Connects DeepSeek Harness to a deployment-owned AI Asset Hub MCP server and exposes eight reviewed read-only asset tools.
Install
# from a prebuilt release tarball
dsh plugin --profile web add "https://github.com/dff652/deepseek-harness-community-plugins/releases/download/dsh-ai-asset-hub-v0.1.1/dff652-dsh-ai-asset-hub-0.1.1.tgz"
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:dff652/deepseek-harness-community-plugins#path:/packages/dsh-ai-asset-hub
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Configuration-only DeepSeek Harness bundle for an already installed AI Asset
Hub executable. It mounts the official @deepseek-ai/dsh-mcp-client peer and
starts a deployment-owned aiah mcp command; it does not copy AIAH handlers,
store credentials, ship a provider binary or expose build/apply/rollback.
Pinned combination
| Item | Pin |
|---|---|
| DeepSeek Harness | 0.2.0-rc.2 |
@deepseek-ai/dsh-mcp-client |
0.2.0-rc.2 |
Deployment contract
The DSH service must define DSH_AIAH_COMMAND as a non-blank absolute path to
a reviewed aiah executable. A missing, blank or relative value is rejected
during activation; the bundle never asks the operating system to resolve a
provider command through PATH. That executable, its version and its SHA-256
belong to the deployment, not this package. The package always passes mcp as
the only argument.
DSH 0.2.0-rc.2 reports a failed optional plugin as an activation warning
and can keep other plugins running. Rejection means this entry exposes no
AIAH tools; it does not require the whole Web host to exit. The activation
check inspects the settled Loader entry and tool registry.
Install an exact package version or reviewed tarball into a disposable DSH profile first. A source checkout is not release acceptance.
dsh plugin --profile <profile> add -w ./dff652-dsh-ai-asset-hub-0.1.3.tgz
dsh --profile <profile> --dump-config
Remove the bundle without deleting the separately managed provider or its data:
dsh plugin --profile <profile> remove @dff652/dsh-ai-asset-hub
dsh --profile <profile> --dump-config
Keep the prior reviewed tarball and digest before an upgrade so the same commands can restore it if acceptance fails.
Configuration-only activation check
From a repository checkout, the package-specific DSH negative activation check
requires a reviewed DSH runtime and fails clearly if dsh is unavailable. The
script is intentionally kept out of the published five-file package. It uses
a temporary DSH home and never starts a provider or touches a live profile:
node tests/dsh-ai-asset-hub-activation.acceptance.mjs
The check covers unset, blank and relative DSH_AIAH_COMMAND values. It is
kept outside npm test because CI environments without DSH must not silently
skip real activation acceptance.
Reviewed tool names
mcp__aiah__aiah_asset_status
mcp__aiah__aiah_diff
mcp__aiah__aiah_doctor
mcp__aiah__aiah_migration_readiness
mcp__aiah__aiah_migration_status
mcp__aiah__aiah_scan
mcp__aiah__aiah_validate
mcp__aiah__aiah_version
The accepted candidate is read-only. Provider-side tests remain authoritative
for the zero-write invariant because DSH does not turn MCP annotations such as
readOnlyHint into an authorization system.
Package contract
The package declares dsh.bundle.patch in package.json and pins the official
MCP client as an exact peer dependency. Deployment-specific command paths,
provider homes, endpoints and credentials stay outside this package.
The package includes its MIT LICENSE so the license notice
travels with every independently distributed tarball.
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 32466
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 4760
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1132
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 506
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 500
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 450
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.