Introduction

One of the design principles of DeepSeek Harness (DSH) is to remove credential-bearing environment variables from model-visible Shell processes. This means that placing WIND_API_KEY in the host’s environment variables makes it inaccessible to the agent’s Bash tool, while copying it into the workspace would break DSH’s boundary isolation.

The xiamu-ssr/snowmountain-market plugin addresses this issue by resolving credentials in a trusted host process. It integrates Wind AIFin MCP tools and Alice workflows into DSH while ensuring the key is not exposed to the model or regular commands.

Plugin Overview

This plugin provides a credential-safe Wind AIFin MCP integration. It connects to Wind’s official streaming HTTP endpoints using DSH’s native MCP client and exposes Alice’s professional financial analysis workflows as tools.

  • Plugin repository: xiamu-ssr/snowmountain-market
  • Maintainer: Xiamu-ssr
  • License: MIT

Core Features

The plugin primarily includes the following three capabilities:

  1. 7 native MCP tools: Registers Wind’s seven official streaming HTTP MCP domains directly as native DSH tools, covering stocks, funds, indices, bonds, documents, macroeconomics, and cross-asset analysis.
  2. Alice workflow integration: Invokes Wind Alice’s professional financial analysis workflows (such as financial statement review, peer comparison, and credit analysis) through the wind_alice tool.
  3. Runtime Skills: Includes two built-in runtime Skills that guide the agent to route requests without requiring API keys or Shell commands to be written into prompts.

Installation and Configuration

The plugin requires DSH 0.1.0-rc.8 or later.

Installation

Run the following command in the target DSH profile (for example, web):

dsh plugin --profile web add github:Xiamu-ssr/snowmountain-market

The profile must be restarted after installation completes.

Configure Credentials

  1. Create an AIFin API Key in the Wind developer portal.
  2. Store this key on the DSH Credentials page as a reference to WIND_API_KEY.
  3. (Optional) Set WIND_API_KEY directly in a trusted DSH startup environment.

Security warning: Do not place WIND_API_KEY in workspace files, Skill files, prompts, the MCP header configuration in cordis.patch.yml, or model-visible Shell configuration files.

Tools and Usage

MCP Tool Naming

MCP tools follow DSH’s standard qualified naming convention, using the prefix mcp__wind_ followed by the specific domain:

Domain Tool prefix
Stocks mcp__wind_stock__
Funds and ETFs mcp__wind_fund__
Indices and industries mcp__wind_index__
Bonds mcp__wind_bond__
Announcements and news mcp__wind_docs__
Macro indicators mcp__wind_economic__
Cross-asset analysis mcp__wind_analytics__

Alice Tool Invocation

The wind_alice tool accepts a text prompt and an optional professional workflow name. For example, to invoke the company one-pager analysis workflow:

tool: wind_alice
prompt: 分析腾讯控股的最新财报情况
workflow: company_one_pager

Security and Notes

  • Network isolation: The credential adapter listens only on 127.0.0.1 and uses unpredictable in-process routing. It accepts only the seven fixed Wind endpoints and does not become a general-purpose authentication proxy.
  • Credential handling: Credentials are resolved only per request, are not cached in files, and are not returned to the model.
  • File handling: Downloadable files generated by Alice are not automatically copied to the DSH workspace; only final text or data is returned in the agent context.
  • Ecosystem note: The plugin has no installation script and does not bundle or distribute Wind’s official Skills repository. It is a community-maintained adapter, not an official Wind product.