Introduction¶
When developing agents with DeepSeek Harness (DSH), executing remote SSH commands usually requires preset host configurations or exposed login credentials. The dsh-ssh-bridge plugin provides a local bridge solution: enter the target host and password through a browser interface to establish an encrypted channel; the Agent executes remote commands via the local localhost API. This plugin does not depend on a specific SSH target and can run independently. The password remains only in process memory at all times.
Core Features¶
- Local SSH bridge service
- Enter password via browser page to establish a connection
- Agent invokes remote commands through tools such as
router_exec - Supports arbitrary SSH targets (no preset hosts required)
- Can run independently from DSH
- Automatic port fallback
- Random token authentication
Deployment and Enablement¶
Install Plugin¶
Install using the DSH plugin command:
dsh plugin --profile web add dsh-ssh-bridge
Dependencies and Environment¶
- DSH version: Requires the DSH 0.1.0-rc series
- Node.js: ≥ 18
- pnpm: Dependency installation tool (handled by
dsh plugin)
pnpm 11 Compatibility Note¶
If using pnpm 11, it blocks the native build scripts (node-gyp) for ssh2 and cpu-features by default, causing installation to fail. You need to allow them in the pnpm-workspace.yaml for the corresponding profile:
allowBuilds:
cpu-features: true
ssh2: true
Standalone Operation (Optional)¶
The core bridge service does not depend on DSH and can be run directly:
npm install
npm start
After startup, visit http://127.0.0.1:23991. If the port is occupied, the next available port is used automatically.
Typical Usage¶
1. Browser Interaction¶
- Open
http://127.0.0.1:23991. - Enter the target host (format:
user@host[:port]) and password, then click “Connect”. - Once the status changes to “Connected”, use the input field below as an interactive terminal for the target host.
- Enter
exitto terminate the entire SSH session, or click the “Disconnect” button.
2. API Calls¶
The service generates a random token after startup. The Agent can communicate with the bridge service via the following APIs:
- Authentication:
POST /api/auth(params:{password, target?}) - Execute command:
POST /api/exec(params:{cmd, token}, returns{code, stdout, stderr}) - Write terminal line:
POST /api/input(params:{line, token}) - Disconnect:
POST /api/disconnect(params:{token}) - Reconnect:
POST /api/reconnect(params:{token})
3. DSH Tool Calls¶
After the plugin is loaded, the Agent can directly call the following tools in the scoped layer:
* router_exec: Execute a remote command
* router_disconnect: Disconnect
* router_reconnect: Reconnect using existing credentials
Notes¶
- Security restriction: The service listens only on
127.0.0.1and is not accessible from external networks. - Credential security: The password is stored only in process memory, never printed or written to disk.
- Token restriction: API calls must include the token from the startup logs, and the token is valid only locally.
- Port conflict: If the port is occupied, the service falls back to the next available port. Check the startup log for the actual port.
Summary¶
dsh-ssh-bridge solves the challenge of securely invoking remote SSH commands in a DSH environment. By combining browser authentication with local API calls, it provides generic SSH access without requiring preset hosts. The code is hosted on GitHub and licensed under MIT.