DeepSeek Harness (DSH) 的插件机制 translates:

The plugin mechanism of DeepSeek Harness (DSH) enables local agents to integrate with a variety of services. For enterprise users, direct access to Aloof’s team knowledge base and approval workflows is essential. The dsh-aloof plugin provides this connectivity, turning Aloof’s data permissions, approval chains, and audit trail capabilities into a native DSH toolset.

The plugin is maintained by gaochonggeng, categorized as a web tool, and licensed under MIT.

Installation

Install it under DSH’s web profile:

dsh plugin --profile web add dsh-aloof

After installation, pass the ticket via an environment variable to use it.

Ticket Usage

Use an Aloof dsh access token. Its format is alf_xxx@https://aloof.你的公司.com.

  • Address binding: The ticket binds the key to an Aloof address, preventing a mistyped address from sending the ticket to the wrong server.
  • Scope: The data-read permissions of an access token are consistent with a login ticket, but it does not have permission to approve/reject. Calling oa_decide under an access token causes the backend to return 403 directly.
  • Revocation: Access tokens can be revoked individually, while login tickets cannot be invalidated individually.

Set the ticket:

export ALOOF_TOKEN='alf_xxxx@https://aloof.你的公司.com'
dsh web

Core Features

The plugin provides two tool groups: Team Knowledge Base (6 tools) and Office Approval (5 tools).

Team Knowledge Base

These tools are for reading and modifying shared documents in Aloof.

Tool Function Notes
kb_spaces List spaces I can access Returns spaceId and role
kb_search Full-text search Search by name, purpose description, and body
kb_list List directory hierarchy Used to find parentId
kb_read Read full document text For binary files such as Word/PPT/images, it explicitly returns “cannot read”
kb_write Create or append to a document Default is append mode; overwriting requires explicitly specifying mode: replace
kb_delete Delete a document or directory Irreversible; confirmation text is provided by the server
  • Version control: kb_write automatically handles the version number (rev) using optimistic locking. If the document has been modified by someone else before writing, the request is rejected by the backend; re-read it before writing again.
  • File types: kb_write only supports text documents (md/csv/html/txt/json); binary file upload is not supported.

Office Approval

These tools are for handling approval workflows, consisting of four steps: query template -> read fields -> fill form -> submit.

Tool Function Notes
oa_todo Query pending tasks Returns taskId
oa_templates Query available templates Returns templateId
oa_form Query form fields Returns field keys, types, required items, etc.
oa_submit Initiate an approval form Gate approval required
oa_decide Approve or reject Always 403 under an access token

Two Gates for Write Operations

All write operations (kb_write, kb_delete, oa_submit, and oa_decide) are controlled by two independent gates.

  1. Local gate: Before sending the request, it calls ctx.approval.request(), writes the operation content into reason, and asks the user to confirm. It continues only if allowed-once is obtained. If rejected or the session is canceled, the request is not sent to the Aloof backend.
  2. Server gate: The Aloof backend has a (method, route) allowlist that intercepts write requests. Write requests not on the allowlist (such as oa_decide) are directly rejected by the backend with 403.

The local gate can be disabled (via configuration), but the server gate cannot be bypassed.

Configuration

The default configuration is in the plugin-bundled cordis.patch.yml. Do not modify this file; upgrades will overwrite it. To override it, replace the config block by id in the profile’s cordis.patch.yml:

- id: aloof
  name: 'dsh-aloof'
  config:
    tokenEnv: ALOOF_TOKEN
    timeoutMs: 20000
    requireApproval: true
  • tokenEnv: Specifies the environment variable name (e.g., ALOOF_TOKEN).
  • timeoutMs: Timeout for a single request (milliseconds).
  • requireApproval: Whether to force write operations through the gate (true is fail closed).
  • baseUrl: Usually not required. Only fill it in when the web address and the DSH-reachable address differ (e.g., dual entry points for internal and external networks).

Limitations

  • No settings page: Configuration can currently only be modified via YAML or environment variables.
  • No dedicated UI card: Output is text only; approval buttons or document diffs cannot be rendered in the conversation.
  • No file transfer: Uploading attachments is not supported.