Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture. In local development or operations scenarios, connecting to servers usually requires maintaining separate SSH configuration files, entering passwords or keys manually, and making it difficult to directly feed command execution results back to an Agent. sycada/dsh-remote-ssh-tools is an SSH session management plugin for DSH. It solves security and efficiency issues in remote connections and operations by centrally managing connection profiles, providing Agent tool interfaces, and including a built-in interactive terminal.
Core Features¶
The plugin provides the following core capabilities:
- Connection profile management: Centrally maintain SSH profiles (name, group, host, port, user, authentication method, private key path, notes, etc.), supporting quick access from the UI or Agent calls.
- One-click Agent execution (
ssh_run): Supports executing a single remote command and retrieving the exit code, standard error output, and execution duration, with output truncation and timeout control. - Interactive terminal (
xterm): Provides an xterm terminal in the browser, supporting window resizing and session keep-alive across page refreshes; closing it ends the remote session. - File transfer (SFTP): Provides upload, download, and listing functions. Download has anti-overwrite protection enabled by default. Upload supports automatic creation of remote directories.
- Credential security: Passwords and private key passphrases are written only as reference names to the DSH credential center (
~/.dsh/.credentials.yaml); the profile JSON file contains no plaintext keys. Password values never enter the process command line. - Host key fingerprint caching: Supports
accept-newandstrictmodes, automatically recording fingerprints on first connection to prevent man-in-the-middle attacks. - Agent tool injection: Plug-and-play system prompts; the Agent can automatically detect and select available tools.
Installation and Enablement¶
Installation requires modifying the package.json file in the DSH profile and adding the dependency from GitHub.
- Open the
package.jsonfile in the DSH profile directory. - Add the GitHub repository link (version
v0.1.2) todependencies:
"dependencies": {
"dsh-remote-ssh-tools": "https://github.com/Sycada/dsh-remote-ssh-tools.git#v0.1.2"
},
"dsh": { "profile": { "bundles": [ "dsh-remote-ssh-tools" ] } }
- Run
pnpm installin the profile directory. - Restart DSH.
Note: A different package named
dsh-remote-sshexists on npm (Yan-Zero/dsh-remote-ssh, Apache-2.0). It is unrelated to this plugin (MIT license, maintained by Sycada). Confirm the repository address when installing.
Typical Usage¶
After installation and restart, relevant features can be invoked from the settings page or conversations:
- Agent command execution:
- Chat instruction: “Connect to the production server and run
df -h”. The Agent automatically selects a profile and executes the command. - Chat instruction: “Use the test profile to run
uptime”.
- Chat instruction: “Connect to the production server and run
- Open terminal:
- Click “Open terminal” on the settings page.
- Or have the Agent execute
ssh_session_open, then callsidebar_opento embed the terminal page in the sidebar.
- File transfer:
- Have the Agent execute
ssh_sftp_upload,ssh_sftp_download, orssh_sftp_list.
- Have the Agent execute
Agent Tool List¶
The plugin provides the following tools to the Agent (13 in total):
ssh_profile_list / add / update / remove: Profile creation, querying, updating, and deletion.ssh_profile_test: Connectivity and authentication testing.ssh_secret_status: Reports credential reference status (does not display values).ssh_run: Remote single-command execution.ssh_session_open / list / close: Interactive session management.ssh_sftp_list / upload / download: SFTP file operations.
System Requirements and Limitations¶
- Environment requirements: Requires DSH >= 0.1.1-rc.1 and Node.js >= 20.
- Agent forwarding: SSH Agent forwarding (
ssh -A) is not supported in the v0.1 interactive engine. - Networking features: Jump host connection and port forwarding are planned (expected in v0.2+).
Summary¶
By integrating SSH profile management with the DSH credential center, this plugin standardizes and secures remote operations. It is suitable for development and operations scenarios that require directly executing remote commands, managing multiple server connections, or transferring files within a conversational workflow. The complete documentation and source code are available in the GitHub repository.