The DeepSeek Harness (DSH) ecosystem supports plugin-based extensions. For scenarios that require performing operations on remote Linux servers, writing Shell scripts directly or hard-coding SSH commands can be cumbersome. dsh-ssh-plugin provides a solution: it adds remote execution capability to the model by using the system’s built-in SSH client and supports persistent connection management.

Plugin Overview

This plugin is maintained by Azurer0121 and is released under the MIT license. It resolves pain points in agent-to-remote-server interaction by registering two model tools, ssh_exec and ssh_connections: the model can execute remote commands directly without manual intervention.

Core Functionality

The plugin includes the following capabilities:

  1. ssh_exec tool: Allows the model to execute Bash commands on a remote Linux server.
  2. ssh_connections tool: Manages persistent SSH connection profiles. Supports saving connections, binding them to workspaces, and listing available hosts.
  3. Key-based authentication: Supports key-based authentication only (BatchMode=yes); it does not prompt for passwords or private key phrases, ensuring fast failure instead of hanging.
  4. SSH config integration: Automatically recognizes and uses host aliases from the local ~/.ssh/config file, without requiring manual saving.
  5. Host and browser support: Registers a settings namespace on the host side and provides a settings card interface on the browser side.
  6. Graceful degradation: If services such as settings or workspaceRegistry are missing, the plugin degrades gracefully without affecting basic functionality.

Installation and Enablement

Install from npm, a GitHub repository, or a local directory. If using a local checkout, build it first.

# 从 npm 安装
dsh plugin --profile <name> add dsh-ssh-plugin

# 从 GitHub 安装
dsh plugin --profile <name> add github:Azurer0121/dsh-ssh-plugin

# 从本地目录安装(需先构建)
dsh plugin --profile <name> add ./dsh-ssh-plugin

Build command must be run before local installation:

cd dsh-ssh-plugin
pnpm install && pnpm bundle

After installation, start Harness with dsh --profile <name>.

Typical Usage

ssh_exec

The model can use the ssh_exec tool, supporting both natural-language instructions and explicit parameter invocations.

Explicit parameters:

Parameter Required Description
host Yes Remote host, in the form [user@]host, or an alias from ~/.ssh/config.
command Yes Bash command to execute remotely.
port No SSH port. Defaults to 22.
key_path No Absolute path to the private key. If omitted, the default path or ssh-agent is used.
timeout_ms No Foreground timeout (milliseconds). Defaults to 30000.
connection No Label of a saved connection, used to populate host/port/user/keyPath.

Natural language example:
The model can understand instructions such as “SSH to root@10.0.0.5 and show disk usage.”

ssh_connections

Used to manage persistent connections. The data is stored in Harness settings and remains available after restart.

  • save: Save a new connection profile (label, host, port, user, key path).
  • list: List saved connections, including hosts discovered from ~/.ssh/config (read-only).
  • delete: Delete the connection with the specified label (also unbinds related workspaces).
  • use: Bind the current workspace to a connection label. After binding, ssh_exec can omit the host parameter and use the default connection directly.

Use Cases and Considerations

  • Remote operations: Automate checking server status, log analysis, or file operations.
  • Environment isolation: Use workspace binding so different projects use different SSH configurations.

Notes:

  1. No password interaction: The plugin does not handle password or private key phrase prompts. If the key is not configured or permissions are insufficient, SSH fails immediately.
  2. Command delivery: Remote commands are sent to bash -s via SSH stdin, so shell escaping rules are the same as local Bash.
  3. Config discovery: Reading ~/.ssh/config is best-effort. A missing or unreadable configuration file does not cause the plugin to error; it only displays an empty list.
  4. Windows permission restrictions: On Windows, the session must be run with the danger-full-access sandbox policy; otherwise ssh.exe may fail to start due to insufficient permissions.
  5. Key security: The plugin stores only the key file path; the key contents never leave the disk.

Summary

dsh-ssh-plugin provides DeepSeek Harness with standardized SSH remote execution capabilities. By integrating with the local SSH client and configuration files, it lowers the barrier for agents to interact with remote infrastructure. Before using it, developers should ensure that target servers support key-based SSH access and configure the correct sandbox policy in Windows environments.

Related links:
* Plugin catalog: azurer0121/dsh-ssh-plugin
* GitHub repository: Azurer0121/dsh-ssh-plugin