Introduction

The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When using OpenAI Codex CLI for code analysis or task execution, developers typically need to log in with an OpenAI account. dsh-codex addresses this pain point by integrating Codex CLI into DSH’s tool and skill system, allowing developers to run Codex with local configurations (such as DeepSeek) without requiring an OpenAI login. Through the dsh tool, developers can natively execute one-off tasks, repository reviews, and session resumptions.

Prerequisites

Before using this plugin, the following conditions must be met:
1. DeepSeek Harness (dsh) is installed.
2. Codex CLI is installed globally:

    npm install -g @openai/codex
    codex --version
  1. The Codex configuration file ~/.codex/config.toml has the provider configured (such as model_provider, base_url, and model for DeepSeek), or you are logged in via codex login.

Installation and Enablement

The plugin is integrated into DSH through a cordis.patch.yml adaptation layer.

Option 1: Temporary local patch loading (for development)
Run the following command in the root directory of the DSH repository to overlay and load the plugin:

pnpm dsh web --patch ./dsh-codex/cordis.patch.yml

After startup, ask the agent to use the tools.

Option 2: Add as a bundle to the profile
Add the following content to the DSH profile configuration file:

- insert:
    - id: codex
      name: './src/index.js'
      config:
        model: deepseek-v4-flash   # If left blank, use ~/.codex/config.toml
        sandbox: read-only         # Optional: read-only | workspace-write | danger-full-access
        cd: /path/to/workspace

Core Features

The plugin provides 4 native dsh tools, along with an accompanying SKILL.md skill file and Schemastery configuration.

  1. codex_status: View the current Codex CLI version, configuration path, and provider summary (provider configuration is masked and does not display keys).
  2. codex_exec: Execute a one-off task. A prompt, working directory (cd), and sandbox level are required.
  3. codex_review: Review repository code. Supports diff-based review or review of uncommitted changes (defaulting to a read-only nature).
  4. codex_resume: Resume a previous session. You can specify a session id or use last=true to resume the most recent session.

Typical Usage

Below are several common operation examples:

# 1. Check status (does not consume model quota)
codex_status

# 2. Execute a one-off review task
codex_exec prompt="Review F:\8.15.6\src\app.ts and identify bugs and optimization points" cd="F:\8.15.6"

# 3. Review uncommitted changes in the current repository
codex_review uncommitted=true

# 4. Resume the last session and continue work
codex_resume last=true prompt="Continue completing the remaining part"

Configuration and Security

Configuration Options
The plugin supports configuring the following parameters via Schemastery:
- codexPath: The execution path for Codex CLI; defaults to codex.
- model: Default model override; if left blank, uses the configuration in ~/.codex/config.toml.
- sandbox: Default sandbox mode; defaults to read-only, with optional values workspace-write or danger-full-access.
- cd: Default working directory.
- ephemeral: Whether to enable ephemeral sessions; defaults to false (persistent).
- timeoutMs: Timeout for a single call; defaults to 600000 milliseconds (10 minutes).

Security Boundaries
- Read-only by default: The default sandbox is read-only, so Codex cannot modify files. To write files, sandbox permissions must be explicitly escalated.
- Privacy protection: The output of codex_status masks the provider configuration and never displays keys.
- Data transmission: Each execution of codex_exec or codex_review sends the prompt and repository content snippets to the configured provider (such as DeepSeek); be mindful of token consumption.
- Session files: Session files are written to ~/.codex/sessions by default. If leaving no trace is desired, consider setting ephemeral=true.

Summary

dsh-codex is an independent community project that seamlessly integrates the capabilities of the OpenAI Codex CLI into DeepSeek Harness’s tool system. Developers can use local configurations (DeepSeek) via the dsh tool to perform code reviews and tasks without requiring an OpenAI login.

Links

  • GitHub: https://github.com/WODE25500/dsh-codex
  • Plugin directory: https://www.skillhub.cn/plugins/WODE25500/dsh-codex