Skip to main content

DSH-taskboard

84Stars6Forks1Issues0Watchers

Adds a native local task board to DeepSeek Harness with SQLite storage for projects, tasks, claims, and automation. Requires manual sign-off for done status. Web profile only.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
Apache-2.0
Branch
main
agentcordisdeepseek-harnessdshdsh-plugintask-managementtaskboard

Install

cmdweb profile
$ dsh plugin --profile web add @shengsheng/dsh-taskboard

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin shengsheng90/DSH-taskboard for me: review the repository at https://github.com/shengsheng90/DSH-taskboard first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

At a Glance

DSH-taskboard is the native local task board plugin for DeepSeek Harness: managing "projects / tasks / comments / claims / automation" in local SQLite, providing a native overlay page at the bottom of the Harness Web Client sidebar, and registering a set of "up to in_review only" work tools for Agents—sensitive actions like acceptance and status changes can only be performed by humans.

Core Capabilities

  • 7-stage status lifecycle: backlog → todo → in_progress → in_review → done, plus blocked, canceled (src/domain/types.ts:6)
  • Sidebar bottom adds "Task Board" entry + native overlay page, covering 6 views: Dashboard, Kanban, List, Labels, Gantt, Workflow (src/client/index.tsx:527-545)
  • 8 Agent in-process tools (taskboard_list / _get / _claim / _comment / _submit_review / _block / _release_claim / _relate), excluding acceptance and general status changes (src/tool/index.ts:32-150)
  • Human-only actions: approve, accept, return, archive, restore, cancel, reopen, force takeover, permanent delete—these can only be triggered via UI or CLI (src/sqlite/provider.ts:344/556/658/729/753/758/792/797/811)
  • Project-level automation: intervals, Agent presets, model routing, concurrent worker limits, quota policies. Host scheduler claims eligible todo and stops at in_review (src/automation/index.ts, README.zh.md:315-317)
  • Optimistic concurrency control: all non-create writes require exact --version match, conflicts throw TASK_STALE_VERSION (src/sqlite/provider.ts:695)

Technical Implementation

  • Language: TypeScript (ESM; React 18 for native overlay)
  • Key Dependencies: node:sqlite (built-in, holds task/claim/activity/attachment metadata) + @deepseek-ai/cordis (host plugin host and config schema validation) + @deepseek-ai/dsh-tools (registers 8 Agent tools) + react ^18.2.0 (native overlay rendering)
  • Architecture Pattern: Dual-half native plugin. Host half injects a plugin row named taskboard via cordis.patch.yml, apply() bootstraps TaskboardService, registers Agent tools, and takes over Harness native Agent scheduling via ctx.inject(['agents','goals','workspaceRegistry','agentPresets','agentDefaultModel'], ...), mounts automation coordinator in effect(), stops everything uniformly on process exit. Client half injects client-runtime / client-locale / client-ui-conversation into web client via package.json#dsh.client.inject, connected to host service via Typert RPC through generated/typert.remote-client.js; orphan claim reconciliation at startup is best-effort and doesn't block scheduler startup (src/index.ts:65-90, package.json:80-94, cordis.patch.yml:1-17)
  • Entry Points: src/index.ts (host plugin entry + config schema), src/cli.ts (JSON CLI), src/client/index.tsx (native overlay entry), src/service/index.ts (business orchestration + RPC routing), src/sqlite/provider.ts (task/claim/activity SQLite persistence)

Use Cases

Scenarios where you need to separate "development tasks" from "conversations" in DSH, let Agents automatically advance tasks, but require human sign-off for completion. For example, in an iteration with N todos, let Agents claim in specified Workspace/branch/worktree one by one, write code, submit for review, and finally have humans decide done or return—this closed loop is handled by this plugin, while Harness itself handles Agent execution, Goals, Sessions, permissions, and conversation history.

Prerequisites and Compatibility

DependencyMinimum VersionDescription
DeepSeek Harness>=0.1.0-rc.5peerDependencies locks @deepseek-ai/cordis ^4.0.1 and all @deepseek-ai/dsh-* ^0.1.0-rc.5 (including cordis / agent / agent-presets / goal / workspace / tools / typert-protocol, etc.), README states "Compatible Host: 0.1.0-rc.5" (package.json:95-117, README.md:12, README.zh.md:12/40)
Host profilewebcordis.patch.yml writes to web profile, package.json#dsh.client.platform = "web", headless / other profiles not in declared scope (cordis.patch.yml:1-17, package.json:84-94)
Node.js^22.19.0 or >=24.0.0engines.node explicitly declares; uses built-in node:sqlite (available in Node 22.5+, works with 22.19 / 24), README recommends 24 (package.json:8-10, README.zh.md:34-49)
PlatformmacOS / Windows / LinuxNo os / cpu fields declared, only depends on Node built-in node:sqlite and Node fs/path, cross-platform (entire package.json)
Native modulenode:sqliteDatabase layer directly uses Node built-in node:sqlite (DatabaseSync), no third-party native modules needed (src/sqlite/schema.ts:3, src/sqlite/provider.ts:6)
Browser half injection@deepseek-ai/dsh-{api-remotes, client-connection, client-locale, client-runtime, client-ui-conversation} ^0.1.0-rc.5package.json#dsh.client.inject lists 5 client packages needed for native overlay (package.json:84-92)
Other runtime dependencieszod ^4.4.3Domain layer type validation; no third-party packages outside official SDKs (package.json:125-127)

Installation

dsh plugin --profile web add github:shengsheng90/DSH-taskboard

Note: lib/ is not in git, git installation won't include compiled artifacts. Source installation requires pnpm install && pnpm build && pnpm pack in the repo first, then dsh plugin --profile web add -w /absolute/path/to/shengsheng-dsh-taskboard-<version>.tgz. After installation, Harness process must be restarted; polling GET / includes @shengsheng/dsh-taskboard and GET /plugins/@shengsheng/dsh-taskboard/client.js returns 200 to be considered activated (README.zh.md:51-202, README.zh.md:16).

Configuration Options

Configuration is parsed by Host, browser cannot directly select paths. Can be overridden at profile composition layer or specified via environment variables.

ConfigTypeDescriptionDefault
databasePathstringSQLite database file path.dsh/taskboard.sqlite (overridable with DSH_TASKBOARD_DATABASE)
attachmentRootstringRoot directory for attachment files.dsh/taskboard-attachments (overridable with DSH_TASKBOARD_ATTACHMENTS)
pageSizenumberPage size for taskboard_list, results include match total100
snapshotTaskLimitnumberMax tasks carried in a single native page snapshot, page prompts when truncated1000
maxAttachmentBytesnumberSingle attachment byte limit26214400 (25 MiB)
maxTaskAttachmentBytesnumberAll attachments combined byte limit per task104857600 (100 MiB)
allowedAttachmentTypesstring[]Allowed MIME type whitelist for uploadsjson / octet-stream / pdf / zip / gif / jpeg / png / webp / markdown / text
minAutomationIntervalMsnumberMinimum interval allowed for project-level automation30000 (30 seconds)
maxProjectWorkersnumberConcurrent claim Agents per project2
maxGlobalWorkersnumberGlobal concurrent claim Agents4
allowSharedWorktreesbooleanWhether multiple Agents can share the same worktreefalse
clientRefreshIntervalMsnumberBrowser overlay snapshot fallback polling interval15000 (15 seconds)
maxChangeWaitersnumberLong polling waiter limit128
maxChangeWatchMsnumberSingle long polling timeout30000 (30 seconds)
defaultAgentPresetstringDefault Agent preset name for automationstandard
defaultModelRoutestringDefault model route for automation (schema required, no default)None (must be supplied at profile layer)

Source: src/index.ts:42-62, cordis.patch.yml:4-17.

FAQ

Q: Can Agents directly change a task to done?

A: No. Agents can only submit their held in_progress to in_review; done can only be written by humans via UI or CLI task accept action (requireHuman is enforced on multiple write paths in the provider layer). Goal completion also doesn't automatically accept tasks.

Q: What if Agent doesn't finish after claiming? Will the claim get stuck?

A: Claims won't be silently taken away. Agents can taskboard_release_claim before submitting; humans can use "force takeover" to release the claim and push the task back to todo, avoiding orphans occupying the entire worker. Returning to todo releases the claim; directly going back to in_progress requires establishing a new explicit claim atomically (README.zh.md:252-259, src/sqlite/provider.ts:790-794).

Q: How to stop tasks running in automation?

A: Simply turn off the automation rules for the corresponding project on the native task board page. Host scheduler will no longer dispatch new claims; already running Agent Sessions are managed normally by Harness, rule disabling won't force-kill them. When quota is exhausted, scheduler only pauses new claims, won't cancel running work (README.zh.md:315-317).

Q: How to back up data?

A: Take both the SQLite (online also needs WAL) and the entire .dsh/taskboard-attachments/ directory; to do offline consistent backup, stop Harness first. Storage panel and dsh-taskboard storage status output SQLite integrity, revision, activity, attachment cleanup queue, and orphan claim diagnostics (README.zh.md:340-344).

Q: Changed status on native page but sidebar didn't refresh immediately?

A: Browser overlay mainly relies on Typert long polling for the next committed global revision; when there's no commit on host side, it falls back to snapshot polling at clientRefreshIntervalMs (default 15 seconds). This fallback doesn't require modifying Harness's Host event whitelist (README.zh.md:341-342).

Q: Installation reports declines no dsh.bundle?

A: Indicates the package's cordis.patch.yml wasn't bundled. Run pnpm build && pnpm pack in the repo first, then dsh plugin --profile web add -w <tarball>, don't manually modify installed copies (README.zh.md:130/217).

Q: Can Agents use tools to create tasks and directly enter todo status?

A: No. Create project, update project, delete project, and creating tasks with status='todo' all trigger requireHuman errors in the SQLite provider. Tasks created by Agent/automation can only land in backlog, require human "approve to start" in UI to enter todo (src/sqlite/provider.ts:344/375/394/416).

Q: Does activity log auto-cleanup? Can I see it in task details?

A: No auto-cleanup—source comments explicitly state "logs grow unbounded per task"; native task detail overlay also doesn't render activity streams, only shows SQLite integrity, revision count, attachment cleanup queue, and orphan claim diagnostics in storage health panel (src/service/index.ts:306, README.zh.md:340-344).

Learning Curve

Advanced — installation requires a chain of steps: pnpm build && pnpm pack + tarball install + host restart + browser polling activation (README lists all 8 steps complete); after installation, sidebar entry and native overlay are visual operations, but letting Agents automatically claim tasks requires configuring workspace/branch/automation rules, rule tuning requires understanding state machines and optimistic locking.

Known Issues and Limitations

  • Only supports web profile: bundle patch and dsh.client.platform are hardcoded to web; under headless / other profiles, browser half doesn't load, and host half's service loses overlay path due to unreachable client (package.json:84-94, cordis.patch.yml:1-17).
  • Must restart Harness process after install/uninstall: plugin bundle registration and client-modules scanning only execute at startup; page refresh won't activate new mounts. Restart terminates the process hosting current sessions, in-progress Agent rounds will be interrupted (README.zh.md:153-179).
  • Database schema version hard constraint: current version is 4. If disk's user_version > 4 or negative, initialization throws STORAGE_SCHEMA_UNSUPPORTED and closes database; lower versions auto-migrate V1→V4. Manually swapping higher version database refuses to start (src/sqlite/schema.ts:36-47).
  • Agents cannot directly create projects or set tasks to todo: create project / update project / delete project / creating task with status='todo' all trigger requireHuman, CLI and human operations can bypass, Agent tool paths don't work (src/sqlite/provider.ts:344/375/394/416).
  • Activity log grows unbounded: source comments explicitly state "native page doesn't render activity streams, logs grow infinitely per task"; taskboard_* tools also don't proactively trim (src/service/index.ts:306).
  • Browser-side snapshot fallback + long polling has limits: maxChangeWaiters=128 / maxChangeWatchMs=30 seconds, falls back to clientRefreshIntervalMs (15 seconds) polling when limits reached; state delays may be noticeable during peak times (src/index.ts:57-59, cordis.patch.yml:14-16).
  • Default model route has no value: defaultModelRoute in schema is z.string() with no default, must be explicitly supplied at profile composition layer, otherwise startup config validation fails (src/index.ts:61).
  • Default database path and attachment root are resolved by Host at startup, browser overlay cannot temporarily change; to isolate multiple profiles, need to start host under different DSH_TASKBOARD_DATABASE / DSH_TASKBOARD_ATTACHMENTS environment variables (README.zh.md:319-321).
  • Offline build depends on lib/typert.* artifacts: build script copies official Typert artifacts bundled with the repo from scripts/copy-typert-artifacts.mjs; tree-out build doesn't depend on adjacent Harness checkout, but generated Remote files go to generated/, after cleanup must re-run pnpm build (README.zh.md:355-358).

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/shengsheng90/DSH-taskboard)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory