Introduction

DeepSeek Harness (DSH) is a plugin-based agent development framework. When building agents with DSH, it is often necessary to let the model operate a remote Linux server directly. Although the model can invoke a shell tool, executing remote commands directly usually requires additional configuration. The dsh-ssh-plugin provides a native ssh_exec tool, allowing the model to run commands directly on remote servers using the system’s built-in SSH client.

Plugin Overview

This plugin was developed by maintainer YOLO-LZL. It mainly addresses two problems: first, it provides an ssh_exec model tool that allows commands to be executed directly on remote Linux servers; second, it supports persistent SSH connections, allowing connection configurations to be saved in the workspace for later use.

Core Features

The plugin’s core features include:
1. Model Tool Integration: Provides an ssh_exec tool for the model, supporting natural language instructions (such as “ssh to root@10.0.0.5 and show disk usage”) or explicit parameter invocation.
2. Persistent Connection Management: Provides an ssh_connections tool that supports saving, listing, and deleting connections, and binds connections to a workspace as the default connection.
3. Key-Based Authentication: Supports key-based authentication only (BatchMode=yes), with no password or private key prompts, preventing hangs caused by authentication failures.
4. No Remote Shell Escaping Layer: Remote commands are passed directly through bash -s, without an additional shell escaping layer.
5. Session Sandbox Awareness: Runs according to the current session’s security policy, and can run unrestricted under the danger-full-access policy.
6. Local Configuration Discovery: Automatically discovers and reads the local ~/.ssh/config file, eliminating the need to manually save configuration aliases.
7. Dual-Side Package Design: Supports both host-side and browser-side usage.
8. Graceful Degradation: The plugin continues to work when certain Harness services (such as settings or workspaceRegistry) are missing.

Installation and Activation

Install the plugin from npm:

dsh plugin --profile <name> add dsh-ssh-plugin

After installation, start Harness to use it:

dsh --profile <name>

Typical Usage

The plugin provides the model with two tools: ssh_exec and ssh_connections.

ssh_exec

The model can use natural language directly or pass explicit parameters to execute a command.

Parameter Required Description
host Yes Remote host address [user@]host, or an alias defined in ~/.ssh/config.
command Yes Command to run on the remote host via bash -s.
port No SSH port, defaults to 22.
key_path No Absolute path to the private key. If omitted, uses the ~/.ssh default or ssh-agent.
timeout_ms No Foreground timeout in milliseconds, defaults to 30000.
connection No Label of a saved connection, used to populate host/port/user/keyPath.

ssh_connections

Used to manage persistent connections. Connection data is stored in Harness settings and persists across restarts.

  • save: Save a connection (requires label and host; optional port, user, keyPath).
  • list: List saved connections, as well as read-only hosts discovered from ~/.ssh/config.
  • delete: Delete a connection by label.
  • use: Bind the current workspace to the specified connection label; subsequent ssh_exec calls can omit the host parameter.

Applicable Scenarios and Notes

  • Target Environment: The target Linux server must have bash installed and key-based SSH access configured (~/.ssh/authorized_keys).
  • Windows Environment: When running on Windows, the session sandbox policy must be danger-full-access; otherwise a restricted token may prevent launching ssh.exe.
  • Security: The plugin stores only the key path; key contents do not leave the local disk.
  • License: The plugin is licensed under the MIT License.

Closing

By wrapping SSH client calls, this plugin simplifies agent operations on remote servers. Combined with persistent connections, it reduces repetitive configuration. The related code is available on GitHub.