Connects DeepSeek Harness to OOMOL-managed apps and services, with progressive Connector Action discovery and execution plus an in-app panel for managing Provider connections.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-oomol
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:oomol-lab/dsh-oomol
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Use OOMOL Connector Actions from DeepSeek Harness through progressive MCP discovery.
dsh-oomol supports OOMOL Hosted and self-hosted OpenConnector. One plugin instance connects to one Connector endpoint.
Requirements
- Node.js 22.19 or later within Node.js 22, or Node.js 24+
- DeepSeek Harness
0.2.0-rc.2or later within 0.2.0 - An OOMOL account for OOMOL Hosted, or a running OpenConnector instance for self-hosted use
Install
Install the plugin into the Web profile and restart Harness:
dsh plugin --profile web add -w dsh-oomol
dsh web
The plugin appears on the Plugins page as dsh-oomol. Open it to configure the Connector key.
OOMOL Hosted
The package connects to OOMOL Hosted by default:
- id: oomol
name: dsh-oomol
config:
endpoint: https://connector.oomol.com/v1/mcp
teamNameEnv: OOMOL_TEAM_NAME
serverName: oomol
toolCallTimeoutMs: 60000
failOnStartupError: false
Create an OOMOL MCP API key in OOMOL Console, then save it on the plugin page. Harness Credentials stores the key under OOMOL_MCP_API_KEY.
Managed environments can provide it at launch:
export OOMOL_MCP_API_KEY="api_..."
dsh web
Set a team identity when needed:
export OOMOL_TEAM_NAME="your-team"
dsh web
The Connections button opens the native Harness panel for OOMOL Hosted accounts.
Self-hosted OpenConnector
Override the endpoint in the profile's cordis.patch.yml:
- update:
id: oomol
config:
endpoint: http://127.0.0.1:3000/mcp
The plugin recognizes every non-official endpoint as self-hosted. Local OpenConnector deployments can run without authentication. Deployments with runtime authentication use the key stored under OOMOL_CONNECT_RUNTIME_TOKEN:
export OOMOL_CONNECT_RUNTIME_TOKEN="oct_..."
dsh web
You can also save the runtime API key on the plugin page. Create persistent runtime keys in the OpenConnector Console Access page.
Self-hosted HTTP endpoints are limited to localhost, 127.0.0.1, and [::1]. Remote deployments use HTTPS:
- update:
id: oomol
config:
endpoint: https://connect.example.com/mcp
The Connections button opens the endpoint origin, such as https://connect.example.com, where OpenConnector serves its Console.
Custom API key environment name
Both modes support an explicit credential reference:
- update:
id: oomol
config:
endpoint: https://connect.example.com/mcp
apiKeyEnv: MY_CONNECT_RUNTIME_TOKEN
Harness Credentials resolves apiKeyEnv first and the launch environment second.
Use Connector Actions
Start with discovery:
Show me the connectors available to this account.
Find Actions that can create a calendar event and inspect the selected Action schema.
For operations with external effects, include the target account and proposed arguments in your request before execution.
How it works
The plugin mounts DeepSeek Harness's Streamable HTTP MCP client with the selected Connector endpoint. Connector Actions remain progressively discoverable, keeping the permanent Harness tool surface small.
OOMOL Hosted stores Provider credentials in OOMOL Connector. Self-hosted deployments store them in OpenConnector. Harness stores only the Connector client key selected by apiKeyEnv.
The browser receives the credential reference and status metadata. Connector API keys and Provider credentials stay in Host-side secret boundaries.
See Architecture for implementation details.
Configuration
| Field | Default | Purpose |
|---|---|---|
endpoint |
https://connector.oomol.com/v1/mcp |
Streamable HTTP MCP endpoint |
apiKeyEnv |
Derived from endpoint |
Harness credential reference and launch environment name |
teamName |
unset | OOMOL Hosted team identity |
teamNameEnv |
OOMOL_TEAM_NAME |
OOMOL Hosted team environment name |
serverName |
oomol |
Harness MCP tool namespace |
toolCallTimeoutMs |
60000 |
Tool call timeout |
failOnStartupError |
false |
Fail Harness startup when MCP discovery fails |
Derived credential references:
| Endpoint mode | Default reference | Required |
|---|---|---|
| OOMOL Hosted | OOMOL_MCP_API_KEY |
Yes |
| Self-hosted | OOMOL_CONNECT_RUNTIME_TOKEN |
Depends on the OpenConnector deployment |
Troubleshooting
| Symptom | Action |
|---|---|
| Plugin missing from the Plugins page | Install it in the web profile and restart dsh web |
| OOMOL Hosted shows Not configured | Save an OOMOL MCP API key on the plugin page |
| Self-hosted returns Unauthorized | Save a runtime API key created by that OpenConnector instance |
| Self-hosted Console link returns 404 | Open the Console URL configured by the OpenConnector deployment |
| Expected app is missing | Open the relevant Connector Console and configure the Provider connection |
| Connections tab does not appear | Open a Session first; the Connections tab lives in that Session's right sidebar |
Run local diagnostics:
pnpm run doctor
Security
- Store Connector API keys in Harness Credentials or the launch environment.
- Use HTTPS for remote self-hosted endpoints.
- Review destructive, externally visible, permission-changing, and broad-sharing Actions before execution.
- Treat an ambiguous side-effecting call as an unknown outcome and inspect the Provider before retrying.
- Report vulnerabilities through SECURITY.md.
Development
pnpm install --frozen-lockfile
pnpm check
Build and install the checkout into a Web profile:
pnpm build
dsh plugin --profile web add -w "$(pwd)"
License: MIT
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 31531
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 3949
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1130
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 499
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 477
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 441
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.