Introduction

When developing agents with DeepSeek Harness (DSH), executing remote SSH commands usually requires preset host configurations or exposed login credentials. The dsh-ssh-bridge plugin provides a local bridge solution: enter the target host and password through a browser interface to establish an encrypted channel; the Agent executes remote commands via the local localhost API. This plugin does not depend on a specific SSH target and can run independently. The password remains only in process memory at all times.

Core Features

  • Local SSH bridge service
  • Enter password via browser page to establish a connection
  • Agent invokes remote commands through tools such as router_exec
  • Supports arbitrary SSH targets (no preset hosts required)
  • Can run independently from DSH
  • Automatic port fallback
  • Random token authentication

Deployment and Enablement

Install Plugin

Install using the DSH plugin command:

dsh plugin --profile web add dsh-ssh-bridge

Dependencies and Environment

  • DSH version: Requires the DSH 0.1.0-rc series
  • Node.js: ≥ 18
  • pnpm: Dependency installation tool (handled by dsh plugin)

pnpm 11 Compatibility Note

If using pnpm 11, it blocks the native build scripts (node-gyp) for ssh2 and cpu-features by default, causing installation to fail. You need to allow them in the pnpm-workspace.yaml for the corresponding profile:

allowBuilds:
  cpu-features: true
  ssh2: true

Standalone Operation (Optional)

The core bridge service does not depend on DSH and can be run directly:

npm install
npm start

After startup, visit http://127.0.0.1:23991. If the port is occupied, the next available port is used automatically.

Typical Usage

1. Browser Interaction

  1. Open http://127.0.0.1:23991.
  2. Enter the target host (format: user@host[:port]) and password, then click “Connect”.
  3. Once the status changes to “Connected”, use the input field below as an interactive terminal for the target host.
  4. Enter exit to terminate the entire SSH session, or click the “Disconnect” button.

2. API Calls

The service generates a random token after startup. The Agent can communicate with the bridge service via the following APIs:

  • Authentication: POST /api/auth (params: {password, target?})
  • Execute command: POST /api/exec (params: {cmd, token}, returns {code, stdout, stderr})
  • Write terminal line: POST /api/input (params: {line, token})
  • Disconnect: POST /api/disconnect (params: {token})
  • Reconnect: POST /api/reconnect (params: {token})

3. DSH Tool Calls

After the plugin is loaded, the Agent can directly call the following tools in the scoped layer:
* router_exec: Execute a remote command
* router_disconnect: Disconnect
* router_reconnect: Reconnect using existing credentials

Notes

  • Security restriction: The service listens only on 127.0.0.1 and is not accessible from external networks.
  • Credential security: The password is stored only in process memory, never printed or written to disk.
  • Token restriction: API calls must include the token from the startup logs, and the token is valid only locally.
  • Port conflict: If the port is occupied, the service falls back to the next available port. Check the startup log for the actual port.

Summary

dsh-ssh-bridge solves the challenge of securely invoking remote SSH commands in a DSH environment. By combining browser authentication with local API calls, it provides generic SSH access without requiring preset hosts. The code is hosted on GitHub and licensed under MIT.