370
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
saya-ch/dsh-mobile★ 371
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
ZSeven-W/dsh-ios★ 312
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
liguobao/ds-harness-remote★ 266
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
wenbin-wb/dsh-bridge★ 184
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.