Introduction

DeepSeek Harness (DSH) supports capability extension through plugins. This plugin connects DeepSeek Harness to Netcatty’s official External MCP server. In local development or when using SSH/SFTP, toolchains usually need to be managed separately or external services are required. With this plugin, DSH can directly invoke the tools provided by Netcatty without exposing sensitive credentials directly to the DSH process.

What Is This

dsh-netcatty is a DeepSeek Harness plugin maintained by developer qq739844663 and released under the MIT License.

Its core role is: registering Netcatty tools into DSH. The plugin itself does not handle SSH sessions, SFTP transfers, or Vault data; these security-sensitive operations remain natively managed by Netcatty. DSH communicates only through the standardized MCP protocol with Netcatty to invoke tools.

Core Features

Based on verified facts, the plugin provides the following capabilities:

  • Connect to the official server: Connects directly to Netcatty’s official External MCP server.
  • Tool registration: Registers the tools exposed by Netcatty in DSH.
  • Permission control: Enforces Netcatty’s permission policies and displays approval requests when protected operations are performed.
  • Protocol support: Supports SSH and SFTP operations.

Installation and Enabling

Before installing, ensure your environment meets the dependency requirements.

Prerequisites

  • DeepSeek Harness: Requires @deepseek-ai/dsh-mcp-client 0.1.0-rc.7 or a newer version.
  • Netcatty: Requires version 1.1.80 or newer.
  • Configuration: Enable the External MCP feature in Netcatty under Settings > AI > External MCP.
  • Running state: Netcatty must remain running while DSH uses the tools; persistent mode is recommended.

Installation Commands

For the default Web Profile:

dsh plugin --profile web add https://github.com/qq739844663/dsh-netcatty

If using a headless Profile, run:

dsh plugin --profile headless add https://github.com/qq739844663/dsh-netcatty

After installation, the DSH Web host must be restarted for the tools to be registered in DSH with the mcp__netcatty__ prefix.

Typical Usage and Configuration

For standard installation paths, DSH automatically locates Netcatty’s netcatty-external-mcp launcher. If the installation location is non-standard, specify it via environment variables or a configuration file.

1. Non-Standard Installation Path

Set the NETCATTY_MCP_LAUNCHER environment variable before starting DSH:

$env:NETCATTY_MCP_LAUNCHER = 'D:\Apps\Netcatty\resources\app.asar.unpacked\electron\cli\netcatty-external-mcp.cmd'
dsh web

2. Non-Default Profile

If using a non-default Netcatty Profile, set NETCATTY_EXTERNAL_MCP_DISCOVERY_FILE to point to that Profile’s external-mcp/discovery.json file.

3. Customized Configuration

You can override default behavior with an Override Patch, for example adjusting timeout duration or reconnection strategy:

- id: netcatty-external-mcp
  config:
    launcherPath: D:\\Apps\\Netcatty\\resources\\app.asar.unpacked\\electron\\cli\\netcatty-external-mcp.cmd
    discoveryFile: C:\\Users\\me\\AppData\\Roaming\\Netcatty\\external-mcp\\discovery.json
    toolCallTimeoutMs: 120000
    failOnStartupError: false
    reconnect:
      enabled: true
      initialDelayMs: 1000
      maxDelayMs: 30000
      maxAttempts: 10

Applicable Scenarios and Notes

Security Mechanisms

The plugin follows the “least privilege” principle. It does not parse Netcatty’s Vault, does not read stored credentials, and does not copy discovery tokens. All authentication and session management are handled independently by Netcatty’s official launcher.

Startup Error Handling

The plugin’s default setting is failOnStartupError: false. This means that if Netcatty is detected as not installed or fails to start, the DSH Profile will continue running, but Netcatty tools will simply be unavailable. If you want the tools to take effect immediately after installing Netcatty, restart DSH after installing or enabling Netcatty.

Summary

dsh-netcatty solves the connection problem between DeepSeek Harness and Netcatty. It allows DSH to leverage Netcatty’s SSH/SFTP capabilities while keeping security boundaries clear. For developers who need to integrate DeepSeek into SSH management or file transfer scenarios, this is a direct integration solution.

  • GitHub Repository: https://github.com/qq739844663/dsh-netcatty
  • Plugin Directory: https://www.skillhub.cn/plugins/qq739844663/dsh-netcatty