Introduction¶
DeepSeek Harness (dsh) adopts an “everything is a plugin” design philosophy. Installing and updating plugins locally usually requires command-line operations. dsh-link-plugin enables a locally running dsh instance to actively connect to the dsh community website through a WebSocket gateway. This allows the browser to act as the control endpoint, remotely manage local plugins, view the store registry, and browse installable entries even in offline environments.
Core Features¶
- Securely connect a locally running DeepSeek Harness (dsh) instance to the dsh community website.
- Remotely install plugins from a browser.
- View the store registry.
- Support offline browsing of installable entries.
Installation and Enablement¶
Install the plugin in a dsh profile by running the following command:
dsh plugin --profile web add "github:qwert702/dsh-link-plugin#main"
After installation, the plugin will appear in the plugin settings of the dsh Web UI.
Configuration¶
In the plugin settings of the dsh Web UI, you need to fill in the following fields:
| Field | Description |
|---|---|
serverUrl |
WebSocket server URL. Default: wss://dsh.cbnac.com/ws/harness |
pairingCode |
One-time pairing code used for initial connection verification |
profile |
Profile to be managed. Default: web |
requireConfirm |
Whether to confirm when an installation instruction is received (no interactive confirmation UI currently; accepted automatically by default) |
autoStart |
Whether to connect automatically when dsh starts |
After the initial successful connection, the plugin persists the token and deviceId to ~/.dsh/src-state-link.json, and they will be automatically restored on reconnection.
Pairing Process¶
- Log in at dsh.cbnac.com/console and click “Generate Pairing Code”.
- Enter
serverUrl,pairingCode, andprofilein the dsh-link-plugin settings, then save the configuration. - The plugin will automatically attempt to connect and complete the handshake. At this point, return to the console to see the device online status and the list of installed plugins.
- On the plugin details page, click “Remote Install”, select a device, the local machine will execute the installation instruction, and the console will display progress.
Security Model¶
The plugin safeguards the local environment through strict validation mechanisms:
- Whitelisted installation: The installation source
specmust be anapproved/manualentry in the store registry, and a secondary local validation is performed. - Dangerous input rejection: Instructions containing
./,../,file:,link:,&&,;,|, spaces, quotes, or similar characters are blocked. - Token security: Device tokens are stored on the server only as SHA256 hashes; only the device owner can dispatch instructions; the connection is encrypted with TLS (wss).
- Risk awareness: Installing a plugin will run its build script (
prepare). Check the source code and license before installation.
Offline Browsing¶
When the plugin connects to the server, it caches a copy of the registry. If a repeated pull occurs within 5 seconds, the server skips the request and reuses the old cache. Even when offline, installable entries can still be viewed in the dsh Web UI.
Conclusion¶
dsh-link-plugin provides remote management capabilities for DSH, making it suitable for scenarios that require batch management of plugins via a Web endpoint or control of a local dsh instance through a browser. The plugin is released under the MIT license and maintained by community developers.
- Plugin directory: https://www.skillhub.cn/plugins/qwert702/dsh-link-plugin
- Code repository: https://github.com/qwert702/dsh-link-plugin