In the DeepSeek Harness (DSH) plugin ecosystem, handling remote development environments usually means manually connecting over SSH or syncing local files. The DSH plugin dsh-rw introduces Remote-SSH-style workspaces, enabling agents to operate the remote file system directly. This plugin is maintained by MDR-EX1000 and aims to eliminate the fragmentation between local and remote environments.

Core Concepts

dsh-rw allows you to select an SSH host and a remote directory, making it a native DSH workspace. The agent works directly on the remote file system via rw_* tools (SFTP/exec based on a persistent ssh2 connection pool). The remote directory is the single source of truth: there is no mirroring and no syncing.

Since version 0.4.0, this plugin supports zero configuration.

Core Features

  • Native remote workspace selector: In DSH’s “Add Workspace” flow, selected via a modal. The interface is split into LOCAL (local folder) and REMOTE (Codex-style page). The remote page supports selecting from an alias dropdown, auto-filling the ~/ path, and live-filtering directories.
  • Language follows DSH global settings: Labels, prompts, validation messages, loading states, and confirmation messages in the selector support Chinese and English, and follow DSH’s global language settings in real time.
  • Read hosts from ~/.ssh/config: No extra configuration is required. Existing SSH aliases are displayed automatically, and the file is re-read when it changes. Password-authenticated hosts can be added through the interface and stored as a local file with 0600 permissions.
  • Real workspace isolation: All rw_* file paths are restricted to the selected workspace root directory. The system rejects ../, absolute paths outside the root directory, and symlink escapes.
  • SSH host key verification: By default, verification uses ~/.ssh/known_hosts. It supports the accept-new (record first-seen keys), strict, and off strategies. Changed host keys are rejected and are not silently accepted.
  • Structured errors: Connection refused, authentication failure, timeout, missing path, permission denied, out-of-workspace access, and host key issues all return distinct error codes, making it easier for agents to handle them correctly.
  • Connection self-healing: Uses ssh2 connection pool heartbeats (15s × 3) to detect disconnections, with a default channel open timeout of 10s. Operations that encounter a dead connection automatically retry once, transparent to the agent.
  • Placeholders rather than copies: The local directory registered in DSH is an empty placeholder (.dsh-rw-meta.json records the source). Remote file contents are not stored, so there are no sync conflicts.
  • Shim Mode (enabled by default): DSH native tools (such as read, write, edit, and bash) are intercepted and translated into remote execution. The agent does not need to learn rw_* tools to operate remotely just like locally. Path mapping is bidirectional between the placeholder and the remote system. Set shim: false to disable this mode.
  • Explicit failure policy: If the host corresponding to a placeholder is removed, operations invoked through that placeholder report an error (NOT_CONNECTED), instead of silently running against an empty local directory.

Installation

Install the plugin through DSH Market:

dsh plugin --profile web add github:MDR-EX1000/dsh-rw

This repository tracks compiled lib/ output, so installing this source does not require a local TypeScript toolchain or build permissions. If you need the exact release package:

dsh plugin --profile web add https://github.com/MDR-EX1000/dsh-rw/releases/latest/download/dsh-rw.tgz

Maintenance note: Because the plugin has no prepare or similar lifecycle hooks, the runtime entry point is the committed lib/index.js. If you modify the source, manually run pnpm build and commit the generated lib/ to Git. The ssh2 dependency used by the plugin may require pnpm permission for optional native modules.

Typical Usage

  1. Select a workspace: In the sidebar or conversation, choose “Add Workspace” -> “REMOTE” card. Select a host from ~/.ssh/config (or add a password-based host), browse or enter a remote path (starting from ~/ by default), then enter a workspace name and activate it.
  2. Routine collaboration: In Shim Mode (default), directly ask the agent to fix bugs, run tests, or refactor code. The agent automatically uses native tools to perform remote operations.
  3. Explicit remote operations: Use rw_* tools for specific operations:
    • File operations: rw_list_dir, rw_read_file, rw_write_file, rw_mkdir, rw_move, rw_delete
    • Command execution: rw_exec (CWD is the workspace root directory)
    • Session management: rw_hosts, rw_connect, rw_disconnect

Notes

  • Shim Mode: Enabled by default. To disable it, set shim: false in the configuration file.
  • Permission Requirements: The ssh2 dependency requires permissions for optional native modules, and pnpm’s build script whitelist must include this dependency.
  • Git Repository: Keep the lib/ folder in Git so that it can be rebuilt after changes to src/.
  • Key Verification: SSH host key verification is based on ~/.ssh/known_hosts.

Summary

dsh-rw brings the SSH operations toolbox concept into DSH agent workspaces, providing an experience close to VS Code Remote-SSH. Through persistent connections and automatic tool interception, it makes remote development environments no different from local ones for the agent.