DeepSeek Harness Plugin

WODE25500/dsh-ssh-pro

Stars ★ 1 Category Remote & Mobile Added 2026-08-21

Enhanced SSH ops: connectivity testing, remote ls, ssh-config import, known_hosts fingerprint checks and multi-host exec.

Install

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:WODE25500/dsh-ssh-pro

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Enhanced SSH ops for DeepSeek Harness — fills the easy-to-overlook gaps of the base dsh-ssh plugin: connectivity testing, remote directory listing, ~/.ssh/config import, known_hosts fingerprint checks, and one-shot exec across many hosts.

Independent community project. Reuses the host store of @linxin666/dsh-ssh (Apache-2.0) but has no runtime dependency on it — only the ssh2 library. Coexists with any SSH plugin.

Why

The base dsh-ssh ships ssh_list/exec/upload/download/tunnel/cluster plus a full GUI, but leaves five engine capabilities unexposed to the agent — the classic "exists but easy to overlook" gap:

Missing capability Base plugin This plugin
connectivity test engine test(), no tool ✅ ssh_test
remote dir listing engine ls(), no tool ✅ ssh_ls
ssh-config import store has importFromSshConfig, no tool ✅ ssh_import
fingerprint check none ✅ ssh_keyscan
multi-host batch cluster tied to GUI panel ✅ ssh_multi_exec (standalone)

Features

  • 5 native tools: ssh_test / ssh_ls / ssh_import / ssh_keyscan / ssh_multi_exec
  • Reads ~/.dsh/dsh-ssh.json directly (interops with dsh-ssh GUI config)
  • ssh_multi_exec filters by alias/environment/tags with concurrency control
  • Bundled SKILL.md, Schemastery config, bundle patch layer
  • Security model mirrors dsh-ssh: 0600 host store, verbatim output, no key leakage

Prerequisites

  • DeepSeek Harness (dsh)
  • ssh2 npm package (plugin dependency)
  • Hosts configured via the dsh-ssh GUI or ~/.dsh/dsh-ssh.json (ssh_import can populate from ~/.ssh/config)

Install

# in a profile's cordis.patch.yml
- insert:
    - id: ssh-pro
      name: './src/index.js'
      config:
        storePath: ~/.dsh/dsh-ssh.json
        sshConfigPath: ~/.ssh/config
        timeoutMs: 30000
# or local dev
pnpm dsh web --patch ./dsh-ssh-pro/cordis.patch.yml

Tools

Tool Behavior
ssh_test connect, run true, report latency/error
ssh_ls SFTP directory listing (name/type/size/mtime)
ssh_import parse ~/.ssh/config into the host store (skips existing/wildcards)
ssh_keyscan check whether a host is in known_hosts
ssh_multi_exec concurrent exec across hosts (alias/env/tag filters)

Config

Key Default Purpose
storePath ~/.dsh/dsh-ssh.json host store path
sshConfigPath ~/.ssh/config import source
knownHostsPath ~/.ssh/known_hosts fingerprint check
timeoutMs 30000 default per-host timeout

Security

  • Passwords/passphrases live in the 0600 host store; tools never emit keys
  • ssh_multi_exec returns output verbatim (env etc. may bring back remote env vars)
  • ssh_keyscan is read-only; a "new host" notice means confirm the fingerprint with the user

Layout

dsh-ssh-pro/
  src/index.js            # plugin entry: 5 tools + ssh2 engine + config
  skills/ssh-pro/SKILL.md # agent skill
  docs/                   # docs
  cordis.patch.yml        # bundle patch layer

License

Apache-2.0.

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.