The DSH philosophy is “Everything is a plugin.” When building a DSH agent to interact with WeChat, the conventional one-way pipeline (WeChat → Hermes skill → dsh --profile headless) causes Token costs on cold starts, loss of conversation context, and no notifications for long-running tasks. The dsh-hermes-bridge plugin solves these issues by reusing persistent sessions and using hermes send with zero LLM consumption.

Plugin Positioning

A DSH plugin maintained by dsh-pulse, providing bidirectional communication between DSH and WeChat: inbound dispatch (WeChat message → DSH agent execution) and outbound push (task progress/result → WeChat). It uses the Hermes gateway as the WeChat transport layer and supports reusing DSH agent sessions by working directory, saving 15–20× tokens compared with one-off headless invocations.

Core Features

  • Session Reuse: Persist a resident session pool by working directory (cwd); subsequent messages continue the same conversation, avoiding cold starts.
  • Automatic Push-back: Task statuses (accepted, started, completed/failed) are pushed to WeChat as structured data.
  • Zero LLM Outbound: Notifications are sent via hermes send and do not consume model Tokens.
  • Visible in Web UI: Tasks are registered in ctx.jobs and can be viewed in the Web interface.
  • Persistence and Crash Recovery: The task queue is persisted to disk (JSONL format); after restart, queued tasks are automatically restored or running tasks are re-entered.
  • Interrupt Re-entry: Supports re-queuing interrupted tasks while preserving session state.

Installation and Enablement

The plugin must be installed under the web profile so that the HTTP event loop remains resident.

  1. Install the plugin
   dsh plugin --profile web add @dsh-pulse/dsh-hermes-bridge
  1. Configuration Registration
    The plugin depends on the @deepseek-ai/cordis peer dependency. Add the following content to ~/.dsh/profiles/web/cordis.patch.yml:
   - insert:
       - id: hermes-bridge
         name: 'file:/absolute/path/to/dsh-hermes-bridge/lib/index.js'
         config:
           port: 8643
           authToken: '${env.DSH_BRIDGE_TOKEN}'   # 必填,拒绝无 Token 启动
           pushTarget: 'weixin:<chat_id>'          # 必填,目标聊天 ID
           hermesBin: '/path/to/hermes'            # 可选,默认 'hermes'
           workspaceRoots: ['/path/to/workspace']  # 可选,工作目录白名单

Environment Assumptions

The plugin is written for a specific development environment and cannot be used out of the box in all environments. Please verify the following assumptions:

  • DSH Version: Development is based on 0.1.0-rc.7 (Node ≥ 22). Items such as ctx.agents / ctx.agentPresets are rc-stage snapshots; upgrades may lead to API drift.
  • DSH Profile: The web profile (dsh web) must be used to keep the plugin process resident.
  • Hermes Installation: You must deploy the Hermes Agent gateway yourself (for example, hermes-gateway.service). Outbound communication depends on the hermes send command.
  • WeChat Channel: The iLink personal bot channel is used by default (ilinkai.weixin.qq.com). Outbound targets must be verified with hermes send --list.
  • Session Path: By default, ~/.dsh/sessions is used; adjust if DSH_HOME differs.

Configuration Items

key type default description
port number 8643 Local listening port (host is hardcoded to 127.0.0.1)
authToken string — Required: Bearer Token verified on each request
pushTarget string — Required: e.g., weixin:<chat_id>, resolved by hermes send
hermesBin string hermes Path to the hermes CLI executable
retries number 1 Number of outbound push retries
maxTextLen number 1500 Truncation length for pushed text
preset string standard Agent preset mounted during session setup

Use Cases and Notes

  • Use Case: DSH users who need to receive and execute tasks from WeChat while reusing conversation context and saving tokens.
  • Notes:
  • No authentication layer: The plugin itself has no authentication mechanism; the host listens only on 127.0.0.1. Do not expose it externally.
  • WeChat rate limiting: The iLink channel has sendmessage rate limiting (ret=-2); burst pushes may be dropped.
  • API drift: Regression verification is required after any DSH upgrade.