DeepSeek Harness 插件

dshn

Forward this machine's local DeepSeek Harness (dsh) web service to the public internet over ds.hn: an outbound WSS tunnel to the relay, plus the trust-fence integration that lets forwarded requests(英文原文)

跳到安装方式

来源信息

GitHub 仓库
jsdvjx/dshn
最近更新
2026年8月21日
分类
模型与服务商
GitHub stars
0
载体类型
plugin
包路径
packages/agent
目录证据
上游声明已找到 dsh.bundle
证据路径
packages/agent/package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/jsdvjx/dshn/tree/HEAD/packages/agent
插件名:dshn
作者:jsdvjx

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器2 个文件
README.md来源说明 · 只读预览

dshn-agent

The dsh plugin half of [dshn](../../README.md). It opens one outbound WebSocket to the relay, claims a subdomain with the (subdomain, password) the user typed in the setup dialog, and replays whatever the relay forwards against the local dsh web server — HTTP over node:http, dsh's own /api/events.* downlink sockets over a tunnelled ws client.

Two halves:

  • Host (src/index.tslib/index.js): the tunnel client, the replay

engine, the reconnect/heartbeat loop, credential persistence, and the /dshn/status · /dshn/configure · /dshn/disconnect routes.

  • Browser (client.js, hand-authored factory format): a shell.overlay

pill that opens the setup dialog when unconfigured (subdomain + password), or the live status + public URL when connected.

Why no trustedHosts patch

The agent rewrites each forwarded request's Host/Origin to the local loopback authority before replaying it to dsh. dsh's /api browser-trust fence then accepts it as a loopback, same-origin request — for any subdomain, with no composition-time trusted-host entry. That is what lets the subdomain be chosen at runtime in the dialog; access is gated by the relay's login instead of the fence.

Config

Credentials (subdomain + password) are not configured here — the user sets them in the dialog (POST /dshn/configure, loopback-only) and they persist to DSHN_STATE. Only infrastructure is env-configured:

envmeaningdefault
DSHN_RELAY_HOSThost the tunnel dialsrelay.ds.hn
DSHN_ORIGIN_CAPEM cert to pin when dialing a direct grey-cloud origin
DSHN_STATEfile the chosen credentials persist to~/.dshn-agent.json
DSHN_LOCAL_PORTlocal dsh port to replay againstthe web server's port
DSHN_ENABLED0 loads the plugin inert1