Introduction

When developing agents with DeepSeek Harness (DSH), controlling skills, MCP servers, or security protections usually requires modifying code or configuration files. When these capabilities need to be adjusted dynamically at runtime, the existing workflow is often insufficiently flexible. The dsh-capability-toggle-plugin provides a way to perform real-time control and enforcement from the WebUI.

What Is This

This is a DeepSeek Harness (DSH) WebUI plugin maintained by lifeopsgo. It allows administrators to control skills, MCP, tools, prompt injection, and security protections (such as approvals and guards) at three levels: session, project, or global. The plugin performs real runtime enforcement for capabilities, including removal, hiding, suppression, rejection, or blocking.

Core Features

Three-Level Resolution

Supports a three-level configuration hierarchy: session > project > global. The nearest explicit value wins. Unset capabilities fall back to the next level; if all levels are unset, the capability remains enabled. Panel row badges always display the resolved result.

Capability Categories

Provides a control panel for the following:

  • Skills: individual model-callable skills
  • MCP: MCP servers (expand a row to view member tools)
  • Tools: individual model-visible tools and their guidance sections
  • Prompt: safe prompt injection whitelist
  • Security: approval escalation and five optional safety guards

Runtime Enforcement

Depending on the capability type, disabling actions take different measures:

  • tool / mcp: removed via ctx.tools.restrict({ deny }); forced calls are rejected
  • skill: hidden by a same-named modelInvocable:false runtime skill
  • prompt: hidden as empty text or suppressed via suppressRuntimeContext()
  • approval: approval requests within scope resolve as rejected
  • guard: matching calls are blocked or require confirmation in tools/pre-execute

Usage Statistics

Skills, MCP servers, and tools display a small badge indicating how many times they were called during the current session. Counts are updated at the end of each turn, persist for the lifetime of the agent, and are not persisted.

Panel Preferences

The expand arrow next to the panel title opens three display preferences, stored in localStorage so they remain effective after refreshes and restarts:

  • Show “enabled / total” on tabs: render badges as fractions (for example, 67/106)
  • Show call stats: show or hide per-row usage badges
  • Level columns to show: display only session, session plus project, or all three columns

Installation and Enablement

  1. Ensure the system meets the requirement Node.js >= 22.6.
  2. Run the installation command:
    dsh plugin --profile web add github:lifeopsgo/dsh-capability-toggle-plugin#v1.3.2
  1. Restart the DSH Web GUI process and refresh the page.

Typical Usage

  • While the agent is idle, open the button next to the control button.
  • Toggle capabilities to enable or disable them.
  • Use the small clear badge to return a capability to the “unset” state.
  • View the usage statistics badge to check call counts.

Use Cases and Notes

  • Use cases: scenarios requiring dynamic adjustment of agent capabilities, such as testing behavior under different configurations or temporarily restricting certain risky operations.
  • Compatibility: compatible with the DSH 0.1.x line; peerDependencies rejects 0.2.0 and later versions.
  • Security guards: safety guards are optional and managed through confirmation prompts.
  • Unset logic: unset capabilities fall back to the next level; if all levels are unset, the capability remains enabled.

Short Conclusion

By integrating capability control into the WebUI, this plugin simplifies runtime management for DSH environments. It supports complex hierarchical overrides and statistics. For more details, visit the GitHub repository.