The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When developing compliance-related skills, developers typically need to manually copy skill files into a local directory. The dsh-compliancehub plugin uses the standard ctx.skills mechanism to load skills directly from a remote JSON catalog, eliminating manual file operations.
Core Positioning¶
This plugin is a remote skill provider maintained by wwumit under the MIT license. It primarily addresses the problem of loading cross-border compliance skills remotely and provides standard list and get interfaces for DSH.
Installation¶
Install the plugin using npm:
npm install @wwumit/dsh-compliancehub
This installation command depends on peer dependencies: @deepseek-ai/cordis and @deepseek-ai/dsh-skill.
Enabling and Usage¶
Import and register the plugin in the DSH plugin entry file. The remote catalog URL must be specified:
import { Context } from '@deepseek-ai/cordis'
import * as skillHub from '@wwumit/dsh-compliancehub'
export function apply(ctx: Context) {
ctx.plugin(skillHub, {
catalogUrl: 'https://wwumit.github.io/skills-catalog/catalog-compliance.json'
})
}
After loading, the DSH model session directory will include the skills provided by this provider, and the model can invoke them through the built-in skill tool.
Core Capabilities¶
- Skill list (
list): Retrieves and validates the skill list from the catalog, then exposes it toctx.skills. - Skill retrieval (
get): FetchesSKILL.mdon demand from the repository associated with the skill. - Fault-tolerant semantics: If the catalog service is unavailable, the plugin retains the last valid state, preventing an empty list and ensuring service availability.
Skill Scope¶
The plugin provides 9 cross-border compliance skills, covering checks and safeguards in areas such as CCPA/GDPR/HIPAA/COPPA.
Known Limitations¶
- Body-only fetch:
get()currently only fetches the body ofSKILL.md, and does not yet cache scripts or other resource files. - Catalog caching:
list()re-fetches the catalog on every call; TTL caching is not yet implemented. - Auth: Private catalogs or signed URLs are not yet supported.