Introduction¶
DeepSeek Harness’s ecosystem philosophy is that “everything is a plugin.” When using an Agent to handle code repository-related tasks, directly invoking the local gh tool is one of the most efficient approaches. Existing MCP solutions often require separately configured Tokens or are limited by a tool list. This plugin aims to address this pain point, allowing you to reuse the local gh login state and execute GitHub commands in Harness with zero configuration.
Plugin Overview¶
This plugin was developed by Nico0713520, is licensed under the MIT License, and is categorized as a network tool. It allows you to directly reuse a locally installed GitHub CLI (gh) in Harness without configuring a new Token or going through a complex OAuth flow. The plugin adopts a read-first security strategy by default and ensures operational safety through a command allowlist mechanism.
Core Features¶
- Reuses the local
ghlogin state (no token configuration required) - Zero configuration, zero tokens
- Read-first; only safe commands are allowed by default
- Write operations require explicitly enabling
fullAccess - Credentials permanently blocked (auth token, secret, etc.)
- No injection (execFile + argument array)
- Supports enterprise/SSO accounts
- Provides the
gh_cli_runandgh_auth_statustools - 18 unit tests + three Node.js CI versions
Installation and Enablement¶
Installing the plugin requires using the official DSH plugin management command. Make sure you have the permission to install gh.
dsh plugin --profile web add git+https://github.com/Nico0713520/dsh-github-cli.git
After installation is complete, the dsh web process must be restarted for the plugin to take effect at the Bundle layer.
Typical Usage¶
The plugin provides two main tools:
- gh_cli_run: Executes any gh subcommand using an argument array.
- gh_auth_status: Checks whether gh is installed and logged in.
They can be invoked directly in a conversation. For example:
- Query open pull requests in a repository:
gh pr list --state open -R deepseek-ai/deepseek-harness
- View changes in PR #123:
gh pr diff 123
- Check the gh login status:
gh_auth_status
Configuration¶
The plugin reads GhCliConfig (configured in the profile’s plugin settings):
- insert:
- id: gh-cli
name: gh-cli
config:
fullAccess: false
timeoutMs: 120000
Notes¶
- After installation,
dsh webmust be restarted for the plugin to take effect. - Commands such as
gh auth tokenare unconditionally rejected. - Read-only by default; permissions can be enabled as needed.
- Requires Node.js ≥ 20 and a logged-in GitHub CLI.
- Supports newer gh versions.
Conclusion¶
This plugin lowers the barrier to using GitHub in Harness by reusing local environment credentials. Its default security model (read-first, credentials permanently blocked) is suitable for scenarios with strict security requirements.