The core philosophy of DSH (DeepSeek Harness) is “everything is a plugin.” When developing agent workflows, agents often need to inspect the current state of the code, view historical commits, or analyze conflicts, without needing to perform commit, push, or file modification operations. dsh-plugin-git-inspect is specifically designed for this scenario and provides a set of read-only Git inspection tools.

Plugin Positioning

This is a read-only Git inspection toolset for DeepSeek Harness. It is not part of the official distribution, but an independent community plugin maintained by developer Wanbinyu. The plugin invokes the system git command through Harness’s subprocess service and does not execute a shell, ensuring the environment’s safety.

Core Features

The plugin registers ten read-only tools, covering common code review needs:

  • git_status: View the current branch and working tree status.
  • git_diff: View the working tree diff or staged diff.
  • git_diff_stat: View the diff summary by file.
  • git_log: View recent commits in a compact one-line format.
  • git_show: View a specified commit, tag, or other revision.
  • git_refs: View recent local branches, remote-tracking branches, and tags.
  • git_conflicts: List unresolved merge conflict files.
  • git_blame: View commit attribution for a line range in a specified file.
  • git_stash_list: View recent stashes without creating or applying them.
  • git_worktree_list: View registered worktrees in a stable format.

Installation and Enablement

In an environment where Harness CLI is installed, you can add the plugin to the web profile with the following command:

dsh plugin --profile web add https://github.com/Wanbinyu/dsh-plugin-git-inspect/releases/download/v0.3.6/dsh-plugin-git-inspect-0.3.6.tgz

After installation, restart dsh, and the plugin will automatically take effect. If the host project needs to manually control the composition layer, you can also install the package with npm install github:Wanbinyu/dsh-plugin-git-inspect and add the git-inspect service to the Cordis composition configuration.

Typical Usage

Tool calls are passed to DSH in JSON format. The following are typical call examples:

View the current branch status:

{"name":"git_status","arguments":{}}

View staged changes for src/index.ts:

{"name":"git_diff","arguments":{"staged":true,"path":"src/index.ts"}}

View the 10 most recent commit records:

{"name":"git_log","arguments":{"maxCount":10,"path":"src/index.ts"}}

View the specific contents of the HEAD commit:

{"name":"git_show","arguments":{"revision":"HEAD","path":"src/index.ts"}}

View conflict files:

{"name":"git_conflicts","arguments":{}}

Analyze code ownership (starting from line 20, for 30 lines):

{"name":"git_blame","arguments":{"path":"src/index.ts","startLine":20,"lineCount":30}}

Environment Requirements and Restrictions

Running this plugin requires the following environment conditions:

  • Operating system: Windows, macOS, or Linux.
  • Node.js version: must be greater than or equal to 22.19.0.
  • System environment: the git executable must be discoverable in the host process’s PATH.
  • Dependent services: the host Harness composition must provide @deepseek-ai/dsh-tools, @deepseek-ai/dsh-system-prompt, @deepseek-ai/dsh-subprocess, and their implementation (for example, @deepseek-ai/dsh-subprocess-local).

In terms of security and behavior, the plugin imposes the following restrictions:

  • Read-only operations: It does not provide commit, push, reset, stash, branch switching, or file modification capabilities.
  • No shell execution: It resolves git through Harness’s subprocess service, starts the process with a fixed argv, and places user-supplied paths after Git’s -- pathspec separator, without shell expansion.
  • Output control: It disables interactive features such as pager, color, and external diff to ensure stable output formatting. When output reaches the limit, it is explicitly marked as truncated.
  • Error handling: When Git returns a non-zero exit code, the directory is not a repository, or the subprocess terminates abnormally, the plugin returns a structured tool error.

Summary

dsh-plugin-git-inspect provides a secure and stable read-only Git inspection layer for the DSH plugin ecosystem. By limiting permissions and performing strict input handling, it makes agents more reliable when reviewing code history, analyzing conflicts, or checking status. The project is licensed under the MIT license and is an independent community plugin.

  • GitHub repository: https://github.com/Wanbinyu/dsh-plugin-git-inspect
  • Plugin directory: https://www.skillhub.cn/plugins/Wanbinyu/dsh-plugin-git-inspect