inmny/dsh-git-bash
DeepSeek Harness插件:让DSH使用Git Bash,同时保持read-only、workspace-write、full-access权限控制依旧可用。
Project Overview项目介绍
This plugin is a native DSH plugin built exclusively for DeepSeek Harness on Windows. It replaces DSH’s default PowerShell shell with Git for Windows Bash for all command executions, while maintaining DSH’s original three permission modes: read-only, workspace-write, and danger-full-access. You can install it via the DSH CLI command targeting your web profile, and it supports installing tagged release versions, the latest available version, or a local checked-out development copy. It also automatically detects the Git Bash installation path in common system locations like Program Files, user directories, and Scoop installations.
After installation completes, you must restart the dsh web process to load the new plugin version, then create a new session to verify the shell works as expected. You can run a sample test command to output the current shell version and environment, and a valid output will show MSYSTEM as MINGW64 or MINGW32. The plugin overrides the default shell for the standard, code, cordis, minimal, and Web Agent presets, with all commands sharing the same Bash executor. It also formats command output properly in the DSH web GUI to preserve alignment and readability.
The plugin installs only as a bundle layer for your DSH profile and does not modify the core DSH installation directory. It requires a Windows x64 system, Node.js version 24 or higher, DSH version 0.1.2-rc.1 or newer, and a 64-bit installation of Git for Windows. The npm package ships precompiled native guard binaries, so standard installations do not require a C++ build environment like Visual Studio or CMake. It is released under the open source MIT license, with a constraint that the installation path must not exceed Windows’ MAX_PATH length and be compatible with the system code page.
这是一款专为 Windows 平台 DeepSeek Harness 开发的原生插件,作用是替换 DSH 默认的 PowerShell,让 DSH 默认使用 Git for Windows Bash 执行命令,同时保留 DSH 原有的 read-only、workspace-write 和 danger-full-access 三种权限语义。插件可通过 DSH CLI 命令安装到 Web 配置文件,支持安装指定版本、最新版本或本地开发版本。
安装完成后需要重启 dsh web 让新版本生效,新建会话后可通过预设命令确认当前 shell 环境,MSYSTEM 输出应为 MINGW64 或 MINGW32 即为正常。插件会作用于 standard、code、cordis、minimal 以及 Web Agent 预设,所有命令共享同一个执行器。适配 Web 界面展示执行详情,支持命令换行、输出保留原格式对齐。
插件仅作为 bundle layer 安装,不会修改 DSH 本身的安装目录。依赖 Windows x64 平台、Node.js 24+、DSH 0.1.2-rc.1 以上版本和 Git for Windows x64,npm 包自带预编译的原生组件,普通安装不需要编译环境。采用 MIT 许可开源,原生限制要求安装路径不超过 MAX_PATH 且兼容当前系统代码页。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-git-bash(inmny/dsh-git-bash)
仓库:https://github.com/inmny/dsh-git-bash
本站详情页:https://www.yhbd.top/plugins/inmny-dsh-git-bash/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 17 · 最近提交 2026-09-20 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 17 stars - an early-stage project星标 17,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-plugin-git-bash@0.3.3
把 inmny/dsh-git-bash 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugin-git-bash
让 DeepSeek Harness 在 Windows 上默认使用 Git for Windows Bash,并保留 DSH 的 read-only、workspace-write 和 danger-full-access 权限语义。

使用方法
插件安装到 profile 后,standard、code、cordis 和 minimal preset 会使用 Git Bash 代替 PowerShell。前台命令、后台命令和 Web Agent preset 共用同一个 executor。
新建会话后可以运行以下命令确认 shell:
printf 'shell=%s\nversion=%s\nmsystem=%s\n' "$BASH" "$BASH_VERSION" "$MSYSTEM"
MSYSTEM 应为 MINGW64 或 MINGW32。
Web 界面中的 Bash 工具行可以展开查看 command、cwd、stdout/stderr 和 exit status。run_code 内的 nested Bash 调用使用同一套 terminal 详情;过长的 command 会自动换行,output 则保留终端横向滚动,以维持日志和表格的列对齐。
插件只作为 bundle layer 安装到目标 profile,不修改 DSH 安装目录。
安装或更新
从 npm 安装固定版本到 Web profile:
dsh plugin --profile web add dsh-plugin-git-bash@0.3.3
更新现有安装时使用同一条命令。安装完成后重启 dsh web,让 Host 和浏览器 client 同时加载新版本,然后新建会话。
安装最新版时可以省略版本号:
dsh plugin --profile web add dsh-plugin-git-bash
开发本地版本时传入 checkout 路径:
dsh plugin --profile web add C:\path\to\dsh-git-bash
权限模式
read-only 和 workspace-write
受限命令仍由 DSH Windows ACL sandbox 创建 WRITE_RESTRICTED token。插件在 sandbox 内先运行 native guard,再由 guard 启动 Git Bash:
DSH ACL runner -> msys-token-guard.exe -> bash.exe -> child processes
read-only可以启动 Git Bash,但不能写 workspace。workspace-write只能写 DSH 授权的 workspace 和 private temp。
danger-full-access
该模式不经过 native guard,直接运行 Git Bash,与插件 0.1.x 的执行方式一致。
配置 Git Bash 路径
插件会自动探测 Program Files、用户安装目录和 Scoop 中的 Git Bash。Web GUI 中打开 设置 -> 插件 -> 插件配置,展开 Git Bash 卡片后可以直接输入 bash.exe 路径,或通过 选择 Git 安装目录 调用系统路径选择窗口。保存后,后续 Bash 命令会立即使用新路径;恢复默认值会回到 profile 配置或自动探测结果。
无 GUI 场景可以在启动 DSH 前设置 DSH_GIT_BASH_PATH:
$env:DSH_GIT_BASH_PATH = 'D:\Apps\Git\bin\bash.exe'
dsh web
也可以直接在 profile 的 cordis.patch.yml 中为 provider 配置 executable:
- id: git-bash-shell
name: dsh-plugin-git-bash
config:
executable: D:\Apps\Git\bin\bash.exe
平台支持
运行时要求:
- Windows x64
- Node.js 24 或更高版本
- DSH
0.1.2-rc.1 - Git for Windows x64
npm 包包含预编译的 msys-token-guard.exe 和 msys-token-guard-hook.dll,普通安装不需要 Visual Studio 或 CMake。当前 native guard 仅支持 win32-x64;其他架构在受限模式下返回 SANDBOX_UNAVAILABLE,不会降级到未隔离执行。
Microsoft Detours 4.0.1 源码按 MIT 许可存放在 native/vendor/detours,许可文本随 npm 包分发。Detours 的 DLL path 参数使用 Windows ANSI API,因此插件安装路径必须能由当前系统代码页无损表示,并且不能超过 MAX_PATH;不满足条件时 guard 会 fail closed。
开发
安装依赖并运行完整验证:
pnpm install
pnpm test
pnpm run pack:check
在 Windows 上重建 native artifact 还需要 Visual Studio C++ Build Tools 和 CMake 3.25 或更高版本。pnpm test 会以 C++20、静态 MSVC runtime、CFG、CET、ASLR 和 NX 构建 native guard,然后运行 Windows ACL permission matrix、fail-closed、Web client 和 package metadata 测试。
非 Windows 主机不会交叉编译 native guard,只会检查预编译 artifact 是否存在。
License
MIT
kenryu42/cc-safety-net
hyhmrright/brooks-lint
zhu1090093659/dsh-trading
lire1131/dsh-undo-savepoint
jigjoy-ai/baro
c3ll256/dsh-toy
huaweicloud/huaweicloud-devkit