DeepSeek Harness (DSH) uses a plugin-based architecture. When handling workspace environment configuration, developers often want to reuse locally configured .envrc files. DSH’s native environment management, however, differs from the behavior of direnv, and parsing .envrc directly within the DSH process introduces complexity in state management. The dsh-workspace-envrc plugin is designed to solve this problem. It delegates the discovery, evaluation, and authorization validation of .envrc entirely to the direnv executable installed on the host, thereby providing native direnv environment behavior within DSH.

This is an out-of-tree DSH bundle maintained by TTTPOB. Its core purpose is to apply the host’s native direnv environment to Bash executions that are explicitly attributed to an Agent or workspace, as well as local stdio workspace MCP lines. The plugin does not parse or source .envrc directly, nor does it maintain its own authorization database; instead, it invokes the host’s direnv to perform all environment changes.

Core Features

  1. Bash Environment Integration: The integration plugin reversibly decorates ctx.shell.resolve. When the call has a current initiator Agent and that Agent maps to a canonical workspace, the plugin replaces request.command with a command launched through direnv exec, ensuring that environment variables are managed by direnv.
  2. MCP Environment Integration: The integration plugin reversibly decorates ctx.workspaceMcp.activate. Only local stdio MCP lines mapped to a canonical workspace are wrapped so that the direnv environment is applied during execution.
  3. Full Delegation: The plugin delegates .envrc discovery, evaluation, authorization hash, allow/deny logic, and stdlib handling entirely to the installed direnv executable. It does not itself hold environment snapshots or authorization data.

Installation and Enablement

Before installing, ensure that direnv is installed on the host and that the required dsh-workspace-overlay dependency is installed. Follow these steps:

  1. Install the overlay bundle first:
    dsh plugin --profile web add https://github.com/TTTPOB/dsh-workspace-overlay/releases/download/v0.1.1/dsh-workspace-overlay-0.1.1.tgz
  1. Then install the envrc bundle:
    dsh plugin --profile web add https://github.com/TTTPOB/dsh-workspace-envrc/releases/download/v0.1.1/dsh-workspace-envrc-0.1.1.tgz
  1. Export the configuration to verify the installation:
    dsh --profile web --dump-config

After installation, verify module resolution and the final composition. Ensure that in dsh.profile.bundles the overlay is placed before envrc, and restart the Host.

Configuration and Usage

The plugin configuration is defined by the WorkspaceEnvrcConfig interface, with the following defaults:

executable: direnv
shimShell: /bin/bash
enableBash: true
enableWorkspaceMcp: true
versionCheckTimeoutMs: 5000

Activation and Preflight:
During activation preflight, the plugin runs direnv version and a restricted shim probe to verify that direnv is available. However, it does not read the workspace’s .envrc at this stage.

Authorization Management:
The authorization process is handled entirely by the host’s direnv. Users must run direnv allow <exact .envrc> outside DSH. The plugin does not expose allow/deny tools to the model and does not invoke direnv allow/permit/grant/edit.

How It Works:
For Bash, the plugin starts a new process via exec direnv exec <canonical-workspace> <managed-env-shim> <original-command>, preserving the caller-resolved cwd for the original program. For MCP, the plugin only rewrites command/args, without changing cwd or explicit env.

Applicable Scenarios and Notes

Unsupported Features:
This bundle does not support persistent shells or terminal creation. DSH mounts terminals in a preset private isolated realm, and this plugin, as a Host profile layer, relies on an internal mounting API that is not yet stable to implement that capability. For this reason, it is currently restricted.

Security and Boundaries:
1. Stateless: The plugin does not modify the Harness process.env. Executions in different workspaces are resolved by Agent scope and do not share mutable workspace state.
2. Privacy Protection: The plugin does not read, log, or print full environment snapshots, .envrc contents, stdout/stderr, or secrets.
3. Sandbox Limitations: The current overlay MCP stdio transport lacks a sandbox/confine seam. Therefore, MCP child processes and .envrc evaluation use the transport’s host process permissions and are not claimed to be equivalent to the Bash sandbox.

Summary

dsh-workspace-envrc provides a non-invasive way for DSH to leverage the host’s native direnv capabilities to manage workspace environments. By using a delegation mechanism, it avoids maintaining environment state inside DSH. It is suitable for development scenarios that require seamless use of local .envrc configurations within DSH.