Introduction

DeepSeek Harness’s ecosystem philosophy is that “everything is a plugin.” When using an Agent to handle code repository-related tasks, directly invoking the local gh tool is one of the most efficient approaches. Existing MCP solutions often require separately configured Tokens or are limited by a tool list. This plugin aims to address this pain point, allowing you to reuse the local gh login state and execute GitHub commands in Harness with zero configuration.

Plugin Overview

This plugin was developed by Nico0713520, is licensed under the MIT License, and is categorized as a network tool. It allows you to directly reuse a locally installed GitHub CLI (gh) in Harness without configuring a new Token or going through a complex OAuth flow. The plugin adopts a read-first security strategy by default and ensures operational safety through a command allowlist mechanism.

Core Features

  • Reuses the local gh login state (no token configuration required)
  • Zero configuration, zero tokens
  • Read-first; only safe commands are allowed by default
  • Write operations require explicitly enabling fullAccess
  • Credentials permanently blocked (auth token, secret, etc.)
  • No injection (execFile + argument array)
  • Supports enterprise/SSO accounts
  • Provides the gh_cli_run and gh_auth_status tools
  • 18 unit tests + three Node.js CI versions

Installation and Enablement

Installing the plugin requires using the official DSH plugin management command. Make sure you have the permission to install gh.

dsh plugin --profile web add git+https://github.com/Nico0713520/dsh-github-cli.git

After installation is complete, the dsh web process must be restarted for the plugin to take effect at the Bundle layer.

Typical Usage

The plugin provides two main tools:
- gh_cli_run: Executes any gh subcommand using an argument array.
- gh_auth_status: Checks whether gh is installed and logged in.

They can be invoked directly in a conversation. For example:
- Query open pull requests in a repository:
gh pr list --state open -R deepseek-ai/deepseek-harness
- View changes in PR #123:
gh pr diff 123
- Check the gh login status:
gh_auth_status

Configuration

The plugin reads GhCliConfig (configured in the profile’s plugin settings):

- insert:
    - id: gh-cli
      name: gh-cli
      config:
        fullAccess: false
        timeoutMs: 120000

Notes

  • After installation, dsh web must be restarted for the plugin to take effect.
  • Commands such as gh auth token are unconditionally rejected.
  • Read-only by default; permissions can be enabled as needed.
  • Requires Node.js ≥ 20 and a logged-in GitHub CLI.
  • Supports newer gh versions.

Conclusion

This plugin lowers the barrier to using GitHub in Harness by reusing local environment credentials. Its default security model (read-first, credentials permanently blocked) is suitable for scenarios with strict security requirements.

Plugin Catalog
GitHub Repository