Introduction¶
One of the design principles of DeepSeek Harness (DSH) is to remove credential-bearing environment variables from model-visible Shell processes. This means that placing WIND_API_KEY in the host’s environment variables makes it inaccessible to the agent’s Bash tool, while copying it into the workspace would break DSH’s boundary isolation.
The xiamu-ssr/snowmountain-market plugin addresses this issue by resolving credentials in a trusted host process. It integrates Wind AIFin MCP tools and Alice workflows into DSH while ensuring the key is not exposed to the model or regular commands.
Plugin Overview¶
This plugin provides a credential-safe Wind AIFin MCP integration. It connects to Wind’s official streaming HTTP endpoints using DSH’s native MCP client and exposes Alice’s professional financial analysis workflows as tools.
- Plugin repository:
xiamu-ssr/snowmountain-market - Maintainer: Xiamu-ssr
- License: MIT
Core Features¶
The plugin primarily includes the following three capabilities:
- 7 native MCP tools: Registers Wind’s seven official streaming HTTP MCP domains directly as native DSH tools, covering stocks, funds, indices, bonds, documents, macroeconomics, and cross-asset analysis.
- Alice workflow integration: Invokes Wind Alice’s professional financial analysis workflows (such as financial statement review, peer comparison, and credit analysis) through the
wind_alicetool. - Runtime Skills: Includes two built-in runtime Skills that guide the agent to route requests without requiring API keys or Shell commands to be written into prompts.
Installation and Configuration¶
The plugin requires DSH 0.1.0-rc.8 or later.
Installation¶
Run the following command in the target DSH profile (for example, web):
dsh plugin --profile web add github:Xiamu-ssr/snowmountain-market
The profile must be restarted after installation completes.
Configure Credentials¶
- Create an AIFin API Key in the Wind developer portal.
- Store this key on the DSH Credentials page as a reference to
WIND_API_KEY. - (Optional) Set
WIND_API_KEYdirectly in a trusted DSH startup environment.
Security warning: Do not place WIND_API_KEY in workspace files, Skill files, prompts, the MCP header configuration in cordis.patch.yml, or model-visible Shell configuration files.
Tools and Usage¶
MCP Tool Naming¶
MCP tools follow DSH’s standard qualified naming convention, using the prefix mcp__wind_ followed by the specific domain:
| Domain | Tool prefix |
|---|---|
| Stocks | mcp__wind_stock__ |
| Funds and ETFs | mcp__wind_fund__ |
| Indices and industries | mcp__wind_index__ |
| Bonds | mcp__wind_bond__ |
| Announcements and news | mcp__wind_docs__ |
| Macro indicators | mcp__wind_economic__ |
| Cross-asset analysis | mcp__wind_analytics__ |
Alice Tool Invocation¶
The wind_alice tool accepts a text prompt and an optional professional workflow name. For example, to invoke the company one-pager analysis workflow:
tool: wind_alice
prompt: 分析腾讯控股的最新财报情况
workflow: company_one_pager
Security and Notes¶
- Network isolation: The credential adapter listens only on
127.0.0.1and uses unpredictable in-process routing. It accepts only the seven fixed Wind endpoints and does not become a general-purpose authentication proxy. - Credential handling: Credentials are resolved only per request, are not cached in files, and are not returned to the model.
- File handling: Downloadable files generated by Alice are not automatically copied to the DSH workspace; only final text or data is returned in the agent context.
- Ecosystem note: The plugin has no installation script and does not bundle or distribute Wind’s official Skills repository. It is a community-maintained adapter, not an official Wind product.