One of the core concepts of DeepSeek Harness (DSH) is “everything is a plugin,” allowing skills to be extended through the filesystem. For CTF-style challenges, managing a large number of skill cards usually means maintaining scattered files in ~/.dsh/skills. This plugin provides a versioned, structured alternative by wrapping the existing HTB skill library.

What This Is

This is a plugin wrapper around the Hack The Box (HTB) skill library.
* Maintainer: qingsiweisan
* Content: 114 skill cards covering 10 areas, including Web, AD-Windows, Linux, databases, cloud, forensics, and more.
* Mechanism: It uses the official @deepseek-ai/dsh-skill-filesystem provider mechanism to register as a skill provider named htb.

Core Features

  • Skill management: Skills are versioned with the package, managed with Git, and support instant hot reloading after edits. They are not written directly into ~/.dsh/skills.
  • Layered structure:
    • T1 routing cards: Placed in the session directory and used for routing.
    • T2 depth cards: Loaded by name and used for deep analysis.
    • T3 reference cards: Loaded by name, with disable-model-invocation: true, used to hide entries or serve as reference material.
  • HTB integration: Registers htb_sherlock_* model tools and supports HTB Labs API operations such as info/tasks/download/submit/submit-file/progress.

Installation and Enablement

Use a link install to allow local code changes and hot reloading:

# 1. 克隆仓库
git clone https://github.com/qingsiweisan/dsh-htb-skills.git

# 2. 安装到 DSH profile(例如 web)
dsh plugin --profile web add link:./dsh-htb-skills

# 3. 重启 dsh web,新建会话即可看到 htb-skill-index 等 T1 卡

The steps are the same on Linux / Kali; simply replace the local path.

Typical Usage

  • View skills: After starting a new session, you will automatically see htb-skill-index (T1 master index) and the corresponding T1 routing cards.
  • Add custom skills: Create a directory under skills/ and write a SKILL.md. Then register the domain and tier in the MAPPING dictionary in scripts/triage_skills.py, and run the validation script.

Applicable Scenarios and Cautions

  • Compatibility: Requires DeepSeek Harness 0.1.0-rc.x (aligned with @deepseek-ai/dsh-skill-filesystem ^0.1.0-rc.6); the Node.js environment must be ^22.19.0 or >=24.0.0.
  • Community nature: This is a community project and does not imply official endorsement or approval by DeepSeek.
  • Conflict handling: After the plugin is mounted, standalone skills with the same name in ~/.dsh/skills will duplicate the plugin skills. When names conflict, the preset layer shadows the global layer. When migrating, it is recommended to back up the standalone directory first before clearing it:
    mv ~/.dsh/skills ~/.dsh/skills.bak
  • Developer preview period: Harness is currently in developer preview; watch for breaking changes after upgrades.

Summary

This plugin integrates the HTB skill library into DeepSeek Harness through the standardized provider mechanism, solves the problem of fragmented skill management, and improves usage efficiency with hot reloading and a layered structure.

GitHub repository | Skill library directory