On Windows, the available bash tool is limited to Git Bash and PowerShell is disabled.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-bash-on-windows
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:bainianlaoyao/bash-on-windows
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
A DeepSeek Harness plugin (bundle + agent presets): on Windows, the available bash tool is limited to Git Bash and PowerShell is disabled.
Components
| Component | Purpose |
|---|---|
cordis.patch.yml |
bundle patch (dsh.bundle.patch): host-plane flips — tool-bash enabled, tool-pwsh disabled; executors bash-sandbox enabled, pwsh-sandbox disabled; win32 sandbox default danger-full-access + approval never (DSH_PERMISSION_MODE escape hatch; non-Windows untouched); mounts plugins/escalation-inert.mjs |
plugins/escalation-inert.mjs |
standalone plugin: in full-access deployments it hides the sandbox_permissions/justification escalation vocabulary on the shell/fs tools from the model and neutralizes same-mode escalation echoes at runtime — without modifying any official package (the equivalent of the old npx-cache harness-core patch, delivered as an installable plugin) |
presets/standard-bash code-bash cordis-bash |
bash-only preset variants (stock preset + two-line flip), because a bundle patch cannot modify dsh's shipped preset files |
scripts/install.ps1 |
installs the three presets as junctions under $DSH_HOME\.agent-presets\ (-Uninstall supported) |
scripts/build-presets.mjs |
regenerates the variants from a pristine @deepseek-ai/dsh source (after dsh upgrades) |
scripts/check-rows.mjs |
contract test: bash-only invariants of presets and patch + escalation-inert strip/sanitize/family-gate logic |
How it works (three planes, all required)
- Host plane (bundle patch): the
bashtool's executor isbash-sandbox(it spawnsbashfrom PATH = Git Bash on Windows);pwsh-sandboxis disabled, so PowerShell does not exist at runtime. - Session plane (derived presets): the web surface (
dsh-web-app) disables both host shell rows and lets each session mount tools from its preset. Making the model see only bash therefore requires the preset files — which is exactly what used to be a fragile local edit of shipped files. This plugin turns it into distributable derived presets that never touch shipped files. - Escalation inert (escalation-inert): a
danger-full-accessdeployment never denies anything, sosandbox_permissions/justificationare noise fields models habitually echo, and a same-mode echo used to hard-fail every call ("not strictly wider"). The plugin strips the two fields from the model-visible tool catalog insystem-prompt/assemble(the assembledparametersare per-assemblystructuredClonesnapshots, so registered schemas are untouched) and replaces same-mode echo args with a sanitized copy intools/execute, so the official escalation path never sees a no-op request — while genuinely wider requests (requested ≠ standing) pass through unchanged and keep the approval flow. This is the harness-core equivalent delivered as an installable plugin: no official package is modified, and a dsh upgrade cannot lose it.
Install
# 1) Host plane (bundle patch)
dsh plugin --profile web add github:bainianlaoyao/bash-on-windows # GitHub distribution
dsh plugin --profile web add dsh-bash-on-windows # npm distribution (published; prebuilt install skips allowBuilds)
# or copy the rows from cordis.patch.yml into the profile patch layer
# 2) Session plane (three bash-only presets, junction install, no code copy)
powershell -ExecutionPolicy Bypass -File scripts/install.ps1
# 3) Restart dsh, create a session, pick the standard-bash / code-bash / cordis-bash preset
Prerequisite: Git for Windows installed (bash on PATH).
The npm package name is dsh-bash-on-windows (the repo is bash-on-windows; also installable by adding "dsh-bash-on-windows" to dsh.profile.bundles and running pnpm install).
Uninstall
powershell -ExecutionPolicy Bypass -File scripts/install.ps1 -Uninstall
# remove the bundle rows from the profile patch layer manually
Test
node scripts/check-rows.mjs # contract: bash-only invariants across presets and patch
After a dsh upgrade
Run node scripts/build-presets.mjs --src <pristine agent-presets dir> to regenerate the variants and commit them; the host-plane patch needs no changes (target row ids are provided by the official packages).
Security
See SECURITY.md — important: on win32 the default sandbox is danger-full-access with approval never; this is a hard requirement of Git Bash's cygwin runtime.
Related plugins
Other dsh plugins by the same author, all listed in the dsh plugin market:
dsh-codex-mode— a Codex-shaped coding mode for GPT-family models:exec_command/write_stdin/apply_patch/view_image, both OpenAI routes, and graphical subagent types. Its presets are bash-only in the same way.dsh-llm-api-pool— pool several OpenAI-compatible API keys and hot-switch by remaining balance.dsh-session-robustness— keep long sessions recoverable.dsh-easy-archive— two-step inline archiving from the workspace sidebar.
License
MIT. The derived presets come from DeepSeek Harness agent presets (MIT, Copyright (c) 2026 DeepSeek); each preset directory carries a LICENSE.deepseek-harness.
Links
More in this category
yjh051108/dsh-routing-suite★ 6995
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3667
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 208
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 167
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 158
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.