Introduction

DeepSeek Harness (DSH) extends its capabilities through a plugin mechanism. When developing and debugging agents, it is often necessary to access log files on servers for troubleshooting. Directly granting agents unrestricted SSH access poses too high a risk. The dsh-ssh-logs plugin uses the built-in @deepseek-ai/dsh-mcp-client bridge in DeepSeek Harness to encapsulate SSH read capabilities into three MCP tools. It manages servers through fixed aliases, ensuring that agents can only read preconfigured log paths and cannot execute arbitrary commands or modify files.

Plugin Overview

  • Name: dsh-ssh-logs
  • Category: Network tool
  • Function: Allows reading authorized remote logs over SSH within a DeepSeek Harness session.
  • Maintainer: 452926826
  • License: MIT

Core Features

The plugin exposes three MCP tools in the DSH context for interacting with log servers:

  1. list_log_servers: Lists configured server aliases.
  2. read_log: Reads the content of log files.
  3. search_log: Searches for specific keywords in log files and returns context.

Server configuration is based on fixed aliases, and agents cannot specify arbitrary hosts or execute arbitrary commands. Each file read request must remain within an authorized log root directory (log root).

Installation and Activation

Run the following command in the DSH environment to install the plugin:

dsh plugin --profile web add github:452926826/dsh-ssh-logs

After installation, restart the dsh web process and refresh the page so that the MCP client registered by the Bundle takes effect. Servers and log paths must be configured in advance.

Typical Usage

After configuration, the above MCP tools can be invoked with natural language instructions:

  • Read the last 300 lines from the application log root in the production environment:
    > Read the last 300 lines of service/api.log from the app log root on production.

  • Search for a specific request ID in the staging environment logs and display context:
    > Search logs/backend.log under staging/app for request-id=abc123 and include 3 lines of context.

Notes

  • Preconfiguration Requirement: Servers and log root directories must be fully configured before installation. The plugin rejects relative paths, backslashes, and directory traversal using ...
  • Permissions and Security:
    • SSH connections are forced to use BatchMode=yes and StrictHostKeyChecking=yes, with an explicit known_hosts path specified.
    • The server side must use a dedicated read-only account.
    • Password prompts, sudo, arbitrary command execution, SFTP writes, file deletion, and file modification are not supported.
    • Output size defaults to 128 KiB, with a hard limit of 4 MiB. A single request can read at most 5,000 lines or return 1,000 search matches.

Conclusion

This plugin provides a secure log lookup mechanism for the DSH ecosystem, suitable for scenarios that require quickly reviewing server logs during conversations. The related directory and source code are available: