Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture, aiming to build agent systems by combining different capabilities. In practical development, managing portable agent roles, verifying role provenance and integrity, and launching a specific role while preserving the independence of the current conversation context are common requirements.
dsh-rolehub-bridge is a native compatibility layer between DeepSeek Harness and RoleHub. It is responsible for discovering roles from Host-configured Hubs, verifying and locking exact package digests, computing all valid Host policies, and creating a separate, role-scoped child session.
Core Features¶
This plugin provides the following capabilities through Host commands and the native UI:
- Hub discovery and validation: Supports Hub discovery, catalog validation, and bounded downloads.
- Integrity checks: Performs exact digest validation for manifests, archives, or Bundles.
- Policy and bindings: Computes effective capability policies and establishes fixed Host tool bindings.
- Session management: Creates a new resumable, role-scoped child session.
- Integration capability: Optionally attaches the session through the Room’s public Host API.
- Native controls: Provides native DSH controls and read-only snapshots.
Installation and Activation¶
Before installing, ensure the environment meets the following requirements:
- Node.js version
^22.19.0 || >=24 - DeepSeek Harness version
0.1.0-rc.6
Run the following commands to install the plugin:
dsh plugin --profile web add github:ishuowang/dsh-rolehub-bridge#v0.2.0
dsh web
After installation, the plugin adds a Host runtime, the /rolehub command, a read-only native API, and a Web client to the currently configured profile.
If you need to attach created role sessions to a Room, you can install the Room plugin under the same profile:
dsh plugin --profile web add github:ishuowang/dsh-agent-team-room#v0.6.0
Note: This package has not yet been published to npm. Officially supported installation is done directly through the GitHub link above.
Typical Usage¶
After installation, you can operate through Host commands or the native UI.
Refresh and Inspect¶
First refresh the configured Hubs to obtain the latest catalog:
/rolehub refresh
Inspect details for a specific role:
/rolehub inspect official/software-engineer
Start a Role¶
Start a role session and specify an initial prompt:
/rolehub start official/software-engineer --label "Software engineer" --prompt "Review the current implementation."
If the Room plugin is installed, you can specify a Room ID during startup to attach directly:
/rolehub start official/software-engineer --room <room-id> --label "Implementation reviewer"
List and Sessions¶
View the list of Host-configured Hubs or installed roles:
/rolehub hubs
/rolehub list
View the persistent role bindings for the current parent session:
/rolehub sessions
Configuration¶
After installation, the plugin inserts the rolehub-bridge configuration item into the profile’s cordis.patch.yml. You can edit it manually if the default configuration does not meet your needs:
- id: rolehub-bridge
name: dsh-rolehub-bridge
config:
storageDir: /srv/dsh/rolehub-bridge
allowCommunityRoles: false
allowedCapabilities:
- filesystem.read
- filesystem.write
- network.fetch
- web.search
- source-control.read
- room.message
fetchTimeoutMs: 15000
Notes¶
- Capability set limits: The executable capability set is strictly limited to
required role requests ∩ bridge support ∩ Host allowlist. This is narrower than the role’s requested intent. - Optional capabilities: Any optional capability is not granted automatically. If a required capability is missing, the system will fail closed.
- Room relationship: Agent Team Room is an optional destination for session results, not a dependency, and not a source of role authority.
- No built-in content: The plugin does not include built-in company teams, personas, or Room scenarios. Roles come only from RoleHub and appear only when the user explicitly selects them.
- Change mechanism: All changes (such as installing a role) are provided only through Agent-scoped Host commands. The plugin intentionally does not provide model-facing “install role” or “start role” tools.
- Browser snapshot: The browser snapshot exposes Hub IDs, public role metadata, digests, capability labels, and bounded Room summaries. It omits catalog/archive URLs, local paths, stored policy receipts, provider bindings, transcripts, and private Room data.
Summary¶
dsh-rolehub-bridge provides DeepSeek Harness with secure integration capabilities with RoleHub through the native UI and Host commands. By enforcing strict validation and Host policy computation, it ensures secure role loading while preserving the integrity of the native DSH architecture.