Bundles the remote-shell skill for secure SSH, SFTP, Telnet, and WinRM remote operations, with an encrypted credential vault whose login and execution scripts never accept plaintext passwords.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-remote-shell
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:wutian122/dsh-remote-shell
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
A DSH (DeepSeek Harness) plugin that bundles the remote-shell skill: secure SSH / SFTP / Telnet / WinRM remote operations with an encrypted credential vault (Fernet + PBKDF2-HMAC-SHA256).
中文说明见 README.zh.md。
Installation
From the npm registry (once published):
dsh plugin --profile web add dsh-remote-shell
From a local checkout (development / testing):
dsh plugin --profile web add /path/to/dsh-remote-shell
Then restart dsh web for the plugin to take effect. The skill appears in the skill catalog as remote-shell (provider dsh-remote-shell, source bundled).
Features
The bundled skill provides:
- Remote command execution over SSH / WinRM / Telnet: single commands, batch execution, script execution, remote system information, and health checks.
- SFTP file transfer: upload, download, and directory listing.
- Encrypted credential vault: login/execution scripts never accept plaintext passwords (there is no
-pflag); credentials are always fetched from the encrypted vault. Usecredctlto add, list, update, and remove credentials. - Safety interception: mutating commands are blocked by default and only run after explicit user confirmation (
--auto-confirm).
How it works
The plugin is a Cordis plugin that injects a single skills provider. On load it scans the bundled skills/ directory for SKILL.md files, parses each file's YAML frontmatter, and registers the skill with the host's skill registry (rank 600, source bundled). The provider is immutable: it performs no file watching or polling, and a missing or malformed skill degrades gracefully (skipped, never thrown).
Line-ending policy
The bundled skill files are copied verbatim from the source skill, which uses mixed line endings. .gitattributes pins each file to its source line ending so checkouts (under any core.autocrlf setting) reproduce the source bytes exactly. SKILL.md is pinned to LF because the provider's frontmatter detection requires exact --- lines — a CRLF checkout would make the provider skip the skill entirely.
Development
Run the unit tests (Node.js built-in test runner, no extra tooling):
node --test
Dependencies
The skill's scripts are written in Python 3 and require third-party libraries such as paramiko (SSH/SFTP) and pywinrm (WinRM). Install them on first use following the instructions in the skill's SKILL.md.
Security Notice
Installing this plugin runs third-party code on your machine. The credential vault master password is managed by you; the plugin does not store or transmit it.
License
MIT — see LICENSE.
Links
More in this category
YuJunZhiXue/dsh-purge★ 4355
Adds a Settings card to edit prompt-inject.md, manage AGENTS.md or CLAUDE.md rule sets, check for plugin updates, and apply or restore reversible local package updates.
FNOSP/fnos-dsh#dsh-codex-auth-plugin★ 24
ChatGPT account sign-in for DeepSeek Harness through a Codex browser OAuth flow with no API key and no workspace selection: subscribes the login to pi-ai's Codex provider, lets you set the global default Codex model and reasoning effort for new sessions, refreshes the model list from the signed-in account's own catalog endpoint, and shows the five-hour and weekly usage windows in the composer.
AgentConnect/dsh-awiki★ 19
Provides DeepSeek Harness agents with native identities based on the open Agent Network Protocol (ANP), plus identity-based direct, group, mail, and Agent-to-Agent communication.
MengYuil/dsh-ponytail★ 16
Port of ponytail: an always-on lazy-senior-developer coding persona with intensity levels, persistence of the default level, and review, audit, debt, gain and help skills for DeepSeek Harness.
xxww0098/dsh-plugin-oauth-subs★ 13
Connect ChatGPT Codex, xAI Grok, Zhipu GLM, AWS Kiro, Google Antigravity, and Cursor subscriptions to DeepSeek Harness through OAuth and a local proxy.
lw-storm/dsh-plugin-masterprompt★ 11
Per-conversation persona / master prompt plugin: create, edit, switch and delete persona templates from the composer toolbar, with highest-priority system-prompt injection, fixed interaction guardrails, subagent inheritance, new-conversation default, and local JSON persistence.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.