Package all dsh basic capabilities into profile combo bundles as the first-layer patch for each profile, hosting 60+ core entries including models, tools, sandbox, permissions, and session persistence.
- Language
- TypeScript
- License
- MIT
- Branch
- master
Install
$ dsh plugin --profile web add @deepseek-ai/dsh-baseRun the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial
Install via your agent
Install the DeepSeek Harness plugin whitelonng/dshcode/packages/bundle/base for me: review the repository at https://github.com/whitelonng/dshcode first, then run the install command and verify the plugin loads successfully.
Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.
Entry package name:
@deepseek-ai/dsh-base, landing page ID:whitelonng/dshcode/packages/bundle/base. Referred to below as the "Base Bundle".
One-Line Description
It's dsh's factory profile "first layer patch" — injecting 60+ base plugins including model, Agent, tools, sandbox, permissions, session persistence, telemetry, subagent, etc. into the root of an empty profile, equivalent to a browser's factory default extensions set; other mode bundles and user configurations are stacked or line-overridden on top of it.
Core Capabilities
- Introduces LLM adapters (DeepSeek native + pi-ai multi-provider bridge) and default model selection (agent-default-model defaults to deepseek-official / deepseek-v4-flash)
- Mounts Agent main loop (agent / agent-loop / agent-default-model / agent-instructions / system-prompt), establishing the task dispatch framework
- Exposes foundational tools: bash/pwsh (one or the other based on platform), fs, fs-search, str-replace-editor, web_search, todo, subagent, subagent-fork, subagent-control, subagent-report, workflow, goal, skill, ralph, jobs, etc.
- Assembles persistence and session management: JSONL session logs (written to
$DSH_HOME/sessions), SQLite session index (in-memory mode by default, content search disabled), in-memory attachment byte store, checkpoint strategies and projections - Enables file sandbox, permission policies and approval switches, defaults to workspace-write + ask, provides three preset levels: read-only / workspace-write / danger-full-access
- Provides local credentials and settings (
$DSH_HOME/.credentials.yaml+$DSH_HOME/settings.yaml, hot-reload) and OTLP telemetry mount (disabled by default)
Technical Implementation
- Language: TypeScript, but runtime is configuration-driven — this package's
src/index.tsonly exports{}, no runtime API, all behavior described bycordis.patch.yml - Key Dependencies:
@deepseek-ai/dsh-llm,@deepseek-ai/dsh-agent,@deepseek-ai/dsh-tools,@deepseek-ai/dsh-session-persistence-jsonl(any 4 listed, seepackage.json:41-119for details) - Architecture Pattern: Declares patch paths via
package.json#dsh.bundle.patchmanifest field, profile combiner parses and loads, no Cordis hooks or event registrations - Entry Files:
src/index.ts(@module declaration only),cordis.patch.yml(actual content),src/invariant.ts(one empty invariant companion)
Applicable Scenarios
Every factory dsh profile (including headless, ACP, CLI, Web) requires this layer as the out-of-the-box capability base; it's not a user-facing "enable-on-demand" extension, but a prerequisite for all upper-layer profile assemblies. When users want to understand which tools and defaults are available by default in their profile and who determines them, they can check this layer's patch file.
Prerequisites and Compatibility
| Dependency | Minimum Version | Description |
|---|---|---|
| DSH | Not separately declared (repository hasn't published lower bound for < dsh-base) | Installed as dsh same-repo profile bundle |
| Node | `^22.19.0 | |
| Platform | macOS / Linux / Windows | Same patch, bash and pwsh tool stacks mutually exclusively mounted by platform |
| Native Modules | None | This package doesn't introduce native modules, some rows in dependency closure may depend on them |
Installing this package automatically pulls in 70+ workspace dependencies (see
package.json:41-119), including LLM, agent, tools, persistence, subagent, shell, and other core packages.
Installation
dsh plugin --profile web add github:whitelonng/dshcode/packages/bundle/base
Configuration
This package has no "user-space" config items; its 50+ lines of row config are default values for subsequent profiles to override. Commonly overridable rows via environment variables:
| Row / Environment Variable | Default Value | Description |
|---|---|---|
sandbox-policy.mode (env var DSH_PERMISSION_MODE) | workspace-write | Three levels: read-only / workspace-write / danger-full-access |
approval.policy (same env var) | ask (becomes never under danger-full-access) | Driven by sandbox-policy row's same-source value |
session-telemetry-otel.mode (env var DSH_TELEMETRY_MODE) | DISABLED | Set to FULL / FEEDBACK_ONLY to enable OTLP reporting |
session-telemetry-otel.exporter.url (env var DSH_TELEMETRY_OTLP_URL) | https://harness-telemetry.deepseeksvc.com/v1/logs | OTLP/HTTP reporting endpoint, can point to self-hosted collector |
agent-default-model.provider / .model | deepseek-official / deepseek-v4-flash | Default model selection, can be overridden by user profile |
session-query-sqlite.openAt | never | Full-text search disabled by default, enable by overriding to first-search or startup, usually with path |
DSH_TELEMETRY_DISABLED(any non-empty value including'0'/'false') completely disables telemetry; launcher directly disables that row at startup.
FAQ
Q: What capabilities does this bundle include?
A: It aggregates all of dsh's "factory-bundled" capabilities — LLM adapters, Agent main loop, bash and pwsh tools, filesystem tools, subagent dispatch and fork, session JSONL persistence, SQLite session index, permission and sandbox policies, local settings/credentials, OTLP telemetry, token usage, compression, plan mode, goal loop, Web search, etc.
Q: Can I edit this bundle?
A: Not necessary and not recommended. Its "configuration" is centralized in a single cordis.patch.yml, mounted by the profile combiner at load time; your overrides should go in your own profile's cordis.patch.yml, line-overriding by row id. The patch semantics is "replace entire row config", no deep merge.
Q: How does behavior differ between macOS / Linux and Windows?
A: The bash and pwsh shell stacks are mutually exclusively mounted in the same patch file. On POSIX, bash-sandbox and tool-bash are enabled, pwsh series disabled; on Windows, pwsh series enabled, bash series disabled. Sandbox, permissions, and fs-sandbox apply to both, with Windows using ACL-restricted token runner.
Q: How do I enable telemetry?
A: Factory defaults to off. To enable, set environment variable DSH_TELEMETRY_MODE to FULL or FEEDBACK_ONLY, and point DSH_TELEMETRY_OTLP_URL to your OTLP/HTTP collector; exported records include the UUID from $DSH_HOME/.anonymous-user-id as user.id.
Q: What is the default permission model?
A: Sandbox defaults to workspace-write (writes limited to workspace and session's temp subdirectory), approval defaults to ask. Setting environment variable DSH_PERMISSION_MODE to danger-full-access switches to full access with no approval; read-only makes it read-only.
Q: Can I full-text search session history by default?
A: No. The session-query-sqlite row defaults to path: ':memory:' and openAt: 'never', full-text search calls return SESSION_QUERY_SEARCH_DISABLED; precise read, title, and lineage still work. To enable, override to first-search or startup in profile and provide a persistent path.
Q: What happens if I uninstall it?
A: It's the first layer patch for all factory profiles — removing it from dsh.profile.bundles list returns the entire profile to an "only user custom rows remain" empty state, common tools, models, and persistence all disappear. It's not a user-facing optional extension, recommended to keep.
Q: Where are images in sessions stored?
A: Bytes are stored in the local directory configured by the attachment-local row (separate from JSONL session logs). Session logs only retain content-addressable references, resolved on-the-fly by that row per request.
Getting Started Difficulty
Beginner — since it exposes no user-writable config surface, regular users don't need to understand it; to customize, simply append line overrides to your own cordis.patch.yml.
Known Issues and Limitations
- Patch whole-line replacement semantics: Profile overrides must rewrite every field to preserve in the target row, no deep merge layer; README explicitly lists this limitation (
README.md:21) - Windows temp directory is session-private subdirectory:
workspace-writerestricts writes to workspace and this session's own temp subdirectory (<temp>\dsh-<hash>, subprocess'sTMP/TEMPrewritten),read-onlygrants no temp directory writes (README.md:22) - bash and pwsh restore recipes must be paired: To switch back to bash on Windows, must simultaneously disable
pwsh-sandbox/tool-pwshand re-enablebash-sandbox/tool-bash, both register the samebashservice, enabling one side alone causes load failure - Full-text session search disabled by default:
session-query-sqliterowopenAt: never, SQL won't open until enabled in profile override (cordis.patch.yml:117-122) - Telemetry disabled by default:
session-telemetry-otel.modedefaults toDISABLED, no reporting withoutDSH_TELEMETRY_MODEset (cordis.patch.yml:148-161)
English | 中文
DSHCode 是一款面向 macOS 和 Windows 的免费开源桌面 AI Agent 应用。它将 DeepSeek 官方开源项目 DeepSeek Harness 的 Web UI 与插件运行时打包成一个可直接安装的 Electron 应用——无需 Node.js、无需终端、无需命令行。

功能特性
DSHCode 继承了 DeepSeek Harness 的完整能力,并加上了开箱即用的桌面体验。
Agent 核心 — 插件化框架,内置 bash、文件系统、网页搜索/抓取、终端、LSP 与子进程工具;支持沙箱隔离与逐操作审批提示。
交互式 UI — 内联渲染的 GenUI 卡片:图表、表格、测验、3D 场景、示意图、表单与进度视图。
Skills 技能 — 可安装的技能目录,为 Agent 提供专项工作流——研究、文档写作、视觉工具等。
编排能力 — Subagent 并行委派,以及可跨多个 Agent 分阶段并行展开的 Workflow。
长任务 — 执行前先审查再批准的 Plan 模式、跨轮次持续进行的 Goal 目标、可恢复的会话。
模型体验 — 通过官方 API 使用 DeepSeek 模型;会话日志完整记录模型所见内容,任何一次运行都可被重建。
模型控制 — 按供应商调节推理强度(关闭到最高)、最大输出 token 数,以及图像输入、图像生成与图像识别等多模态能力开关。

个性化 — 主题与皮肤合集、选区批注工作流、命令快捷键、中英双语界面。
插件管理 — 从 npm 或 Git 仓库安装插件、检查更新,并可逐个启用或禁用。

故障恢复 — 加载失败的插件会连同诊断信息一起报告:可禁用该插件、以安全模式启动,或让 Agent 携带失败上下文自动修复。


归档管理 — 搜索已归档会话,可恢复或彻底删除。

可扩展 — 安装新能力无需改动应用本体。
桌面集成 — 托盘图标、系统通知、单实例运行、加固的 Electron 窗口。

详见 Web UI 指南 的操作讲解,以及桌面应用指南中的架构、平台目标与当前限制。
下载
| 平台 | 安装包 |
|---|---|
| macOS Apple Silicon | DSHCode-*-macos-arm64.dmg |
| macOS Intel | DSHCode-*-macos-x64.dmg |
| Windows x64 | DSHCode-*-win-x64.exe |
每个版本都会随安装包发布 SHA-256 校验和(SHA256SUMS.txt)。
预览版安装包尚未进行代码签名或公证,因此 macOS Gatekeeper 与 Windows SmartScreen 可能在首次启动前发出警告。软件本身是安全的;警告只是因为二进制文件缺少付费签名证书:
- macOS:在访达中右键点击应用并选择打开,然后在弹窗中确认。或者在终端执行一次
xattr -cr /Applications/DSHCode.app。 - Windows:在 SmartScreen 弹窗中点击更多信息,然后选择仍要运行。
快速开始
安装 DSHCode 安装包后,从 macOS“应用程序”文件夹或 Windows“开始”菜单打开 DSHCode。应用会自行启动和停止内置 Web profile;安装版用户无需运行终端命令。
从源码运行
开发者仍可从仓库源码运行上游 Web 入口:
git clone https://github.com/whitelonng/dshcode.git
cd dshcode
pnpm install
pnpm run build
pnpm dsh web
命令会打印本地 Web UI 地址。详见 Web UI 指南。
桌面应用
打开 DSHCode 时,应用会启动内置的 Harness Web profile,并在经过安全加固的 Electron 窗口中显示。桌面外壳刻意保持精简;产品行为和 Web UI 仍由上游包提供,因此后续可以继续集成上游更新,而不必维护第二套界面。
本地服务与端口
应用每次启动时都会在 Electron 主进程内启动一个 HTTP 服务。该服务只绑定 127.0.0.1,并让操作系统分配一个可用的临时端口,因此不会占用固定端口,通常也不会与其他本地服务冲突。DSHCode 只允许一个应用实例,只加载其自身的精确回环地址;进程退出前会先释放 Harness 树,所以关闭应用也会停止服务并释放端口。
构建桌面安装包
git clone https://github.com/whitelonng/dshcode.git
cd dshcode
pnpm install
pnpm run desktop:dist
构建产物写入 .artifacts/desktop/release/。名为 Desktop 的 GitHub Actions 工作流会构建 macOS Apple Silicon、macOS Intel 和 Windows x64 安装包;desktop-v* tag 会把完整构建矩阵及 SHA-256 校验和发布到 GitHub Releases。
常见问题
DSHCode 是什么?
DSHCode 是一款免费、开源的桌面应用,把 DeepSeek 的插件化 AI Agent 框架 DeepSeek Harness 变成可直接安装的 macOS 与 Windows 应用,并提供图形化的对话与工作区界面。
DSHCode 是 DeepSeek 官方软件吗?
不是。DSHCode 是独立的社区项目。它保留上游包名、版权、架构、文档和 upstream Git 远程地址,以便正确归属来源并继续合并上游变更;但除非 DeepSeek 明确授权,它不代表 DeepSeek 官方发行、背书或认证。
需要 Node.js 或终端吗?
不需要。安装版用户得到的是普通应用;Node.js、CLI 与终端只在从源码运行或自行构建安装包时才需要。
为什么 macOS/Windows 会弹出安全警告?
预览版安装包尚未进行代码签名或公证。这是签名证书的成本问题,不是安全问题;一次性打开步骤见下载一节。
需要 API Key 吗?
需要。DSHCode 通过官方 API 运行 DeepSeek 模型;在应用设置中配置一次即可。
DSHCode 可以扩展吗?
可以。内置插件安装器可在不改动应用本体的前提下添加新能力;安全模式可以禁用导致崩溃的插件,保证应用仍能正常启动。
项目定位
DeepSeek Harness(dsh)是由 DeepSeek AI 开发的官方开源插件式 agent harness(智能体框架)。DSHCode 作为桌面端配套发行版参与其插件生态,并使用 dsh-plugin 和 deepseekharness-plugin 仓库标签便于检索。
DSHCode 是独立的社区项目。除非 DeepSeek 明确授权,否则它不代表 DeepSeek 官方发行、背书或认证。
开发
请先阅读开发指南、架构文档和桌面应用指南。面向 agent:请遵循 AGENTS.md。
致谢
- LINUX DO — 本项目也在 LINUX DO 社区持续分享与交流。
- dsh-genui — 为内置生成式 UI 能力提供插件实现。
- dsh-annotation — 为内置文本批注流程提供插件实现。
- dsh-web-ui — 为内置 Web UI 功能与皮肤集合提供插件实现。
许可证与品牌
源码继续使用上游 MIT 许可证。再次分发时必须保留 DeepSeek 的版权与许可声明;内置第三方软件及其许可证见 THIRD_PARTY_NOTICES.md,桌面安装包会同时附带这两个文件。
MIT 软件许可证本身不等于获得 DeepSeek 商标或 Logo 的 DSHCode 品牌使用许可。DeepSeek 的用户协议(中文版)保留了这些品牌标识的相关权利。DSHCode 发行版使用独立应用图标;内嵌 Harness 界面保留的上游身份标识及官方 powered by dsh 署名只用于说明兼容关系,不代表官方背书。
Read the usage guide →
Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.
Listing badge
[](https://deepseek-plugin.org/plugins/whitelonng/dshcode/packages/bundle/base)Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.