Skip to main content

dshcode/packages/bundle/base

90Stars8Forks0Issues1Watchers

Package all dsh basic capabilities into profile combo bundles as the first-layer patch for each profile, hosting 60+ core entries including models, tools, sandbox, permissions, and session persistence.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
MIT
Branch
master
agentdeepseekdeepseekharness-plugindsh-pluginharness

Install

cmdweb profile
$ dsh plugin --profile web add @deepseek-ai/dsh-base

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin whitelonng/dshcode/packages/bundle/base for me: review the repository at https://github.com/whitelonng/dshcode first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

Entry package name: @deepseek-ai/dsh-base, landing page ID: whitelonng/dshcode/packages/bundle/base. Referred to below as the "Base Bundle".

One-Line Description

It's dsh's factory profile "first layer patch" — injecting 60+ base plugins including model, Agent, tools, sandbox, permissions, session persistence, telemetry, subagent, etc. into the root of an empty profile, equivalent to a browser's factory default extensions set; other mode bundles and user configurations are stacked or line-overridden on top of it.

Core Capabilities

  • Introduces LLM adapters (DeepSeek native + pi-ai multi-provider bridge) and default model selection (agent-default-model defaults to deepseek-official / deepseek-v4-flash)
  • Mounts Agent main loop (agent / agent-loop / agent-default-model / agent-instructions / system-prompt), establishing the task dispatch framework
  • Exposes foundational tools: bash/pwsh (one or the other based on platform), fs, fs-search, str-replace-editor, web_search, todo, subagent, subagent-fork, subagent-control, subagent-report, workflow, goal, skill, ralph, jobs, etc.
  • Assembles persistence and session management: JSONL session logs (written to $DSH_HOME/sessions), SQLite session index (in-memory mode by default, content search disabled), in-memory attachment byte store, checkpoint strategies and projections
  • Enables file sandbox, permission policies and approval switches, defaults to workspace-write + ask, provides three preset levels: read-only / workspace-write / danger-full-access
  • Provides local credentials and settings ($DSH_HOME/.credentials.yaml + $DSH_HOME/settings.yaml, hot-reload) and OTLP telemetry mount (disabled by default)

Technical Implementation

  • Language: TypeScript, but runtime is configuration-driven — this package's src/index.ts only exports {}, no runtime API, all behavior described by cordis.patch.yml
  • Key Dependencies: @deepseek-ai/dsh-llm, @deepseek-ai/dsh-agent, @deepseek-ai/dsh-tools, @deepseek-ai/dsh-session-persistence-jsonl (any 4 listed, see package.json:41-119 for details)
  • Architecture Pattern: Declares patch paths via package.json#dsh.bundle.patch manifest field, profile combiner parses and loads, no Cordis hooks or event registrations
  • Entry Files: src/index.ts (@module declaration only), cordis.patch.yml (actual content), src/invariant.ts (one empty invariant companion)

Applicable Scenarios

Every factory dsh profile (including headless, ACP, CLI, Web) requires this layer as the out-of-the-box capability base; it's not a user-facing "enable-on-demand" extension, but a prerequisite for all upper-layer profile assemblies. When users want to understand which tools and defaults are available by default in their profile and who determines them, they can check this layer's patch file.

Prerequisites and Compatibility

DependencyMinimum VersionDescription
DSHNot separately declared (repository hasn't published lower bound for < dsh-base)Installed as dsh same-repo profile bundle
Node`^22.19.0
PlatformmacOS / Linux / WindowsSame patch, bash and pwsh tool stacks mutually exclusively mounted by platform
Native ModulesNoneThis package doesn't introduce native modules, some rows in dependency closure may depend on them

Installing this package automatically pulls in 70+ workspace dependencies (see package.json:41-119), including LLM, agent, tools, persistence, subagent, shell, and other core packages.

Installation

dsh plugin --profile web add github:whitelonng/dshcode/packages/bundle/base

Configuration

This package has no "user-space" config items; its 50+ lines of row config are default values for subsequent profiles to override. Commonly overridable rows via environment variables:

Row / Environment VariableDefault ValueDescription
sandbox-policy.mode (env var DSH_PERMISSION_MODE)workspace-writeThree levels: read-only / workspace-write / danger-full-access
approval.policy (same env var)ask (becomes never under danger-full-access)Driven by sandbox-policy row's same-source value
session-telemetry-otel.mode (env var DSH_TELEMETRY_MODE)DISABLEDSet to FULL / FEEDBACK_ONLY to enable OTLP reporting
session-telemetry-otel.exporter.url (env var DSH_TELEMETRY_OTLP_URL)https://harness-telemetry.deepseeksvc.com/v1/logsOTLP/HTTP reporting endpoint, can point to self-hosted collector
agent-default-model.provider / .modeldeepseek-official / deepseek-v4-flashDefault model selection, can be overridden by user profile
session-query-sqlite.openAtneverFull-text search disabled by default, enable by overriding to first-search or startup, usually with path

DSH_TELEMETRY_DISABLED (any non-empty value including '0'/'false') completely disables telemetry; launcher directly disables that row at startup.

FAQ

Q: What capabilities does this bundle include?

A: It aggregates all of dsh's "factory-bundled" capabilities — LLM adapters, Agent main loop, bash and pwsh tools, filesystem tools, subagent dispatch and fork, session JSONL persistence, SQLite session index, permission and sandbox policies, local settings/credentials, OTLP telemetry, token usage, compression, plan mode, goal loop, Web search, etc.

Q: Can I edit this bundle?

A: Not necessary and not recommended. Its "configuration" is centralized in a single cordis.patch.yml, mounted by the profile combiner at load time; your overrides should go in your own profile's cordis.patch.yml, line-overriding by row id. The patch semantics is "replace entire row config", no deep merge.

Q: How does behavior differ between macOS / Linux and Windows?

A: The bash and pwsh shell stacks are mutually exclusively mounted in the same patch file. On POSIX, bash-sandbox and tool-bash are enabled, pwsh series disabled; on Windows, pwsh series enabled, bash series disabled. Sandbox, permissions, and fs-sandbox apply to both, with Windows using ACL-restricted token runner.

Q: How do I enable telemetry?

A: Factory defaults to off. To enable, set environment variable DSH_TELEMETRY_MODE to FULL or FEEDBACK_ONLY, and point DSH_TELEMETRY_OTLP_URL to your OTLP/HTTP collector; exported records include the UUID from $DSH_HOME/.anonymous-user-id as user.id.

Q: What is the default permission model?

A: Sandbox defaults to workspace-write (writes limited to workspace and session's temp subdirectory), approval defaults to ask. Setting environment variable DSH_PERMISSION_MODE to danger-full-access switches to full access with no approval; read-only makes it read-only.

Q: Can I full-text search session history by default?

A: No. The session-query-sqlite row defaults to path: ':memory:' and openAt: 'never', full-text search calls return SESSION_QUERY_SEARCH_DISABLED; precise read, title, and lineage still work. To enable, override to first-search or startup in profile and provide a persistent path.

Q: What happens if I uninstall it?

A: It's the first layer patch for all factory profiles — removing it from dsh.profile.bundles list returns the entire profile to an "only user custom rows remain" empty state, common tools, models, and persistence all disappear. It's not a user-facing optional extension, recommended to keep.

Q: Where are images in sessions stored?

A: Bytes are stored in the local directory configured by the attachment-local row (separate from JSONL session logs). Session logs only retain content-addressable references, resolved on-the-fly by that row per request.

Getting Started Difficulty

Beginner — since it exposes no user-writable config surface, regular users don't need to understand it; to customize, simply append line overrides to your own cordis.patch.yml.

Known Issues and Limitations

  • Patch whole-line replacement semantics: Profile overrides must rewrite every field to preserve in the target row, no deep merge layer; README explicitly lists this limitation (README.md:21)
  • Windows temp directory is session-private subdirectory: workspace-write restricts writes to workspace and this session's own temp subdirectory (<temp>\dsh-<hash>, subprocess's TMP/TEMP rewritten), read-only grants no temp directory writes (README.md:22)
  • bash and pwsh restore recipes must be paired: To switch back to bash on Windows, must simultaneously disable pwsh-sandbox/tool-pwsh and re-enable bash-sandbox/tool-bash, both register the same bash service, enabling one side alone causes load failure
  • Full-text session search disabled by default: session-query-sqlite row openAt: never, SQL won't open until enabled in profile override (cordis.patch.yml:117-122)
  • Telemetry disabled by default: session-telemetry-otel.mode defaults to DISABLED, no reporting without DSH_TELEMETRY_MODE set (cordis.patch.yml:148-161)

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/whitelonng/dshcode/packages/bundle/base)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory