DeepSeek Harness 插件

agent

把本地 dsh 网页通过带登录门禁的中继转发到公网 *.ds.hn 子域名(也可自托管到自己的域名),支持可选的端到端加密(PBKDF2 到 AES-256-GCM)。

跳到安装方式

来源信息

GitHub 仓库
jsdvjx/dshn
最近更新
2026年8月21日
分类
远程与移动
GitHub stars
0

安装

默认先复制一段 Prompt,让 Agent 读页面和仓库;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读页面和仓库。

请先不要安装。阅读这个 DeepSeek Harness 插件,说明它解决什么问题、会访问哪些文件、网络或密钥,以及如何安装和卸载。

插件页面:https://deepseekplugins.org/zh/plugins/jsdvjx/dshn~23agent
GitHub:https://github.com/jsdvjx/dshn/tree/main/packages/agent
插件名:dshn#agent
作者:jsdvjx
安装命令:dsh plugin --profile web add "https://github.com/jsdvjx/dshn/releases/latest/download/dshn.tgz"

确认前不要执行安装命令。

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器2 个文件
README.md来源说明 · 只读预览

dshn-agent

The dsh plugin half of [dshn](../../README.md). It opens one outbound WebSocket to the relay, claims a subdomain with the (subdomain, password) the user typed in the setup dialog, and replays whatever the relay forwards against the local dsh web server — HTTP over node:http, dsh's own /api/events.* downlink sockets over a tunnelled ws client.

Two halves:

  • Host (src/index.tslib/index.js): the tunnel client, the replay

engine, the reconnect/heartbeat loop, credential persistence, and the /dshn/status · /dshn/configure · /dshn/disconnect routes.

  • Browser (client.js, hand-authored factory format): a shell.overlay

pill that opens the setup dialog when unconfigured (subdomain + password), or the live status + public URL when connected.

Why no trustedHosts patch

The agent rewrites each forwarded request's Host/Origin to the local loopback authority before replaying it to dsh. dsh's /api browser-trust fence then accepts it as a loopback, same-origin request — for any subdomain, with no composition-time trusted-host entry. That is what lets the subdomain be chosen at runtime in the dialog; access is gated by the relay's login instead of the fence.

Config

Credentials (subdomain + password) are not configured here — the user sets them in the dialog (POST /dshn/configure, loopback-only) and they persist to DSHN_STATE. Only infrastructure is env-configured:

envmeaningdefault
DSHN_RELAY_HOSThost the tunnel dialsrelay.ds.hn
DSHN_ORIGIN_CAPEM cert to pin when dialing a direct grey-cloud origin
DSHN_STATEfile the chosen credentials persist to~/.dshn-agent.json
DSHN_LOCAL_PORTlocal dsh port to replay againstthe web server's port
DSHN_ENABLED0 loads the plugin inert1