Introduction¶
The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When using OpenAI Codex CLI for code analysis or task execution, developers typically need to log in with an OpenAI account. dsh-codex addresses this pain point by integrating Codex CLI into DSH’s tool and skill system, allowing developers to run Codex with local configurations (such as DeepSeek) without requiring an OpenAI login. Through the dsh tool, developers can natively execute one-off tasks, repository reviews, and session resumptions.
Prerequisites¶
Before using this plugin, the following conditions must be met:
1. DeepSeek Harness (dsh) is installed.
2. Codex CLI is installed globally:
npm install -g @openai/codex
codex --version
- The Codex configuration file
~/.codex/config.tomlhas the provider configured (such asmodel_provider,base_url, andmodelfor DeepSeek), or you are logged in viacodex login.
Installation and Enablement¶
The plugin is integrated into DSH through a cordis.patch.yml adaptation layer.
Option 1: Temporary local patch loading (for development)
Run the following command in the root directory of the DSH repository to overlay and load the plugin:
pnpm dsh web --patch ./dsh-codex/cordis.patch.yml
After startup, ask the agent to use the tools.
Option 2: Add as a bundle to the profile
Add the following content to the DSH profile configuration file:
- insert:
- id: codex
name: './src/index.js'
config:
model: deepseek-v4-flash # If left blank, use ~/.codex/config.toml
sandbox: read-only # Optional: read-only | workspace-write | danger-full-access
cd: /path/to/workspace
Core Features¶
The plugin provides 4 native dsh tools, along with an accompanying SKILL.md skill file and Schemastery configuration.
- codex_status: View the current Codex CLI version, configuration path, and provider summary (provider configuration is masked and does not display keys).
- codex_exec: Execute a one-off task. A prompt, working directory (cd), and sandbox level are required.
- codex_review: Review repository code. Supports diff-based review or review of uncommitted changes (defaulting to a read-only nature).
- codex_resume: Resume a previous session. You can specify a
session idor uselast=trueto resume the most recent session.
Typical Usage¶
Below are several common operation examples:
# 1. Check status (does not consume model quota)
codex_status
# 2. Execute a one-off review task
codex_exec prompt="Review F:\8.15.6\src\app.ts and identify bugs and optimization points" cd="F:\8.15.6"
# 3. Review uncommitted changes in the current repository
codex_review uncommitted=true
# 4. Resume the last session and continue work
codex_resume last=true prompt="Continue completing the remaining part"
Configuration and Security¶
Configuration Options
The plugin supports configuring the following parameters via Schemastery:
- codexPath: The execution path for Codex CLI; defaults to codex.
- model: Default model override; if left blank, uses the configuration in ~/.codex/config.toml.
- sandbox: Default sandbox mode; defaults to read-only, with optional values workspace-write or danger-full-access.
- cd: Default working directory.
- ephemeral: Whether to enable ephemeral sessions; defaults to false (persistent).
- timeoutMs: Timeout for a single call; defaults to 600000 milliseconds (10 minutes).
Security Boundaries
- Read-only by default: The default sandbox is read-only, so Codex cannot modify files. To write files, sandbox permissions must be explicitly escalated.
- Privacy protection: The output of codex_status masks the provider configuration and never displays keys.
- Data transmission: Each execution of codex_exec or codex_review sends the prompt and repository content snippets to the configured provider (such as DeepSeek); be mindful of token consumption.
- Session files: Session files are written to ~/.codex/sessions by default. If leaving no trace is desired, consider setting ephemeral=true.
Summary¶
dsh-codex is an independent community project that seamlessly integrates the capabilities of the OpenAI Codex CLI into DeepSeek Harness’s tool system. Developers can use local configurations (DeepSeek) via the dsh tool to perform code reviews and tasks without requiring an OpenAI login.
Links¶
- GitHub: https://github.com/WODE25500/dsh-codex
- Plugin directory: https://www.skillhub.cn/plugins/WODE25500/dsh-codex