Preface¶
DeepSeek Harness (DSH) uses a plugin-based architecture, aiming to achieve flexible feature integration through extension points. dsh-telegram is a client-side plugin that provides a Telegram channel for DSH. Users can converse with the Harness agent through a Telegram bot, and the agent responds using the same tools and session logs. This plugin addresses the need for remote access to the agent from a mobile phone, without keeping a shell open on the server, and without relying on existing middleware such as OpenClaw or Hermes.
Plugin Positioning¶
This is a plugin maintained by sazzadurrahmaan. Its core design philosophy treats “remote shell access through a chat application” as a first-class feature, not a peripheral detail.
Core Features¶
- Default-deny allowlist mechanism: This is the first line of defense. The plugin validates access using numeric Telegram user IDs. An empty allowlist means all access is denied. Only allowed user IDs can send messages to the agent.
- In-chat approval for destructive tools: For dangerous tools such as
bash,pwsh,terminal,write,edit, andstr_replace_editor, atools/pre-executegate is triggered before execution. The system shows “Allow/Deny” buttons in the chat interface. Only the originating chat window can respond, using a random UUID as the callback token. Requests that do not receive a response before timeout are denied. - Session isolation: Each chat corresponds to an independent agent instance. The
/newcommand destroys the current agent and starts a new session. There are no shared sessions between users. - No additional dependencies: The plugin does not depend on extra network frameworks or bot libraries. It calls the Bot API directly using
fetchand receives updates through long polling. The entire client-side code is contained in a single small file.
Installation and Configuration¶
- Install the plugin:
Use the following command to add the plugin under thewebprofile:
dsh plugin --profile web add github:sazzadurrahmaan/dsh-telegram
- Configure environment variables:
After installation, you need to set the Telegram Bot Token and the allowed user IDs.
export DSH_TELEGRAM_TOKEN='123456:ABC...' # 从 @BotFather 获取
export DSH_TELEGRAM_ALLOWED_USER_IDS='123456789' # 你的数字用户 ID
- Configuration file approach:
You can also configure it directly in~/.dsh/cordis.patch.yml:
plugins:
dsh-telegram:
token: ${DSH_TELEGRAM_TOKEN}
allowedUserIds: [123456789]
cwd: /home/dsh/workspace
Common Commands¶
In a Telegram chat, you can use the following commands:
/start: Display the command list./new: Destroy the current chat’s agent and start a brand-new session./stop: Cancel the currently running turn./status: View the session ID and agent status./whoami: Get your numeric Telegram user ID. This is the only command that responds without allowlist authorization and is used to obtain the ID required for configuration.
Security and Usage Considerations¶
- The allowlist is the only line of defense: Anyone can find your bot by Telegram username and try to send messages. Ensure
allowedUserIdsis accurate, and avoid setting this value from untrusted sources. - Destructive tool configuration: If you set the configuration item
allowDestructiveToolstotrue, all approval prompts are removed. In that case, allowed users can directly run any command Harness can execute from their phone, with no secondary confirmation. - Group limitations: The plugin does not support group chats. Adding the bot to a group causes messages from all members to reach it. Although only allowlisted users will be responded to, this broadens the attack surface. Use private chats.
- Bot token permissions: A bot token grants full control of the bot. Store the token in environment variables, and do not commit it to code repositories or configuration files.
- Developer preview: The current Harness version is
0.1.x, which is in developer preview and is subject to breaking changes. It is recommended to pin the Harness version before use.
Conclusion¶
dsh-telegram provides the ability to securely access DeepSeek Harness agents on mobile. Through a strict default-deny policy and interactive approval flows, it balances convenience and security. For developers who need to use Harness in mobile scenarios, it is a practical tool.