Preface¶
In the development scenarios of DeepSeek Harness (DSH), agents need to frequently access code repositories to perform operations. Managing accounts on multiple code hosting platforms (GitHub, Gitea, etc.), ensuring project-level access isolation, and controlling push behavior are common security and collaboration pain points. Manual configuration is often cumbersome and prone to leaking sensitive information, while directly exposing credentials to the model context creates security risks.
dsh-git-forge is a community plugin designed to provide DSH with centralized repository account management, project-path-based authorization, and fine-grained push policy control.
What Is This¶
This is a DeepSeek Harness community plugin maintained by thirsty5034. It is integrated into dsh-better-sidebar (≥ 0.12) and addresses Git access and permission management issues for agents in multi-account and multi-project environments.
Core features include:
* Account Store: Unified management of GitHub / Gitea / GitLab / Gitee / Bitbucket accounts.
* Project Authorization: Binds account authorization to the DSH session workspace path.
* Push Guard: Intercepts unauthorized git push and git remote operations in the host tools.guard.
Core Features¶
Accounts and Authorization¶
The plugin stores data under $DSH_HOME/git-forge/:
* accounts.json: account metadata (does not contain tokens).
* secrets.json: tokens (permissions 0600).
* grants.json: mapping between project paths and account IDs.
The authorization key (projectPathKey) defaults to the current working directory of the workspace (workspace cwd). In the Agent Shell environment, the authorization key is passed via the environment variable DSH_GIT_FORGE_PROJECT.
Model Tools¶
Models can perform read-only operations by calling the GitForge tool:
* action=list_accounts: lists all configured accounts.
* action=get_policy: retrieves the current authorization policy.
* action=list_project_accounts: lists authorized accounts for the current project.
* action=check_remote: checks whether a remote repository URL is in the authorized list (for example: url=git@github.com:org/repo.git).
Agent HTTPS and Credentials¶
In the DSH Agent Shell, HTTPS Git operations are handled by the plugin’s credential assistant:
* Secure Isolation: Tokens never enter the model context or are included in tool/API return results.
* R1 Limitation: For the same Git host, at most one authorized token account is filled in.
* Assistant Resolution: The credential resolution order is environment variable -> exact current directory -> upward traversal of /workspace parent directories.
Push Policy¶
- Guard Mechanism: Push policies are enforced in the host
tools.guard, interceptingbash git pushandgit remote add|set-urloperations pointing to unauthorized hosts. - Progressive Enablement: If no authorization is configured for a specific project, push is not blocked by default (progressive enablement); in this case, the credential assistant also does not provide credentials.
Installation and Enablement¶
Before installing, ensure Node.js 18+ is installed and that the DSH Web configuration file integrates dsh-better-sidebar (version ≥ 0.12).
Run the following command to install on macOS or Linux:
curl -fsSL https://raw.githubusercontent.com/thirsty5034/dsh-git-forge/main/scripts/install.sh | bash
After installation is complete, restart the DSH Web service and perform a hard refresh in the browser (Cmd/Ctrl + Shift + R) to load the plugin.
Applicable Scenarios and Notes¶
- Applicable Scenarios: Scenarios where agents need restricted Git access, account isolation in multi-team collaboration environments, or security audit requirements for code push behavior.
- SSH and System Tools: SSH remote connections and system-level
gh authcontinue to use local SSH configuration or GitHub CLI, and are not affected by this plugin. Only in the DSH Agent Shell do HTTPS requests have authorized credentials filled in by the plugin’s credential assistant. - Security Notice: The plugin enforces policies through the host
tools.guard, and token file permissions are strictly set to0600, ensuring that only the user running DSH can read them.
Summary¶
dsh-git-forge provides a complete solution from account management to project authorization and then to push policy control. It isolates sensitive information from the model context and restricts the scope of agent Git operations through fine-grained policies, making it suitable for DSH ecosystem builds that require rigorous permission management.