Preface

The official workflow-worker-thread engine for DeepSeek Harness uses node:vm as the API-shape mechanism. Its documentation notes that this is not a security boundary and that a different engine must be used when scripts are untrusted. dsh-workflow-isolate explores this interface without changing the model-facing workflow tool.

Core Features

This plugin is a QuickJS/WASM isolated workflow engine, primarily addressing the fact that model-authored workflow scripts need JavaScript capabilities but should not inherit Node.js permissions. It provides the following capabilities:

  1. Provide a WorkflowEngine service provider.
  2. Execute QuickJS/WASM scripts.
  3. Limit resources (memory, stack, interrupt fuel, time).
  4. Block Node.js APIs (process, require, filesystem, network, timers).
  5. Preserve DSH workflow hooks and lifecycle events.
  6. An isolated JavaScript runtime and realm.
  7. Limit concurrency and subagent budgets.

Installation and Configuration

Installing the plugin requires adding the generated tarball to a DSH profile.

dsh plugin --profile web add ./dsh-workflow-isolate-0.1.0.tgz

The plugin is enabled by the cordis.patch.yml configuration. This configuration disables the default workflow-worker-thread and inserts workflow-isolate. DSH allows only one ctx.workflowEngine service provider per context, so these two engines cannot be mounted simultaneously.

For local source iteration, you can use the following command:

dsh plugin --profile web add .

Usage Notes

When deploying and using it, note the following:

  • Language boundary: QuickJS/WASM is a stronger language boundary than node:vm, but it is not perfect isolation.
  • Host trust: The host subagent provider remains trusted and can use configured models, tools, network access, and credentials.
  • Script authoring: Workflow bodies must use portable JavaScript and must not rely on Node.js APIs, V8-specific behavior, or dynamic module loading.
  • Communication mechanism: Subagents connect to the host through an RPC bridge.
  • Security risk: Runtime vulnerabilities, side channels, and supply-chain compromise remain relevant.
  • Provider limitation: Only one ctx.workflowEngine provider is allowed per context.

Conclusion

dsh-workflow-isolate provides a QuickJS/WASM-based isolation environment for DeepSeek Harness. With resource limits and hook preservation, it is suitable for scenarios that need to execute untrusted scripts in workflows.