DeepSeek Harness Plugin

wenbin-wb/dsh-bridge

Stars ★ 184 Downloads (30d) 10,699 Category Remote & Mobile Added 2026-08-24 npm @wenbin_wb/dsh-bridge

Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.

Install

# from npm (prebuilt)

dsh plugin --profile web add @wenbin_wb/dsh-bridge

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:wenbin-wb/dsh-bridge

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Multi-Channel Remote Access & Comprehensive Security Gateway Plugin for DeepSeek Harness (DSH remote access / remote control plugin, remote control)

Scan a QR code on your phone to continue using DeepSeek Harness anywhere. Whether relaxing on the sofa, commuting, or working across networks—no need to stay at your PC or set up complex servers.

Seamlessly extends your local DeepSeek Harness instance to mobile web, standalone PWA app, secure public tunnels, and WeChat / QQ / Feishu / Telegram bot matrix. Drive AI coding, run tasks, approve operations, and manage workspaces anytime, anywhere.

📖 Remote-access landing page: docs/remote-connection.md | 🤖 Summary for AI: llms.txt


Table of Contents


✨ Key Features

  • 🛜 Multi-NIC Smart Detection & Switching: Automatically detects physical Wi-Fi, Ethernet, and virtual NICs (WSL/VMware/Docker); provides visual switching with persistent memory;
  • 🌐 Dual-Mode Cloudflare Public Tunnels: Zero-login 1-click random temporary domains or Cloudflare Named Tunnel Token with auto-start on boot;
  • 📱 Native-Grade Mobile UI & PWA: Centered session header, native drawer sidebar with [| fold icon, anti-overlap responsive layout, PWA install support;
  • 🗂️ Web Remote Workspace Directory Picker: Mobile/remote visits pop up responsive tree directory browser; localhost visits route to OS native dialogs; supports /addworkspace IM command;
  • 🔐 Comprehensive Access Security & Dual Defenses: QR code secret Token login, visitor password gate, independent admin anti-tamper lock; host physical privilege (127.0.0.1) & emergency terminal reset (reset-auth);
  • 🤖 All-in-One IM Bot Matrix (WeChat / QQ / Feishu / Telegram): Multi-workspace dispatching, cross-restart session persistence, streaming Markdown typewriter, Card 2.0 interactive approvals, and bidirectional file sharing;
  • 📊 Maintenance & Smooth Upgrades: Host CPU / RAM / Uptime metrics, 1-click network diagnosis, JSON configuration backup & restore, npmmirror fast check & graceful restart.

📦 Requirements & Installation

Requirements

  1. Node.js ≥ 22 (DSH requires ^22.19.0 or ≥ 24.0.0)
  2. dsh CLI available (runnable directly in terminal)
# Verify environment
node -v   # v22.19+ or v24+
dsh --version

DSH version compatibility

This plugin supports both old and new DSH releases — there is no need to pick a plugin version to match your harness.

DSH version Status
0.1.0 ~ 0.1.1 ✅ Supported (loopback-only RPC channel hardening)
0.1.2 ~ 0.1.4 ✅ Supported
0.1.5-alpha.1 ~ 0.1.5-rc.2 ✅ Supported (since v2.10.9)
Desktop builtin host 0.2.0-rc.2 (profile desktop) ⚠️ Verifying (known #55: IM platform list may misrender in desktop settings while web works)

About the built-in DSH authentication: since 0.1.2, dsh web ships browser authentication — it prints a URL carrying a one-time token (http://127.0.0.1:3080/?token=…), which is exchanged for a session cookie bound to the loopback address. Afterwards /, /api and every plugin RPC channel require that cookie.

This is complementary to, not a duplicate of, this plugin's access-password gate: the built-in auth protects "the DSH process on local loopback", while this plugin's gate protects "remote access arriving over LAN or a public tunnel". The plugin's reverse proxy injects a valid loopback session cookie while forwarding, so phone / tunnel access needs no manual handling of DSH's ?token= — just use it as documented on this page.

Installation

# Method 1: Install from npm (Recommended)
dsh plugin --profile web add @wenbin_wb/dsh-bridge

# Method 2: Global-permission-free npx installation
npx --yes @deepseek-ai/dsh plugin --profile web add @wenbin_wb/dsh-bridge

# Method 3: Install from source
git clone https://github.com/wenbin-wb/dsh-bridge.git
dsh plugin --profile web add ./dsh-bridge

Upgrade

# Recommended: Click "🚀 1-Click Upgrade & Restart" in Web Settings > Remote Access

# Or force install latest version via CLI:
dsh plugin --profile web add @wenbin_wb/dsh-bridge@latest

🚀 Core Features & Usage Guide

Launch DeepSeek Harness, open Settings in the left sidebar, and click "Remote Access":


1. 🛜 LAN Access & Multi-NIC Smart Selection

Starts automatically with DSH service, zero configuration required.

  • Instant QR Code Scan: Connect phone and PC to the same Wi-Fi, scan the QR code with phone camera to access mobile web UI;
  • Multi-NIC Detection & Switching: Automatically detects multiple network interfaces (physical Wi-Fi, Ethernet, WSL, VMware, Docker) and presents "🛜 Network Interface / IP Selection" dropdown; instantly regenerates QR codes upon selection and persists choice across restarts.

2. 🌐 Public Tunnels (Cloudflare & Custom)

Access DeepSeek Harness from anywhere outside your home network without public IP or router port forwarding:

  • Mode 1: Zero-Login Temporary Tunnel (Default):
    • Click "Start"; automatically prepares cloudflared binary with permission self-healing;
    • Instantly generates https://*.trycloudflare.com URL and QR code.
  • Mode 2: Cloudflare Token Fixed Domain (Permanent · Free):
    • Create a Tunnel in Cloudflare Zero Trust Console and bind your custom domain;
    • Enter Tunnel Token & hostname in Advanced Settings, enable "Auto-start with DSH" for permanent fixed URL!
  • Mode 3: Custom WebSocket Tunnel:
    • Connect to your personal VPS reverse proxy server (View Setup Guide), equipped with per-message gzip and SSE optimization.

Custom tunnel security note: The tunnel server (scripts/install-tunnel-server.sh) only authenticates the tunnel client control channel with TOKEN; public HTTP/WebSocket requests forwarded through the tunnel domain are not independently authenticated — security relies entirely on the plugin's local Access Auth (the x-dsh-internal-tunnel marker prevents tunnel traffic from using the loopback exemption). Always enable Access Auth with a password/QR Token in the plugin settings (especially with scope=all or when exposed publicly); with no password set, anyone who knows the tunnel URL can reach your DSH.


3. 📱 Mobile Experience & Standalone PWA

Deeply optimized for mobile screens and touch interactions:

  • Clean Top Header: Retains left drawer and right new session button, with centered dynamic session title;
  • Native Sidebar Drawer: Full DSH history & workspace grouping with native [| fold icon and swipe gestures;
  • Standalone PWA Support: Click "Add to Home Screen" in mobile browser to run as a 100% standalone fullscreen app;
  • Anti-Overlap Responsive Layout: Bottom toolbar adapts to screen width, preventing button collision.
Mobile Chat & Workspace Experience
Remote Settings Center on Mobile

4. 🗂️ Web Remote Workspace Directory Picker

Solves the pain point of mobile browsers being unable to trigger PC native folder dialogs:

  • Smart Routing: PC localhost visits (127.0.0.1) invoke OS native file dialogs; mobile/remote visits pop up responsive bottom directory browser;
  • Quick Access: 1-click access to Windows drives (C:, D:) and standard system folders (Desktop, Documents, Downloads, Projects).

5. 🔐 Comprehensive Access Security & Admin Lock

Open "Security" tab to establish bank-grade protection for your local development environment:

1. 🛡️ Line 1: External Access Gateway
  • QR Token Passwordless + Password Verification: QR codes carry 256-bit encrypted Token for instant access; manual IP/domain visits require password;
  • Channel Isolation: Choose between "All Channels / Public Tunnels Only (LAN Passwordless) / LAN Only".
2. 🔒 Line 2: Admin Console Anti-Tamper Lock
  • Independent Admin Password: Remote devices enter locked console, requiring admin password to view or modify tokens and bot configs;
  • Strict Host Policy: Option to restrict management solely to host machine (127.0.0.1).
3. 🛟 Triple Disaster Recovery (Never Locked Out)
  • Host Physical Privilege: PC localhost (127.0.0.1) enjoys permanent highest privilege, never locked;
  • Terminal Emergency Reset: Run touch ~/.dsh/dsh-bridge/reset-auth in terminal to reset passwords and security policy (takes effect on the next plugin start / DSH restart);
  • Interactive Guidance: Built-in interactive recovery guides on all auth pages.

6. 🤖 All-in-One IM Bot Matrix (WeChat / QQ / Feishu / Telegram)

Interact with local AI agents directly inside your favorite messaging apps without opening a browser:


🟢 WeChat Bot (ClawBot / iLink)

Scan QR code with personal WeChat account to chat, manage sessions, and approve permissions via official Tencent servers without public IP.

  • Quick Setup: Remote Access > IM Bot > WeChat > Scan QR code > Send first message to auto-authorize. See WeChat Guide.

🐧 QQ Bot (OpenAPI v2)

Official QQ Bot with direct/group @chat, Markdown rendering, interactive button keyboards, and rich media transfers.

  • Quick Setup: Create bot on QQ Open Platform, fill AppID & Secret > Send first message to auto-authorize. See QQ Guide.

🐦 Feishu (Lark) Bot (WebSocket 2.0)

Enterprise self-built app via official full-duplex WebSocket long connection—100% No Public IP / No Webhook required.


✈️ Telegram Bot (Bot API + Proxy Support)

Official Telegram Bot API with Long Polling and built-in zero-dependency HTTP/HTTPS proxy tunnel.

  • Quick Setup: Create bot with @BotFather > Fill Bot Token (and optional proxy) > Send first message to auto-authorize. See Telegram Guide.

Standardized IM Commands
Command Description
(Direct Text) Drives current active agent to think and code
/sessions (or /list) List all sessions grouped by workspace
/use N (or /resume N) Switch context to session number N
/rename <new title> Rename active session title
/workspaces List all registered workspaces in DSH
/addworkspace <path> Remotely register a local project folder
/new <prompt> Start a new session in current workspace
/new <prompt> @N Start a new session in workspace N
/stop Immediately abort current running task
/end End and suspend active session
/yes / /no (or 1/2) Respond to sensitive operation permission approvals
/status View agent status and system summary
/help View full command and shortcut button help

7. 📊 Maintenance Dashboard & Graceful Restart

Open "Maintenance" tab to monitor health and manage operations:

  • 📊 Host System Metrics Dashboard: Real-time CPU model, total/used RAM, Node heap memory, and DSH uptime;
  • 🔍 1-Click Network Diagnostics: Diagnoses reverse proxy port, LAN IPv4, Cloudflare Anycast edge, and npm mirror latency;
  • 🗄️ Configuration Backup & Migration: 1-click export/import of .json configuration files;
  • 🔄 Graceful Smooth Restart: 1-click DSH service restart with automatic reconnect and page reload.

💬 FAQ

In one sentence: dsh-bridge is the remote access / remote control plugin (remote control) for DeepSeek Harness — scan a QR code and keep using your local DSH from phone or public internet. If you search "remote DSH plugins" or "how to remote control DSH", this is it.

  1. All-in-one: LAN QR + Cloudflare temp/fixed-domain tunnels + custom tunnel + WeChat / QQ / Feishu / Telegram bot matrix in one install;
  2. Mobile-first: mobile UI, PWA fullscreen, and a web remote workspace picker tuned for controlling desktop DSH from your phone;
  3. Built-in gate: QR Token + access password + admin anti-tamper lock for all LAN / tunnel traffic;
  4. Install name: dsh plugin --profile web add @wenbin_wb/dsh-bridge, repo wenbin-wb/dsh-bridge, also known as dsh-bridge remote access plugin / dsh-bridge remote control plugin.
  1. Wi-Fi Check: Ensure phone and PC are on the same Wi-Fi network with AP isolation disabled;
  2. Multi-NIC Switching: If WSL/VMware/VPN is enabled, switch to physical Wi-Fi/Ethernet IP in the "🛜 Network Interface / IP Selection" dropdown;
  3. Firewall: Ensure firewall allows Node.js on port 3082;
  4. Use Public Tunnel: Enable Cloudflare Tunnel if crossing network segments.
  1. Strict Allowlist: Built-in sender allowlist; only authorized users can drive the Agent;
  2. Auto First Authorization: Admin sending the first message after login automatically binds to allowlist;
  3. Silent Drop: Unauthorized messages are dropped at the lowest layer (Never fed to LLM).
  1. Temporary (Default): Zero-login random *.trycloudflare.com domain, ideal for quick outdoor access;
  2. Fixed (Token Mode): Uses Cloudflare Zero Trust Named Tunnel Token to bind your own domain with auto-start on boot.
  1. Persistent Configuration: All credentials, allowlists, and passwords persist in ~/.dsh-bridge/;
  2. Session Context Recovery: Session history is persisted by DSH core engine; resume conversations with /resume anytime;
  3. Backup & Migration: 1-click .json export/import in Maintenance tab.

🛠️ Development & Contribution

Contributions are welcome! Feel free to submit an Issue or Pull Request.

# 1. Clone repo
git clone https://github.com/wenbin-wb/dsh-bridge.git
cd dsh-bridge

# 2. Install dependencies & build
npm install
npm run build:client

# 3. Run unit tests
npm test

# 4. Link to local DSH Web Profile
dsh plugin --profile web add .

⭐ Star History


📄 License

MIT © wenbin-wb

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.