Introduction

In the DSH WSL development environment, agents often need to interact with GitHub, for example, checking the number of open PRs in a repository or the latest CI Actions run status. For security reasons, developers usually do not want personal access tokens (PATs) exposed in chat history or tool output.

The dsh-wsl-github plugin solves this problem by using the GitHub App mechanism. It allows the WSL agent to issue short-lived installation tokens in memory, call the GitHub API securely, and ensures that tool output never contains the private key, JWT, or token itself.

What Is This

This is a plugin designed for the DSH WSL environment and maintained by user 173787247. It is intended to provide lightweight GitHub interaction capabilities without introducing heavyweight integration libraries.

The plugin is part of the dsh-wsl-kit suite. It is recommended to use the KIT_SET environment variable (for example, github or full) to manage dependencies in a unified way. Its core value is “zero key leakage”: all sensitive information exists only briefly in memory, and tool output contains only business data (such as PR lists and Actions status).

Core Features

The plugin provides two core tools:

  • github_app_hint: checks whether GitHub App credentials or the environment file (~/.dsh/dsh-wsl-github.env) are configured in the current environment. It only indicates “existence” and does not output any key contents.
  • github_repo_status: retrieves information for the current repository (or a specified repo). The result includes up to 5 open PRs and the latest Actions run status.

Installation and Activation

Install it using the official DSH plugin command:

dsh plugin --profile web add github:173787247/dsh-wsl-github

After installation, ensure your DSH version meets the requirement (minimum ≥ 0.1.2).

Typical Usage

The standard workflow for using the plugin consists of three steps: register the App, load the environment, and call the tools.

  1. Register the GitHub App
    The first time you use it, generate and register the GitHub App locally. Run the following command:
    npm run register-app
This script uses the permission configuration in `github-app-manifest.json`, creates the App on GitHub, and writes the App ID and private key path to the `~/.dsh/` directory. It **does not** print sensitive information to the terminal.
  1. Load Environment Variables
    Before starting dsh web, load the environment variables into the current process:
    set -a
    source "$HOME/.dsh/dsh-wsl-github.env"
    set +a
    dsh web
In Windows PowerShell, you can use a similar pipeline command to inject the environment variables into the process.
  1. Call the Tools
    When chatting with the agent, send commands directly:
    • “Run github_app_hint.”
    • “Run github_repo_status for this repo.”
      The agent executes the corresponding tool and returns status information. If you need to open a returned link, use win_open_url together with the dsh-wsl-browser plugin.

Notes

  • Configuration Logic: In the plugin configuration file, if appId, privateKeyPath, or installationId is an empty string, the plugin automatically reads them from environment variables.
  • Dependency: To open links with win_open_url, ensure that the dsh-wsl-browser plugin is installed and enabled.
  • Version Requirement: The plugin requires a DSH version of 0.1.2 or higher.
  • Security: The tool is designed to output only business data; private keys and tokens never appear in logs or tool output.