Introduction¶
When developing agents with DeepSeek Harness (DSH), controlling skills, MCP servers, or security protections usually requires modifying code or configuration files. When these capabilities need to be adjusted dynamically at runtime, the existing workflow is often insufficiently flexible. The dsh-capability-toggle-plugin provides a way to perform real-time control and enforcement from the WebUI.
What Is This¶
This is a DeepSeek Harness (DSH) WebUI plugin maintained by lifeopsgo. It allows administrators to control skills, MCP, tools, prompt injection, and security protections (such as approvals and guards) at three levels: session, project, or global. The plugin performs real runtime enforcement for capabilities, including removal, hiding, suppression, rejection, or blocking.
Core Features¶
Three-Level Resolution
Supports a three-level configuration hierarchy: session > project > global. The nearest explicit value wins. Unset capabilities fall back to the next level; if all levels are unset, the capability remains enabled. Panel row badges always display the resolved result.
Capability Categories
Provides a control panel for the following:
- Skills: individual model-callable skills
- MCP: MCP servers (expand a row to view member tools)
- Tools: individual model-visible tools and their guidance sections
- Prompt: safe prompt injection whitelist
- Security: approval escalation and five optional safety guards
Runtime Enforcement
Depending on the capability type, disabling actions take different measures:
- tool / mcp: removed via
ctx.tools.restrict({ deny }); forced calls are rejected - skill: hidden by a same-named
modelInvocable:falseruntime skill - prompt: hidden as empty text or suppressed via
suppressRuntimeContext() - approval: approval requests within scope resolve as
rejected - guard: matching calls are blocked or require confirmation in
tools/pre-execute
Usage Statistics
Skills, MCP servers, and tools display a small badge indicating how many times they were called during the current session. Counts are updated at the end of each turn, persist for the lifetime of the agent, and are not persisted.
Panel Preferences
The expand arrow next to the panel title opens three display preferences, stored in localStorage so they remain effective after refreshes and restarts:
- Show “enabled / total” on tabs: render badges as fractions (for example,
67/106) - Show call stats: show or hide per-row usage badges
- Level columns to show: display only session, session plus project, or all three columns
Installation and Enablement¶
- Ensure the system meets the requirement Node.js >= 22.6.
- Run the installation command:
dsh plugin --profile web add github:lifeopsgo/dsh-capability-toggle-plugin#v1.3.2
- Restart the DSH Web GUI process and refresh the page.
Typical Usage¶
- While the agent is idle, open the button next to the control button.
- Toggle capabilities to enable or disable them.
- Use the small clear badge to return a capability to the “unset” state.
- View the usage statistics badge to check call counts.
Use Cases and Notes¶
- Use cases: scenarios requiring dynamic adjustment of agent capabilities, such as testing behavior under different configurations or temporarily restricting certain risky operations.
- Compatibility: compatible with the DSH 0.1.x line;
peerDependenciesrejects 0.2.0 and later versions. - Security guards: safety guards are optional and managed through confirmation prompts.
- Unset logic: unset capabilities fall back to the next level; if all levels are unset, the capability remains enabled.
Short Conclusion¶
By integrating capability control into the WebUI, this plugin simplifies runtime management for DSH environments. It supports complex hierarchical overrides and statistics. For more details, visit the GitHub repository.