Introduction

The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin,” extending agent functionality by loading different capability modules. Cloudflare D1 is a SQLite-based serverless database accessed through a REST API, with no traditional TCP socket. The existing dsh-sql plugin cannot directly connect to D1. dsh-d1 was created specifically to solve this problem: it interacts directly with the database through D1’s HTTP API and provides a dedicated set of tools for the Harness Agent.

Plugin Introduction

dsh-d1 is a management toolkit for Cloudflare D1, categorized under “networking tools” and maintained by developer cndn. The plugin defaults to read-only mode, allowing the agent to query the D1 database safely. Write operations are permitted only after explicit configuration and approval. It has no runtime dependencies and can be used immediately after installation.

Core Features

The plugin registers six tools, covering the entire process from database discovery, read-only queries, and schema inspection to collecting statistics.

  • d1_list: Lists configured databases and probes the connectivity of each one.
  • d1_query: Executes read-only statements. Supports SELECT, VALUES, WITH, PRAGMA (introspection only), and EXPLAIN. Supports parameter binding, and result sets are limited by maxRows.
  • d1_exec: Executes write or DDL statements. It is denied by default. Writing must be explicitly enabled and interactive approval must be passed.
  • d1_schema: Lists user tables, or describes the column structure of a specified table via PRAGMA table_info.
  • d1_stats: Retrieves the number of tables, row counts per table (batched), and database size.
  • d1_health: Probes all databases and prints the security configuration and any configuration errors.

Installation and Configuration

The plugin is installed via npm. Since the DSH profile directory is typically the root of a pnpm workspace, use the -w flag during installation.

dsh plugin --profile web add -w dsh-d1

After installation, the plugin automatically inserts a configuration entry into the profile, but the API token is not written there. You need to override the configuration through cordis.patch.yml, specifying the Cloudflare accountId and the list of databases to connect to.

- id: d1
  name: 'dsh-d1'
  config:
    accountId: 'your-32-hex-cloudflare-account-id'
    databases:
      - name: prod
        databaseId: 00000000-0000-0000-0000-000000000000
      - name: analytics
        databaseId: 11111111-1111-1111-1111-111111111111
    maxRows: 1000
    readOnly: true
    writeApproval: true
    queryTimeoutMs: 60000
    execTimeoutMs: 120000

Security and Limitations

dsh-d1 uses a two-layer security defense.

First, API token environment isolation. Cloudflare API tokens must be provided via environment variables. The plugin reads them at runtime and never stores them in configuration files or logs. It supports a global token (CLOUDFLARE_API_TOKEN) or database-specific tokens (DSH_D1_TOKEN_<NAME>).

Second, default read-only and approval mechanism. By default, readOnly: true is set, and d1_exec is denied. Even if set to false, the default writeApproval: true routes all write operations to the DSH approval service and requires interactive confirmation.

In addition, d1_query uses lexical protection. After removing comments and string literals, only specific read-only statements are allowed. This prevents accidental writes without relying on keyword blacklists. Error messages are automatically sanitized to remove sensitive information such as tokens, request headers, and path values.