In the DeepSeek Harness (DSH) plugin ecosystem, handling remote development environments usually means manually connecting over SSH or syncing local files. The DSH plugin dsh-rw introduces Remote-SSH-style workspaces, enabling agents to operate the remote file system directly. This plugin is maintained by MDR-EX1000 and aims to eliminate the fragmentation between local and remote environments.
Core Concepts¶
dsh-rw allows you to select an SSH host and a remote directory, making it a native DSH workspace. The agent works directly on the remote file system via rw_* tools (SFTP/exec based on a persistent ssh2 connection pool). The remote directory is the single source of truth: there is no mirroring and no syncing.
Since version 0.4.0, this plugin supports zero configuration.
Core Features¶
- Native remote workspace selector: In DSH’s “Add Workspace” flow, selected via a modal. The interface is split into LOCAL (local folder) and REMOTE (Codex-style page). The remote page supports selecting from an alias dropdown, auto-filling the
~/path, and live-filtering directories. - Language follows DSH global settings: Labels, prompts, validation messages, loading states, and confirmation messages in the selector support Chinese and English, and follow DSH’s global language settings in real time.
- Read hosts from
~/.ssh/config: No extra configuration is required. Existing SSH aliases are displayed automatically, and the file is re-read when it changes. Password-authenticated hosts can be added through the interface and stored as a local file with 0600 permissions. - Real workspace isolation: All
rw_*file paths are restricted to the selected workspace root directory. The system rejects../, absolute paths outside the root directory, and symlink escapes. - SSH host key verification: By default, verification uses
~/.ssh/known_hosts. It supports theaccept-new(record first-seen keys),strict, andoffstrategies. Changed host keys are rejected and are not silently accepted. - Structured errors: Connection refused, authentication failure, timeout, missing path, permission denied, out-of-workspace access, and host key issues all return distinct error codes, making it easier for agents to handle them correctly.
- Connection self-healing: Uses ssh2 connection pool heartbeats (15s × 3) to detect disconnections, with a default channel open timeout of 10s. Operations that encounter a dead connection automatically retry once, transparent to the agent.
- Placeholders rather than copies: The local directory registered in DSH is an empty placeholder (
.dsh-rw-meta.jsonrecords the source). Remote file contents are not stored, so there are no sync conflicts. - Shim Mode (enabled by default): DSH native tools (such as
read,write,edit, andbash) are intercepted and translated into remote execution. The agent does not need to learnrw_*tools to operate remotely just like locally. Path mapping is bidirectional between the placeholder and the remote system. Setshim: falseto disable this mode. - Explicit failure policy: If the host corresponding to a placeholder is removed, operations invoked through that placeholder report an error (
NOT_CONNECTED), instead of silently running against an empty local directory.
Installation¶
Install the plugin through DSH Market:
dsh plugin --profile web add github:MDR-EX1000/dsh-rw
This repository tracks compiled lib/ output, so installing this source does not require a local TypeScript toolchain or build permissions. If you need the exact release package:
dsh plugin --profile web add https://github.com/MDR-EX1000/dsh-rw/releases/latest/download/dsh-rw.tgz
Maintenance note: Because the plugin has no prepare or similar lifecycle hooks, the runtime entry point is the committed lib/index.js. If you modify the source, manually run pnpm build and commit the generated lib/ to Git. The ssh2 dependency used by the plugin may require pnpm permission for optional native modules.
Typical Usage¶
- Select a workspace: In the sidebar or conversation, choose “Add Workspace” -> “REMOTE” card. Select a host from
~/.ssh/config(or add a password-based host), browse or enter a remote path (starting from~/by default), then enter a workspace name and activate it. - Routine collaboration: In Shim Mode (default), directly ask the agent to fix bugs, run tests, or refactor code. The agent automatically uses native tools to perform remote operations.
- Explicit remote operations: Use
rw_*tools for specific operations:- File operations:
rw_list_dir,rw_read_file,rw_write_file,rw_mkdir,rw_move,rw_delete - Command execution:
rw_exec(CWD is the workspace root directory) - Session management:
rw_hosts,rw_connect,rw_disconnect
- File operations:
Notes¶
- Shim Mode: Enabled by default. To disable it, set
shim: falsein the configuration file. - Permission Requirements: The
ssh2dependency requires permissions for optional native modules, and pnpm’s build script whitelist must include this dependency. - Git Repository: Keep the
lib/folder in Git so that it can be rebuilt after changes tosrc/. - Key Verification: SSH host key verification is based on
~/.ssh/known_hosts.
Summary¶
dsh-rw brings the SSH operations toolbox concept into DSH agent workspaces, providing an experience close to VS Code Remote-SSH. Through persistent connections and automatic tool interception, it makes remote development environments no different from local ones for the agent.