When developing agents with DeepSeek Harness (DSH), API settings, credentials, profile plugin patches, and user agent presets are often scattered across different files. Manually migrating these configurations is tedious and error-prone. The dsh-config-sync plugin provides a toolkit for exporting DSH configuration as a portable backup package or encrypted file, enabling fast recovery in new environments.

Plugin Overview

  • Name: muyifc/dsh-config-sync
  • Category: Workflow
  • License: MIT

Core Features

The plugin registers 5 model tools for backing up, restoring, and inspecting configuration status:

  1. dsh_config_export: Exports the configuration as a directory package containing manifest.json and the corresponding files.
  2. dsh_config_export_encrypted: Exports the configuration as a single passphrase-encrypted file (.dshsync).
  3. dsh_config_import: Restores configuration from a directory package. Previewing is supported before import, and an automatic backup is created before the actual overwrite.
  4. dsh_config_import_encrypted: Decrypts and restores configuration from a .dshsync file.
  5. dsh_config_status: Inspects the configuration and backup manifest. This tool filters out credential contents to ensure safety.

Installation and Activation

Run the following command in the terminal to install the plugin:

dsh plugin --profile web add dsh-config-sync

After installation is complete, restart the DeepSeek Harness service for the changes to take effect.

Typical Usage

Issue instructions directly in the conversation, or let the model call the tools above:

  1. Export as a directory package:
    “Export my configuration to D:\backup”
  2. Export as an encrypted file:
    “Encrypt and export my configuration to D:\backup”
  3. Restore from an encrypted file:
    “Restore configuration from D:\backup\dsh-config-.dshsync, passphrase xxx”
  4. Check status:
    “Check my DSH configuration sync status”

Security and Notes

  • Path restrictions: Import operations only accept allowlisted paths, and explicitly reject path traversal (..), absolute paths, and the node_modules directory.
  • Automatic backup: Imports default to a dry_run preview. If overwriting is confirmed, old files are automatically backed up to <DSH_HOME>\config-backups\pre-import-<timestamp>.
  • Privacy protection: Credential contents will never appear in the execution results of any tool.
  • Encryption standard: Encrypted files use PBKDF2-SHA256 (600,000 iterations) + AES-256-GCM. The passphrase is the only line of defense; losing the passphrase will make the file unrecoverable.

This plugin is suitable for developers who need to synchronize DSH configuration across multiple machines or want to store sensitive credentials encrypted. It is recommended to review the source code and license before installation.