Introduction¶
DeepSeek Harness (DSH) establishes a trust boundary by decoupling credentials from Shell processes visible to the model. Placing the Wind CLI API key in an environment variable does not grant the Agent access, and copying the key directly into the workspace also breaks the boundary. This plugin injects credentials into a trusted host process and integrates Wind AIFin’s official services with DSH.
Plugin Scope¶
This is xiamu-ssr/dsh-wind-aifin, a plugin for DeepSeek Harness. It connects Wind AIFin’s official Streamable HTTP MCP domains and Alice workflows as native tools, while keeping the API key invisible to the model. The plugin belongs to the admin-security category and is licensed under MIT.
Core Features¶
The plugin provides the following capabilities:
- MCP tool integration: It connects to seven Wind Streamable HTTP MCP domains through DSH’s
@deepseek-ai/dsh-mcp-clientand exposes them as native tools:wind_stock,wind_fund,wind_index,wind_bond,wind_docs,wind_economic, andwind_analytics. - Alice workflow invocation: It provides the
wind_alicetool for invoking Wind Alice’s specialized financial analysis workflows, including fact-checking, company briefs, earnings reviews, and more. - Runtime Skills: It includes runtime Skills to route tool calls based on request type, so the Agent does not need to include an API key or Shell commands in prompts.
- Credential management: It declares
WIND_API_KEYas a DSH credential reference in the Settings namespace.
Installation and Enabling¶
Before installation, ensure that the DSH version is 0.1.0-rc.8 or newer.
dsh plugin --profile web add github:Xiamu-ssr/snowmountain-market
Restart the profile after installation. To install it to another profile, replace web in the command with the corresponding profile name.
Typical Usage¶
When used in an Agent, MCP tools follow DSH’s standard naming convention. For example, the stock data tool is invoked as mcp__wind_stock__. To call an Alice workflow, use the wind_alice tool and pass the prompt and optional workflow name.
The WIND_API_KEY credential must be configured through the Credentials page or provided in a trusted DSH startup environment. Do not write the key into workspace files, Skill files, or model-visible Shell configuration.
Applicable Scenarios and Notes¶
This plugin is suitable for scenarios that require secure access to Wind AIFin data and services in a DSH environment.
Before installation, check the source code and license. During use, note the following security and runtime mechanisms:
- Network restrictions: The adapter listens only on
127.0.0.1and uses unguessable per-process routes. It accepts only the seven fixed Wind endpoints and cannot be used as a generic authentication proxy. - Credential handling: Credentials are resolved per request and are not cached in files.
- No install scripts: The plugin has no install scripts and does not bundle or distribute Wind’s official Skills repository.
- File handling: Alice’s final text/data artifacts are returned to the Agent, but downloadable files generated by Alice are not automatically copied into the DSH workspace.
- Compliance: Before sending sensitive information, be sure to review Wind’s terms of service.