Skip to main content

Deepseek-Harness-Desktop/vendor/deepseek-harness/packages/bundle/base

127Stars9Forks0Issues0Watchers

dsh shared core profile bundle: inserts basic plugin rows including model adapter, tool, persistence, sandbox, and telemetry at the empty profile root, serving as the first layer for all profiles

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki

ⓘ This plugin is a sub-package of the ChisaAlter/Deepseek-Harness-Desktop monorepo — stars and activity count the whole repository.

Language
JavaScript
License
MIT
Branch
main
deepseekdeepseek-harnessdsh-plugin

Install

cmdweb profile
$ dsh plugin --profile web add @deepseek-ai/dsh-base

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin ChisaAlter/Deepseek-Harness-Desktop/vendor/deepseek-harness/packages/bundle/base for me: review the repository at https://github.com/ChisaAlter/Deepseek-Harness-Desktop first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

This documentation corresponds to the subpath vendor/deepseek-harness/packages/bundle/base in the vendor repository and is the content source for the Plugin Encyclopedia module on the landing page /plugins/{owner}/{repo}.

One-Line Summary

@deepseek-ai/dsh-base is DSH's shared core profile bundle: inserting approximately 75 base plugins at once on an empty profile root, covering all profile-shared components including model adaptation, tools, persistence, sandbox strategies, settings/credentials, and telemetry, serving as the first layer loaded by any profile.

Core Capabilities

  • Registers core services on empty profile root including model adaptation, Agent sessions, Typert type registration and RPC gateway, default model selection
  • Enables tool directory: file I/O, code editing, sub-agent invocation, plan mode, Todo, goals, Web search and other model-facing tools
  • Mounts localized data plane: JSONL session persistence, SQLite session indexing (in-memory by default, on-demand), local attachments, credentials and settings files
  • Installs default sandbox and permission policies: file effect strategy, bash/pwsh shell stack (auto-selects based on platform), approval and permission presets
  • Registers host-level sub-agent and workflow capabilities: in-process spawn/fork sub-agents, worker-thread workflow execution
  • Configures basic telemetry and session checkpoints: OTLP log upload disabled by default, checkpoint persistence per model request

Technical Implementation

  • Language: TypeScript(ESM,src/index.ts only has export {}, no runtime API; code inside package only used for loading invariant companion)
  • Key Dependencies: @deepseek-ai/cordis(peer, host runtime)、@deepseek-ai/dsh-llm(model capability surface)、@deepseek-ai/dsh-session(session core)、@deepseek-ai/dsh-sandbox-local(sandbox); full list in dependencies (~81 workspace packages)
  • Architecture Pattern: Composition package (profile bundle) — package's cordis.patch.yml exposes to profile composer via manifest field dsh.bundle.patch, composer reads and inserts line by line; instead of registering a Service class, it inserts a patch list
  • Entry Files: src/index.ts(no runtime export)+ src/invariant.ts(empty implementation, only registers package name to satisfy invariant companion rules)+ actual payload cordis.patch.yml

Use Cases

Any user running DSH agent on their machine will encounter this bundle as the first step: it serves as the common foundation for all profiles like --profile web, --profile headless. When users want out-of-the-box DeepSeek model invocation, local session archiving, automatic bash/pwsh selection by platform, default file sandbox protection in DSH without repeatedly assembling these basic components for each profile, adding this to the profile suffices.

Prerequisites & Compatibility

DependencyMin VersionDescription
DSH0.1.0-rc.6+Same-name workspace packages @deepseek-ai/cordis and @deepseek-ai/dsh-invariants must be available in host; released in same cycle as upstream 0.1.0-rc.7
Node>=22.19.0From upstream monorepo engines.node: ^22.19.0 || >=24.0.0
PlatformmacOS / Windows / LinuxSame patch file works cross-platform; shell stack auto-enables bash (POSIX) or pwsh (Windows) based on process.platform, no platform-specific patch branches
Native ModulesNoneThis package itself has no native dependencies; underlying @deepseek-ai/dsh-sandbox-local mounts @deepseek-ai/dsh-sandbox-windows-acl on Windows, this is composition behavior not declared by this package

Installation

dsh plugin --profile web add github:ChisaAlter/Deepseek-Harness-Desktop/vendor/deepseek-harness/packages/bundle/base

Configuration Options

This bundle does not expose independent config to users. It writes default config for approximately 75 downstream plugins in cordis.patch.yml — these are static declarations read by the profile composer, not directly overridable via dsh CLI or settings files. To modify values on these lines, replace the entire line by id in a higher-level profile cordis.patch.yml or bundle layer. Below lists key defaults set in the patch (for reference only, not user config entry points):

Default LineDefault ValueMeaning (Plain Language)
agent-default-model.providerdeepseek-officialDefault model provider
agent-default-model.modeldeepseek-v4-flashDefault model ID
session-title.fallbackMaxWords5Session title fallback word limit
session-title-llm.timeoutMs60000LLM title generation timeout
session-persistence-jsonl.rootdshHomePath('sessions')JSONL session log root directory
session-query-sqlite.openAtneverFull-text search disabled by default; SQLite not opened, key-value exact reads and session lineage queries still available
session-telemetry-otel.modeprocess.env.DSH_TELEMETRY_MODE || 'DISABLED'Telemetry mode (FULL / FEEDBACK_ONLY / DISABLED)
sandbox-policy.modeprocess.env.DSH_PERMISSION_MODE ?? 'workspace-write'Default file sandbox mode (workspace-write only)
bash-sandbox.disabledprocess.platform === 'win32'bash sandbox disabled on Windows
pwsh-sandbox.disabledprocess.platform !== 'win32'pwsh sandbox disabled on non-Windows
approval.policyFollows DSH_PERMISSION_MODE, set to never when danger-full-access, otherwise askDefault user approval behavior
permission.presetsread-only / workspace-write / danger-full-accessPermission preset collection
tool-web.fetchfalseDisable model-driven Web fetching (keep search)
tool-web.searchTimeoutMs60000DeepSeek search timeout

FAQ

Q: Does installing this bundle automatically grant DeepSeek web search capability?

A: Yes. The patch registers DeepSeek official search route, reusing the same API key managed by the Models page, with a 60-second timeout; but does not provide Web fetching (tool-web.fetch disabled by default).

Q: Do I need to install anything extra to run this bundle on Windows?

A: No. The bash and pwsh shell stacks are mutually exclusively mounted in the same patch based on platform, with Windows automatically enabling pwsh sandbox and pwsh tools. If you prefer executing unsandboxed local PowerShell directly, you need to fully override in your own cordis.patch.yml: disable the pwsh line and re-enable the bash line (both register the same bash service, incomplete recipe will error on load).

Q: Does it upload telemetry data by default?

A: No upload. session-telemetry-otel defaults to mode: 'DISABLED'. To enable, set environment variable DSH_TELEMETRY_MODE=FULL or FEEDBACK_ONLY, endpoint can be overridden with DSH_TELEMETRY_OTLP_URL; non-empty DSH_TELEMETRY_DISABLED also force-disables in reverse.

Q: I want to change the default model, should I modify this bundle's patch or settings?

A: Modify settings. Write llm-deepseek: or llm-pi-ai: sections in $DSH_HOME/settings.yaml for hot reload without rebundling; the Web's Models page writes to this document.

Q: Will installing this also pull in Codex / Claude Code provider?

A: No. This bundle explicitly does not depend on or mount @deepseek-ai/dsh-subagent-codex and @deepseek-ai/dsh-subagent-claude-code; to use them, install the corresponding Profile package separately.

Q: What does the default "writable within workspace" sandbox actually control?

A: Writing is restricted to the current working directory and that session's temporary subdirectory; read-only mode grants no write permissions. On Windows, file effects are enforced through ACL-restricted token runners, with permission switcher and approval services operating on the same semantics.

Q: My profile has cordis.patch.yml, will it conflict with this bundle?

A: No conflict, but will replace the entire line's config by id. Bundle and your patch don't deep merge; if your override doesn't restate a field, the new value is determined by bundle defaults; when upgrading bundle version, custom overrides still hit the entire line by id.

Difficulty Level

Beginner — this is the essential foundation layer for profiles, usable without reading source code; customization only requires writing one line in cordis.patch.yml at a higher layer to replace defaults by id.

Known Issues & Limitations

  • Full-line config replacement: patch hits by same line id for entire line overwrite, no deep merge layer; profile overrides must restate all fields they want to keep on that line, otherwise they'll be overwritten by bundle defaults
  • Windows temp directory authorization is per-session private subdirectory: workspace-write limits writable scope to workspace + that session's own temp subdirectory (like <temp>\dsh-<hash>, restricted subprocess's TMP/TEMP is rewritten); read-only grants no temp directory write permissions

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/ChisaAlter/Deepseek-Harness-Desktop/vendor/deepseek-harness/packages/bundle/base)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory