DeepSeek Harness Plugin

dff652/deepseek-harness-community-plugins#dsh-ai-asset-hub

Stars ★ 1 Category Tools & Capabilities Added 2026-08-24

Connects DeepSeek Harness to a deployment-owned AI Asset Hub MCP server and exposes eight reviewed read-only asset tools.

Install

# from a prebuilt release tarball

dsh plugin --profile web add "https://github.com/dff652/deepseek-harness-community-plugins/releases/download/dsh-ai-asset-hub-v0.1.1/dff652-dsh-ai-asset-hub-0.1.1.tgz"

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:dff652/deepseek-harness-community-plugins#path:/packages/dsh-ai-asset-hub

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Configuration-only DeepSeek Harness bundle for an already installed AI Asset Hub executable. It mounts the official @deepseek-ai/dsh-mcp-client peer and starts a deployment-owned aiah mcp command; it does not copy AIAH handlers, store credentials, ship a provider binary or expose build/apply/rollback.

Pinned combination

Item Pin
DeepSeek Harness 0.2.0-rc.2
@deepseek-ai/dsh-mcp-client 0.2.0-rc.2

Deployment contract

The DSH service must define DSH_AIAH_COMMAND as a non-blank absolute path to a reviewed aiah executable. A missing, blank or relative value is rejected during activation; the bundle never asks the operating system to resolve a provider command through PATH. That executable, its version and its SHA-256 belong to the deployment, not this package. The package always passes mcp as the only argument.

DSH 0.2.0-rc.2 reports a failed optional plugin as an activation warning and can keep other plugins running. Rejection means this entry exposes no AIAH tools; it does not require the whole Web host to exit. The activation check inspects the settled Loader entry and tool registry.

Install an exact package version or reviewed tarball into a disposable DSH profile first. A source checkout is not release acceptance.

dsh plugin --profile <profile> add -w ./dff652-dsh-ai-asset-hub-0.1.3.tgz
dsh --profile <profile> --dump-config

Remove the bundle without deleting the separately managed provider or its data:

dsh plugin --profile <profile> remove @dff652/dsh-ai-asset-hub
dsh --profile <profile> --dump-config

Keep the prior reviewed tarball and digest before an upgrade so the same commands can restore it if acceptance fails.

Configuration-only activation check

From a repository checkout, the package-specific DSH negative activation check requires a reviewed DSH runtime and fails clearly if dsh is unavailable. The script is intentionally kept out of the published five-file package. It uses a temporary DSH home and never starts a provider or touches a live profile:

node tests/dsh-ai-asset-hub-activation.acceptance.mjs

The check covers unset, blank and relative DSH_AIAH_COMMAND values. It is kept outside npm test because CI environments without DSH must not silently skip real activation acceptance.

Reviewed tool names

mcp__aiah__aiah_asset_status
mcp__aiah__aiah_diff
mcp__aiah__aiah_doctor
mcp__aiah__aiah_migration_readiness
mcp__aiah__aiah_migration_status
mcp__aiah__aiah_scan
mcp__aiah__aiah_validate
mcp__aiah__aiah_version

The accepted candidate is read-only. Provider-side tests remain authoritative for the zero-write invariant because DSH does not turn MCP annotations such as readOnlyHint into an authorization system.

Package contract

The package declares dsh.bundle.patch in package.json and pins the official MCP client as an exact peer dependency. Deployment-specific command paths, provider homes, endpoints and credentials stay outside this package.

The package includes its MIT LICENSE so the license notice travels with every independently distributed tarball.

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.