Introduction

DeepSeek Harness (DSH) adopts a plugin-based architecture. harness-github is a GitHub connector plugin within it, designed to allow agents to directly handle PRs, issues, CI checks, and release workflows on GitHub. It does not require users to configure OAuth or Device Flow separately; it reuses existing authentication state.

Core Features

The plugin mainly resolves authentication and permission issues when agents interact with GitHub:
1. Full-process coverage: Supports checking PRs, triaging issues, debugging failed Actions checks, handling review feedback, and preparing code changes for review.
2. Connector-first: Prefers the gh CLI, and automatically falls back to the REST API (fetch) when it is unavailable.
3. Zero-extra-step authentication: Reuses the gh CLI login state or the GITHUB_TOKEN environment variable; no GitHub App or web login flow is used.
4. Safety mechanisms: All write operations (such as commenting, creating a PR, and merging) request human approval before execution; tokens are only used in memory and are never written to logs or configuration files.

Installation and Enablement

Before installation, ensure the DSH version is not lower than 0.1.0-rc.6.

  1. Run the installation command under any profile (web / tui / headless):
dsh plugin add harness-github
  1. After restarting DSH, the plugin becomes active. The system injects the github:workflow workflow guidance and registers 18 github_* tools. No extra configuration is needed to start using it (public repositories are immediately available; write operations require credentials and approval).

Typical Usage

Understand the plugin workflow through the following scenario examples:

  1. Viewing and triaging: View pending issues in a repository.
    User: Check whether deepseek-ai/deepseek-harness has any pending issues
    Agent: github_issue_list repo=deepseek-ai/deepseek-harness
  1. Debugging CI: Locate the failed checks in a PR.
    User: The CI for PR #123 is failing. Help me check it
    Agent: github_pr_view repo=o/r number=123 → get details and check summary
          github_workflow_run repo=o/r runId=... → view failed steps and logs
  1. Handling feedback: Fetch comments and reply.
    User: Handle this review feedback and then reply to them
    Agent: github_review_feedback repo=o/r number=123 → fetch comment threads
          github_pr_comment repo=o/r number=123     → reply (approval required)
  1. Publishing changes: Prepare code changes and create a PR.
    User: Make a PR for my changes
    Agent: github_pr_prepare repo=o/r → check/commit/push (approval required) + create PR (approval required)

Tool List

The plugin provides 18 tools, divided into read tools and write tools.

Tool Name Function Notes
github_repo_view Repository overview Read tool
github_pr_list List PRs Read tool
github_pr_view PR details + file changes + comments + checks Read tool
github_checks_view Head commit status checks + Actions run list Read tool
github_workflow_run Failed steps for a single run + key logs Read tool
github_issue_list List issues Read tool
github_issue_view Issue details + comments Read tool
github_search Search issues/PRs/repos/code Read tool
github_release_list Recent releases Read tool
github_review_feedback PR review comment threads Read tool
github_pr_create Create PR (duplicate prevention, draft supported) Write tool (approval required)
github_pr_comment Comment on PR/issue Write tool (approval required)
github_review_submit approve / comment / request-changes Write tool (approval required)
github_pr_merge merge / squash / rebase Write tool (approval required)
github_issue_create Create issue (labels/assignees) Write tool (approval required)
github_issue_comment Comment on issue Write tool (approval required)
github_issue_close Close issue Write tool (approval required)
github_pr_prepare Local workflow: check/commit/push/create PR Write tool (approval required)

Authentication and Permissions

Resolution Order

  1. The gh CLI is logged in (gh auth status is valid) → reuse it directly.
  2. Environment variable GITHUB_TOKEN → authenticated REST API.
  3. Public repository read-only → anonymous REST API calls (rate limited, about 60 requests/hour).
  4. None of the above and write operations are needed → tools fail; run gh auth login or set GITHUB_TOKEN.

Permission Boundaries

  • Read-only tools: Available for public repositories; private repositories require credentials.
  • Write tools: Require repo write permission, and must pass human approval before each execution. The default policy is ask; silent pass-through is rejected.

Compatibility

  • DeepSeek Harness: >= 0.1.0-rc.6 < 0.2.0 (recommended rc.7 / rc.8)
  • Node.js: >= 18.0.0
  • gh CLI: Optional (automatically uses REST if not installed)
  • Platform: Works across web / tui / headless

Conclusion

By reusing the gh CLI and REST API, harness-github provides DSH with a GitHub interaction solution that requires no extra login configuration. It translates the complex GitHub API into 18 concrete tools and ensures security in automated workflows through strict approval mechanisms and an in-memory token strategy.