Huawei Cloud DevKit �� MCP server, 30+ skills, safety hooks, and sandbox deployment for coding agents.
Install
# from npm (prebuilt)
dsh plugin --profile web add huaweicloud-devkit
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:huaweicloud/huaweicloud-devkit
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
中文 | English
Help AI coding agents use Huawei Cloud safely and accurately — a single integration that gives agents cloud knowledge, CLI tooling, and safety guardrails.
Supports OpenCode, Codex, CodeArts Agent, WorkBuddy, DeepSeek Harness (DSH), OfficeAce, Hermes, OpenClaw, and AtomCode.
Prerequisites
- Node.js >= 22
China mainland users: If you experience slow downloads or connection issues with the default npm registry, configure the Huawei Cloud npm mirror:
npm config set registry https://mirrors.huaweicloud.com/repository/npm/Restore the default registry:
npm config delete registry
Quick Start
If
--targetis omitted, the installer auto-detects agents on your machine. When multiple agents are detected, all of them will be installed. Specify--targetto control which agent receives the install.
OpenCode
npx --yes huaweicloud-devkit install --target opencode
Restart the session after installation.
npx --yes huaweicloud-devkit doctor --target opencode
npx --yes huaweicloud-devkit status --target opencode
npx --yes huaweicloud-devkit update --target opencode
npx --yes huaweicloud-devkit uninstall --target opencode
rm -rf ~/.npm/_npx/ # Linux/macOS only; Windows path TBD
Codex
npx --yes huaweicloud-devkit install --target codex
Restart the Codex session after installation.
npx --yes huaweicloud-devkit doctor --target codex
npx --yes huaweicloud-devkit status --target codex
npx --yes huaweicloud-devkit update --target codex
npx --yes huaweicloud-devkit uninstall --target codex
Requires Codex CLI — the
codexcommand must be in PATH. If Codex is installed via WindowsApps (Microsoft Store), use--target codex-desktopinstead. Runcodex --versionto verify CLI availability.
CodeArts Agent
npx --yes huaweicloud-devkit install --target codearts
Restart the session after installation.
npx --yes huaweicloud-devkit doctor --target codearts
npx --yes huaweicloud-devkit status --target codearts
npx --yes huaweicloud-devkit update --target codearts
npx --yes huaweicloud-devkit uninstall --target codearts
Sandbox mode: CodeArts defaults to sandbox mode which blocks KooCLI.
install-hclouddetects this and shows how to resolve it — install KooCLI outside the sandbox terminal, or disable sandbox mode in CodeArts settings (Settings → Chats → Agents Terminal Command Running Mode → Auto Running).
CodeArts Work
npx --yes huaweicloud-devkit install --target codearts-work
Restart the session after installation.
npx --yes huaweicloud-devkit doctor --target codearts-work
npx --yes huaweicloud-devkit status --target codearts-work
npx --yes huaweicloud-devkit update --target codearts-work
npx --yes huaweicloud-devkit uninstall --target codearts-work
CodeArts Work (CodeArts Space, appId:
com.codearts.work) uses user-level config at%USERPROFILE%\.codeartswork\. No project-level.codeartsworkdirectory is created.
WorkBuddy
npx --yes huaweicloud-devkit install --target workbuddy
Restart the session after installation.
npx --yes huaweicloud-devkit doctor --target workbuddy
npx --yes huaweicloud-devkit status --target workbuddy
npx --yes huaweicloud-devkit update --target workbuddy
npx --yes huaweicloud-devkit uninstall --target workbuddy
DeepSeek Harness (DSH)
npx --yes huaweicloud-devkit install --target dsh
Restart the DSH session after installation.
npx --yes huaweicloud-devkit doctor --target dsh
npx --yes huaweicloud-devkit status --target dsh
npx --yes huaweicloud-devkit update --target dsh
npx --yes huaweicloud-devkit uninstall --target dsh
DSH V1 reuses the existing MCP server through
@deepseek-ai/dsh-mcp-client. If the installer reports that the client is not detected, run:npx @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-mcp-client.
OfficeAce
npx --yes huaweicloud-devkit install --target officeace
Restart OfficeAce after installation.
npx --yes huaweicloud-devkit doctor --target officeace
npx --yes huaweicloud-devkit status --target officeace
npx --yes huaweicloud-devkit update --target officeace
npx --yes huaweicloud-devkit uninstall --target officeace
Hermes
npx --yes huaweicloud-devkit install --target hermes
Restart the Hermes session after installation.
npx --yes huaweicloud-devkit doctor --target hermes
npx --yes huaweicloud-devkit status --target hermes
npx --yes huaweicloud-devkit update --target hermes
npx --yes huaweicloud-devkit uninstall --target hermes
Uninstall notes: On Linux, run
rm -rf ~/.npm/_npx/* && npm cache clean --forceafter uninstall to ensure a clean slate. On Windows, close all Hermes sessions first to release file locks, then after uninstall check%LOCALAPPDATA%\hermes\config.yamlfor YAML corruption and manually remove%LOCALAPPDATA%\hermes\huaweicloud-pluginsif any files remain. Safety hooks: The installer configures Hermes shell hooks (config.yaml→hooks.pre_tool_call) to intercept unsafe terminal commands such as credential file reads, environment variable dumps, and unapprovedhcloudwrite operations. Hermes shows a consent prompt the first time; approve it or sethooks_auto_accept: trueinconfig.yamlto auto-accept. MCP Python SDK: The installer automatically installs themcpPython package required by Hermes for MCP tool discovery. If you see[FAIL] Hermes MCP Python SDKindoctor, runpip3 install mcpmanually. Windows: See docs/hermes-windows.md for known issues and workarounds.
OpenClaw
# Recommended (ClawHub)
openclaw plugins install clawhub:huaweicloud-devkit
openclaw plugins uninstall huaweicloud-devkit
openclaw plugins update huaweicloud-devkit
Restart OpenClaw after installation. If prompted for security risk acknowledgment, add --acknowledge-clawhub-risk.
# Or via npx
npx --yes huaweicloud-devkit install --target openclaw
npx --yes huaweicloud-devkit status --target openclaw
npx --yes huaweicloud-devkit update --target openclaw
npx --yes huaweicloud-devkit uninstall --target openclaw
rm -rf ~/.npm/_npx/ # Linux/macOS only; Windows path TBD
AtomCode
npx --yes huaweicloud-devkit install --target atomcode
Restart the AtomCode session after installation.
npx --yes huaweicloud-devkit doctor --target atomcode
npx --yes huaweicloud-devkit status --target atomcode
npx --yes huaweicloud-devkit update --target atomcode
npx --yes huaweicloud-devkit uninstall --target atomcode
Other Agents
Any agent that supports MCP can use the standard config:
{
"mcpServers": {
"huaweicloud-devkit": {
"command": "npx",
"args": ["-y", "-p", "huaweicloud-devkit", "huaweicloud-devkit-mcp"]
}
}
}
No installation required — npx handles everything.
Set
HW_ACCESS_KEY/HW_SECRET_KEYin the MCP configenvfield for project-level credentials.
Install KooCLI
npx --yes huaweicloud-devkit install-hcloud
Configure Credentials
npx --yes huaweicloud-devkit auth init
Synchronizes AK/SK to KooCLI, OBS, and sandbox APIs in one step.
Install All Agents
npx --yes huaweicloud-devkit install --target all
Update All Agents
npx --yes huaweicloud-devkit update --target all
update is incremental — it refreshes installed files without touching your config.
What It Does
- Guided cloud operations — agents get step-by-step guidance for 20+ Huawei Cloud services (ECS, OBS, VPC, RDS, GaussDB, FunctionGraph, APIG, CCE, and more)
- Safety-first execution — all write operations require explicit user approval; credentials and secrets are automatically redacted from output
- Pre-execution risk checks — public exposure, credential leaks, and destructive operations are caught before they run
- Regional awareness — auto-discovers available regions and checks service availability before creating resources
- Sandbox (DevStation) — temporary cloud runtime for web app deployment with instant public URL preview
Supported Services
ECS, OBS, VPC, IAM, RDS, GaussDB, FunctionGraph, APIG, CCE, SMN/DMS, ModelArts, Cloud Eye, CTS, DEW, Billing, CBR, WAF/AAD, DDS/DCS, Deployment, and Getting Started guides.
Documentation
- Architecture
- Safety Model
- Hook Rule Model
- DeepSeek Harness Integration
- Changelog
- KooCLI official docs
Contributors
License
This project is licensed under the Apache-2.0 License. See LICENSE.
Links
More in this category
strukto-ai/mirage#dsh★ 3600
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 302
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
ZSeven-W/dsh-ios★ 275
A live iOS Simulator — and a USB-connected iPhone — inside a DSH conversation: 21 agent tools to boot devices, build and run Xcode projects, drive the UI by accessibility identity, OCR text or list rows, read unified logs and inspect processes, backtraces and leaks, with a streaming sidebar panel you can tap, drag and rotate on.
lire1131/dsh-undo-savepoint★ 144
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 115
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
kanneiren/dsh-network-settings★ 108
Visualize the DSH process network path on Windows or WSL with layered DNS/TCP/TLS/HTTP probes, detect stale proxy configuration, and apply snapshot-guarded repairs.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.