Introduction¶
DeepSeek Harness (DSH) supports extending capabilities through plugins, but the community ecosystem is large, and unknown risks related to plugin provenance, dependencies, and code logic are high. DeepAtlas (dsh-deepatlas) is a task-aware plugin navigation tool that helps DSH users scan the ecosystem, recommend plugins by task, audit risks before installation, and execute controlled installation only after explicit user consent.
Core Features¶
DeepAtlas provides the following capabilities:
* Task-aware navigation: Scans and recommends candidate plugins based on capability needs such as cross-session memory, messaging integration, and browser automation.
* Ecosystem scanning: Scans the dsh-plugin ecosystem from GitHub and community sources to build a local index.
* Provenance and evidence: Recommends plugins based on provenance and reads evidence such as manifests and READMEs at the full commit.
* Pre-installation audit: Checks lifecycle scripts, dependency structure, native dependencies, bundle patch source-code risks, and Node compatibility.
* Controlled installation: Creates a profile snapshot before installation, triggers the recovery flow on failure, and supports only explicitly authorized installations.
* Local storage: Indexes, audit records, and installation status are stored locally; the GitHub Token is used only to increase API quotas.
Installation and Activation¶
DeepAtlas is in public preview and requires DeepSeek Harness 0.1.1-rc.1 / 0.1.1-rc.2 and Node.js ^22.19.0 || >=24.0.0. DSH plugin management commands are forwarded to pnpm.
1. Install the Plugin¶
Use the official installation command to add the plugin:
dsh plugin --profile web add https://codeload.github.com/Oscar-Williams/dsh-deepatlas/tar.gz/refs/tags/v0.2.3
2. Verify the Configuration¶
After installation, verify that the configuration is active:
dsh --profile web --dump-config
The output should contain the dsh-deepatlas or deepatlas configuration layer.
3. Enable Actual Installation¶
By default, dryRun=true and only a plan is generated. If actual installation is required, override the deepatlas configuration item in the profile configuration:
- id: deepatlas
config:
dryRun: false
Typical Usage¶
DeepAtlas provides six tools: deepatlas_scan, deepatlas_status, deepatlas_find, deepatlas_advise, deepatlas_audit, and deepatlas_install. The recommended workflow is: status check -> scan -> search -> audit -> confirmation -> installation.
1. Describe the Task and Search¶
In DSH, describe the requirement directly, and the host model will invoke the appropriate tools. For example:
* “I want to add cross-session memory to DSH. Help me compare suitable plugins.”
* “Find a Telegram message integration plugin and list candidates and risk signals first.”
2. Audit a Specified Commit¶
After selecting a candidate, check the audit results for the specified commit:
* “Check this plugin’s specified commit; show the audit results before asking me whether to install it.”
3. Execute Installation¶
After user confirmation, DeepAtlas performs static audit, compatibility checks, snapshot, locked installation, and the recovery flow.
Applicable Scenarios and Notes¶
- Applicable scenarios: When specific capabilities need to be added to DSH (such as memory or automation), quickly screen safe candidates; perform detailed code-level audits before installing unfamiliar plugins.
- Permissions and security: Plugins run with the permissions of the current DSH process. Indexes and audit records are stored locally; ensure the
DEEPATLAS_GITHUB_TOKENenvironment variable is configured correctly. - Current status: DeepAtlas is in public preview, and DeepSeek Harness is in Developer Preview.
Conclusion¶
DeepAtlas introduces capability coverage checks and risk audit mechanisms to the DSH plugin ecosystem, turning plugin navigation from “blind selection” into “evidence-based decision-making.” For more details, refer to its plugin directory page or GitHub repository.