Preface

In the development scenarios of DeepSeek Harness (DSH), agents need to frequently access code repositories to perform operations. Managing accounts on multiple code hosting platforms (GitHub, Gitea, etc.), ensuring project-level access isolation, and controlling push behavior are common security and collaboration pain points. Manual configuration is often cumbersome and prone to leaking sensitive information, while directly exposing credentials to the model context creates security risks.

dsh-git-forge is a community plugin designed to provide DSH with centralized repository account management, project-path-based authorization, and fine-grained push policy control.

What Is This

This is a DeepSeek Harness community plugin maintained by thirsty5034. It is integrated into dsh-better-sidebar (≥ 0.12) and addresses Git access and permission management issues for agents in multi-account and multi-project environments.

Core features include:
* Account Store: Unified management of GitHub / Gitea / GitLab / Gitee / Bitbucket accounts.
* Project Authorization: Binds account authorization to the DSH session workspace path.
* Push Guard: Intercepts unauthorized git push and git remote operations in the host tools.guard.

Core Features

Accounts and Authorization

The plugin stores data under $DSH_HOME/git-forge/:
* accounts.json: account metadata (does not contain tokens).
* secrets.json: tokens (permissions 0600).
* grants.json: mapping between project paths and account IDs.

The authorization key (projectPathKey) defaults to the current working directory of the workspace (workspace cwd). In the Agent Shell environment, the authorization key is passed via the environment variable DSH_GIT_FORGE_PROJECT.

Model Tools

Models can perform read-only operations by calling the GitForge tool:
* action=list_accounts: lists all configured accounts.
* action=get_policy: retrieves the current authorization policy.
* action=list_project_accounts: lists authorized accounts for the current project.
* action=check_remote: checks whether a remote repository URL is in the authorized list (for example: url=git@github.com:org/repo.git).

Agent HTTPS and Credentials

In the DSH Agent Shell, HTTPS Git operations are handled by the plugin’s credential assistant:
* Secure Isolation: Tokens never enter the model context or are included in tool/API return results.
* R1 Limitation: For the same Git host, at most one authorized token account is filled in.
* Assistant Resolution: The credential resolution order is environment variable -> exact current directory -> upward traversal of /workspace parent directories.

Push Policy

  • Guard Mechanism: Push policies are enforced in the host tools.guard, intercepting bash git push and git remote add|set-url operations pointing to unauthorized hosts.
  • Progressive Enablement: If no authorization is configured for a specific project, push is not blocked by default (progressive enablement); in this case, the credential assistant also does not provide credentials.

Installation and Enablement

Before installing, ensure Node.js 18+ is installed and that the DSH Web configuration file integrates dsh-better-sidebar (version ≥ 0.12).

Run the following command to install on macOS or Linux:

curl -fsSL https://raw.githubusercontent.com/thirsty5034/dsh-git-forge/main/scripts/install.sh | bash

After installation is complete, restart the DSH Web service and perform a hard refresh in the browser (Cmd/Ctrl + Shift + R) to load the plugin.

Applicable Scenarios and Notes

  • Applicable Scenarios: Scenarios where agents need restricted Git access, account isolation in multi-team collaboration environments, or security audit requirements for code push behavior.
  • SSH and System Tools: SSH remote connections and system-level gh auth continue to use local SSH configuration or GitHub CLI, and are not affected by this plugin. Only in the DSH Agent Shell do HTTPS requests have authorized credentials filled in by the plugin’s credential assistant.
  • Security Notice: The plugin enforces policies through the host tools.guard, and token file permissions are strictly set to 0600, ensuring that only the user running DSH can read them.

Summary

dsh-git-forge provides a complete solution from account management to project authorization and then to push policy control. It isolates sensitive information from the model context and restricts the scope of agent Git operations through fine-grained policies, making it suitable for DSH ecosystem builds that require rigorous permission management.