In the DeepSeek Harness (DSH) environment, agents typically tend to use shell commands (such as curl, wget, or PowerShell’s Invoke-WebRequest) to download files. These commands are typically single-connection downloads that are slower and lack visibility. Even if agents use a script named aria2-dl.js, if the script does not call the aria2 engine internally, download speed may be only a fraction of the speed of a single connection (in practice, for a 4.76 GB file, node download.cjs achieved only 0.13 MB/s, while aria2 could reach 11.78 MB/s). dsh-download-guard changes this rule from a prompt suggestion to runtime enforcement: it intercepts shell download commands before tool execution and returns the correct aria2 command.

Overview

This plugin makes a decision before a tool actually runs by listening to the cordis tools/pre-execute hook (waterfall mode).

Core features include:
1. Intercepting common shell download commands (such as curl -o, wget <url>, Invoke-WebRequest ... -OutFile).
2. Automatically returning an aria2 alternative command with the correct parameters.
3. Distributing the aria2-dl.cjs forwarder script with the package, supporting connections to the aria2-next engine over JSON-RPC.

Installation

Run the following command in the terminal:

cd ~/.dsh && dsh plugin --profile <your-profile> add "dsh-download-guard@github:BeiWay1145/dsh-download-guard"

After installation, restart DSH to apply the changes.

Usage Examples

When an agent attempts to download files using shell commands, the plugin intercepts it and suggests using the aria2 command:

curl -o F / wget <url> / Invoke-WebRequest ... -OutFile F

The plugin returns a prompt similar to the following, suggesting the use of the forwarder script provided with the package:

node "$env:USERPROFILE\.dsh\skills\aria2-download\scripts\aria2-dl.js" "<URL>" --out=<filename>

The actual invocation is as follows:

node scripts/aria2-dl.cjs <url> --out=<文件名> [--dir=<目录>] [--no-wait]
node scripts/aria2-dl.cjs --status <gid>

Limitations and Notes

This plugin cannot cover every scenario. Before using it, be aware of the following boundaries:

  1. Downloads inside commands cannot be intercepted: for example, in python script.py, the hook can only see python script.py and cannot detect internal urllib requests.
  2. Non-DSH processes are not affected: executing curl -o in a terminal opened outside DSH will not be intercepted.
  3. Host environment dependency: the host must provide the tools/pre-execute hook.
  4. Engine dependency: it depends on a locally running aria2-next engine, and errors are reported if it is not started.

Summary

dsh-download-guard addresses the issue where agents may bypass the aria2 engine when downloading large files. By enforcing interception of shell commands, it ensures that all downloads go through the local aria2 engine, providing multi-threaded downloads, resumability, and visibility.

  • GitHub: https://github.com/BeiWay1145/dsh-download-guard