Introduction¶
DeepSeek Harness (DSH) is a plugin-based agent development framework. When building agents with DSH, it is often necessary to let the model operate a remote Linux server directly. Although the model can invoke a shell tool, executing remote commands directly usually requires additional configuration. The dsh-ssh-plugin provides a native ssh_exec tool, allowing the model to run commands directly on remote servers using the system’s built-in SSH client.
Plugin Overview¶
This plugin was developed by maintainer YOLO-LZL. It mainly addresses two problems: first, it provides an ssh_exec model tool that allows commands to be executed directly on remote Linux servers; second, it supports persistent SSH connections, allowing connection configurations to be saved in the workspace for later use.
Core Features¶
The plugin’s core features include:
1. Model Tool Integration: Provides an ssh_exec tool for the model, supporting natural language instructions (such as “ssh to root@10.0.0.5 and show disk usage”) or explicit parameter invocation.
2. Persistent Connection Management: Provides an ssh_connections tool that supports saving, listing, and deleting connections, and binds connections to a workspace as the default connection.
3. Key-Based Authentication: Supports key-based authentication only (BatchMode=yes), with no password or private key prompts, preventing hangs caused by authentication failures.
4. No Remote Shell Escaping Layer: Remote commands are passed directly through bash -s, without an additional shell escaping layer.
5. Session Sandbox Awareness: Runs according to the current session’s security policy, and can run unrestricted under the danger-full-access policy.
6. Local Configuration Discovery: Automatically discovers and reads the local ~/.ssh/config file, eliminating the need to manually save configuration aliases.
7. Dual-Side Package Design: Supports both host-side and browser-side usage.
8. Graceful Degradation: The plugin continues to work when certain Harness services (such as settings or workspaceRegistry) are missing.
Installation and Activation¶
Install the plugin from npm:
dsh plugin --profile <name> add dsh-ssh-plugin
After installation, start Harness to use it:
dsh --profile <name>
Typical Usage¶
The plugin provides the model with two tools: ssh_exec and ssh_connections.
ssh_exec¶
The model can use natural language directly or pass explicit parameters to execute a command.
| Parameter | Required | Description |
|---|---|---|
host |
Yes | Remote host address [user@]host, or an alias defined in ~/.ssh/config. |
command |
Yes | Command to run on the remote host via bash -s. |
port |
No | SSH port, defaults to 22. |
key_path |
No | Absolute path to the private key. If omitted, uses the ~/.ssh default or ssh-agent. |
timeout_ms |
No | Foreground timeout in milliseconds, defaults to 30000. |
connection |
No | Label of a saved connection, used to populate host/port/user/keyPath. |
ssh_connections¶
Used to manage persistent connections. Connection data is stored in Harness settings and persists across restarts.
save: Save a connection (requireslabelandhost; optionalport,user,keyPath).list: List saved connections, as well as read-only hosts discovered from~/.ssh/config.delete: Delete a connection by label.use: Bind the current workspace to the specified connection label; subsequentssh_execcalls can omit thehostparameter.
Applicable Scenarios and Notes¶
- Target Environment: The target Linux server must have bash installed and key-based SSH access configured (
~/.ssh/authorized_keys). - Windows Environment: When running on Windows, the session sandbox policy must be
danger-full-access; otherwise a restricted token may prevent launchingssh.exe. - Security: The plugin stores only the key path; key contents do not leave the local disk.
- License: The plugin is licensed under the MIT License.
Closing¶
By wrapping SSH client calls, this plugin simplifies agent operations on remote servers. Combined with persistent connections, it reduces repetitive configuration. The related code is available on GitHub.