Preface¶
The official workflow-worker-thread engine for DeepSeek Harness uses node:vm as the API-shape mechanism. Its documentation notes that this is not a security boundary and that a different engine must be used when scripts are untrusted. dsh-workflow-isolate explores this interface without changing the model-facing workflow tool.
Core Features¶
This plugin is a QuickJS/WASM isolated workflow engine, primarily addressing the fact that model-authored workflow scripts need JavaScript capabilities but should not inherit Node.js permissions. It provides the following capabilities:
- Provide a WorkflowEngine service provider.
- Execute QuickJS/WASM scripts.
- Limit resources (memory, stack, interrupt fuel, time).
- Block Node.js APIs (process, require, filesystem, network, timers).
- Preserve DSH workflow hooks and lifecycle events.
- An isolated JavaScript runtime and realm.
- Limit concurrency and subagent budgets.
Installation and Configuration¶
Installing the plugin requires adding the generated tarball to a DSH profile.
dsh plugin --profile web add ./dsh-workflow-isolate-0.1.0.tgz
The plugin is enabled by the cordis.patch.yml configuration. This configuration disables the default workflow-worker-thread and inserts workflow-isolate. DSH allows only one ctx.workflowEngine service provider per context, so these two engines cannot be mounted simultaneously.
For local source iteration, you can use the following command:
dsh plugin --profile web add .
Usage Notes¶
When deploying and using it, note the following:
- Language boundary: QuickJS/WASM is a stronger language boundary than
node:vm, but it is not perfect isolation. - Host trust: The host subagent provider remains trusted and can use configured models, tools, network access, and credentials.
- Script authoring: Workflow bodies must use portable JavaScript and must not rely on Node.js APIs, V8-specific behavior, or dynamic module loading.
- Communication mechanism: Subagents connect to the host through an RPC bridge.
- Security risk: Runtime vulnerabilities, side channels, and supply-chain compromise remain relevant.
- Provider limitation: Only one
ctx.workflowEngineprovider is allowed per context.
Conclusion¶
dsh-workflow-isolate provides a QuickJS/WASM-based isolation environment for DeepSeek Harness. With resource limits and hook preservation, it is suitable for scenarios that need to execute untrusted scripts in workflows.