Environment housekeeper for the agent: toolchain inventory (node/pnpm/git/gh/ffmpeg/browsers), scratch/cache scan with whitelist-guarded one-click cleanup, and the machine rules file (AGENTS.md) editor - all in the Web GUI settings.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:guo6x/dsh-housekeeper
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
中文说明 · DeepSeek Harness plugin
Keep your agent's hands clean: toolchain inventory, two-step cache cleanup, and machine rules (AGENTS.md) editing — all inside the DSH Web GUI settings. Zero runtime dependencies, one command install.
- 📋 Toolchain inventory — auto-detects node/pnpm/git/gh/ffmpeg/Edge/Chrome locations and versions
- 🗑️ Honest cache cleanup — scans the
.tmpand cache directories agents leave behind: size / file count / mtime, 4000-file truncation markers, 30-day-untouched highlighting, click-to-expand content preview; create a plan, then confirm deletion - 🛡️ Whitelist protection — only project
.tmpdirs and cache-root children are deletable;..escapes, symlink escapes, and system paths are rejected, with a realpath re-check before every delete - 📝 Machine rules editor with a safety net — read/write
~/.dsh/AGENTS.md(the global rules every agent session loads), auto-backup of the previous version on every save, one-click restore, live on save - 🌍 Configurable — scan roots default per platform (Windows:
D:\github/D:\environment\cache), editable in the panel, overridable via env vars - 🤖 Agent tools —
housekeeper_report(inventory + disk report),housekeeper_plan(review only), andhousekeeper_clean(executes a single-use token)
Install — copy, paste, confirm
# Install from GitHub — this is the supported release channel.
dsh plugin --profile web add github:guo6x/dsh-housekeeper
Restart a running dsh web process, then open Settings → Plugins → 环境管家. Seeing the Toolchain inventory section means installation is complete.
Requirements: the DSH web profile and Node ≥ 22. The plugin needs no account, API key, or extra service.
Developing from a checkout instead? Run dsh plugin --profile web add . from the repository directory. The committed lib/ files mean GitHub installs do not run a build script.
First safe pass in 60 seconds
Nothing in this walkthrough deletes files or writes rules.
- Open Settings → Plugins → 环境管家.
- Inspect the detected toolchain and cache candidates; click a row to preview its contents.
- Do not select anything yet. You have verified the inventory and the candidate list without changing the machine.
For the same non-destructive proof through chat, paste:
Run
housekeeper_reportand summarize the detected toolchain plus the largest cache candidates. Do not create a cleanup plan, delete files, or change machine rules.
When you are ready to clean, select only scratch directories you recognize and choose Generate cleanup plan. Read the approved and rejected paths; deletion remains impossible until you explicitly use that plan’s one-time confirmation action.
The same reviewed flow is available to an agent: ask for housekeeper_report, review housekeeper_plan, and only then allow the returned token to reach housekeeper_clean.
If the panel is missing
- Confirm the plugin is installed in the web profile:
dsh plugin --profile web list dsh-housekeeper. - Restart the
dsh webprocess after installing; a browser refresh alone cannot load new host code. - Check that Node is version 22 or newer. The inventory can run without Edge, Chrome, or any cloud credential.
Security model
- All routes accept loopback clients only (403 otherwise)
- Cleanup whitelist — a path is deletable only when ALL hold:
- under
<projects-root>\<repo>\ .tmp\, or a direct child of<cache-root>\ - normalized path stays inside the whitelist root (no
..) realpathstill lands inside the whitelist root (no symlink escapes)- the whitelist roots and repo dirs themselves are never deletable
- under
- Two-step confirmation — a cleanup plan exists only in memory; its confirmation token expires after five minutes, is single-use, and every path is checked against the whitelist and
realpathagain immediately before deletion - The rules endpoint reads/writes
$DSH_HOME/AGENTS.mdonly; the path is fixed - No telemetry, no external network calls
How it works
GUI settings ──fetch──▶ /housekeeper/state|clean/plan→clean|rules (loopback) ──▶ host plugin
├─ probe: candidate paths + PATH lookup + versions
├─ scan: rule-driven walk with sizes (4000-file cap)
├─ clean: whitelist + realpath → plan → single-use confirmation → re-check, then rm
└─ rules: read/write $DSH_HOME/AGENTS.md (64KB cap)
Develop
pnpm install
pnpm test # build, safety regression suite, and release-package check
MIT licensed. Issues and ideas welcome.
Links
More in this category
yjh051108/dsh-routing-suite★ 7003
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3666
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 166
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 155
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.