namehousiqi/dsh-ssh-manager
适配DeepSeek Harness 官方桌面端 - SSH管理插件
Project Overview项目介绍
dsh-ssh-manager is a native cordis plugin built specifically for DSH (DeepSeek Harness), packaged as a bundle that ships both a Host half running inside the DSH process and a browser-side settings page rendered as part of the DSH Web GUI. Installation is done by cloning the repository, running pnpm install followed by pnpm pack to produce a workspace-dsh-ssh-manager-<version>.tgz file, and then adding that archive either through DSH's graphical plugin manager or via the dsh plugin add ./workspace-dsh-ssh-manager-<version>.tgz command; the package's cordis.patch.yml inserts an include:dsh-ssh-manager line that wires both halves together. A full restart of DSH is mandatory after installation, otherwise the in-memory version keeps serving stale settings and tools.
Its core purpose is consolidating password-authenticated SSH servers into a managed host list so the Agent can operate them by ID only, with passwords never echoed back through either the settings UI or read-only tool results. The intended workflow offers two entry points: manually adding hosts in Settings → SSH Hosts with optional connection testing, or handing a host list file to the Agent which parses it and calls ssh_host_apply for atomic bulk import after item-by-item confirmation. Available Agent tools include ssh_hosts, ssh_host_create, ssh_host_update, ssh_test, ssh_exec, and ssh_upload, while dangerous deletion patterns such as rm, rmdir, unlink, find -delete, xargs rm, rsync --delete, and git clean trigger a DSH approval flow before any connection is opened. The target audience is operators who want Agent-assisted sysadmin work without scattering credentials into chat history.
Dependencies and limitations deserve attention: installation will request approval for build scripts of ssh2@1.17.0 and cpu-features@0.0.10, and failure to approve them is non-fatal since ssh2 falls back to a pure-JavaScript implementation with reduced performance. Host records are stored in plaintext at ~/.dsh/ssh-manager/hosts.json with file mode 0600 and directory mode 0700, overridable through the DSH_SSH_HOSTS_FILE environment variable, and password values entered via Agent tools will appear in that session's tool arguments and persistent logs. Only password authentication is supported today, with no key or agent forwarding yet; remote commands time out at 30 seconds, stdout and stderr are capped at 64 KiB each, single-file SFTP uploads are limited to 100 MiB and require an absolute remote path without auto-created directories, and each host may carry at most 20 tags. There is no interactive PTY, no download, no directory sync, and no long-running background task; the deletion audit is a heuristic text check rather than a guarantee, and it does not cover Docker, Kubernetes, or database resources. The license is Apache-2.0, and first-run users must remember to restart DSH and verify the SSH Hosts page appears in Settings before proceeding.
dsh-ssh-manager 是一个面向 DSH(DeepSeek Harness)的原生 SSH 主机管理 cordis 插件,作为 bundle 打包,同时挂载 DSH 进程的 Host 半区与浏览器侧设置半区。安装方式为克隆仓库后执行 pnpm install 与 pnpm pack 生成 tgz,再通过 DSH 插件管理器或 dsh plugin add ./workspace-dsh-ssh-manager-<版本>.tgz 命令安装,安装后必须重启 DSH 才能生效。核心能力是把用密码登录的 SSH 服务器集中收纳到受管理的清单中,仅暴露主机 ID 给 Agent 操作,界面与工具结果均不回显密码。
典型工作流包含两种入口:一是手动在设置 → SSH 主机页面新增、编辑、测试连接;二是把主机清单文件交给 Agent,由 Agent 解析后调用 ssh_host_apply 批量写入,前置逐项确认后才原子落盘,避免半成品状态。Agent 可调用 ssh_hosts、ssh_host_create/update、ssh_test、ssh_exec、ssh_upload 等工具,对命中 rm、rmdir、find -delete、rsync --delete、git clean 等删除模式命令,连接前先经 DSH 审批服务申请批准。目标用户是需要让 Agent 协助运维、又不愿把账号密码散落在对话中的团队。
依赖与限制方面,安装时需批准 ssh2@1.17.0 与 cpu-features@0.0.10 的构建脚本,未通过也能以纯 JS 回退运行;主机数据明文存于 ~/.dsh/ssh-manager/hosts.json,文件权限 0600,可由 DSH_SSH_HOSTS_FILE 环境变量覆盖。仅支持密码认证,尚未支持密钥或 Agent 转发;命令超时 30 秒、stdout/stderr 各上限 64 KiB、上传上限 100 MiB、每台主机最多 20 个标签,不提供交互式 PTY、下载或目录同步。许可证为 Apache-2.0,首次使用前请务必重启 DSH 并在设置页确认插件已加载。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-ssh-manager(namehousiqi/dsh-ssh-manager)
仓库:https://github.com/namehousiqi/dsh-ssh-manager
本站详情页:https://www.yhbd.top/plugins/namehousiqi-dsh-ssh-manager/
本站登记:类型 client · 归类 原生 DSH 插件 · 许可证未声明 · ⭐ 2 · 最近提交 2026-09-29 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
- Desktop client: installation downloads an executable - verify the publisher and checksums桌面客户端:安装会下载可执行文件,请核对发布者与校验和
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:namehousiqi/dsh-ssh-manager
把 namehousiqi/dsh-ssh-manager 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH SSH 主机管理插件
在 DSH Web GUI 里集中管理用密码登录的 SSH 服务器,把「执行命令」和「上传文件」交给 Agent 去做,同时让常见的删除命令必须先经你批准。
为什么需要它
服务器多了以后,账号密码通常散落在各种笔记和文件里;想让 Agent 帮忙运维,又不想每次都把地址密码贴进对话;更担心它手一抖执行了 rm -rf。
这个插件把主机信息收进一份受管理的清单:
- Agent 只能操作清单里的主机 ID,不能凭空指定任意 IP、账号或密钥路径;
- 给人看的界面和给模型看的工具结果,都不会回显密码;
- 命中常见删除命令时,连接之前就先向你申请批准。
功能一览
| 能力 | 说明 |
|---|---|
| 主机管理界面 | 设置 → SSH 主机:新增、编辑、删除、启用/停用、测试连接 |
| 对话批量导入 | 你给一个文件(IP、账号、密码),Agent 读取解析后批量写入;保存前逐项列出变更请你确认 |
| 标签 | 给主机打标签,按标签筛选(多选取交集)与检索;支持重命名/合并 |
| 远程执行命令 | 非交互命令,30 秒超时,stdout/stderr 各上限 64 KiB,返回退出码与信号 |
| 文件上传 | SFTP 单文件上传到绝对路径,仅限会话工作区内的文件,上限 100 MiB,默认不覆盖 |
| 删除命令审核 | 命中常见删除命令时,连接前经 DSH 审批服务向你申请批准 |
| 主机指纹 | 首次认证成功记录 SHA-256 主机指纹,之后发生变化即拒绝连接 |
安装
前置条件:一个可用的 DSH Web GUI。本插件同时提供 Host 半区(跑在 DSH 进程里)和浏览器半区(设置页),所以安装的是 bundle。
1. 获取并打包
git clone git@github.com:namehousiqi/dsh-ssh-manager.git
cd dsh-ssh-manager
pnpm install
pnpm pack
打包会得到 workspace-dsh-ssh-manager-<版本>.tgz。
2. 安装到 DSH
图形方式(推荐):打开 DSH 的插件管理器,把上面的 tgz 作为 bundle 安装。
命令行方式:
dsh plugin add ./workspace-dsh-ssh-manager-<版本>.tgz
包名是 @workspace/dsh-ssh-manager,它带的 cordis.patch.yml 会插入一行 include:dsh-ssh-manager,同时挂上 Host 与浏览器两侧。
3. 允许依赖的构建脚本
安装时包管理器会请求 ssh2@1.17.0 与 cpu-features@0.0.10 的安装脚本许可。在你明确同意之前,这些脚本不会运行。它们编译的是可选的原生加速模块,装不上也能用(ssh2 会回退到纯 JavaScript 实现),只是性能路径略短。
4. 重启 DSH(很重要)
安装完必须重启 DSH。 如果只是覆盖安装,进程里跑的还是内存中的旧版本,设置页和工具都不会更新——这一点很容易被误判成"插件坏了"。
5. 打开设置页
重启后打开 设置(侧边栏底部)→ SSH 主机。
快速上手
方式一:手动添加
点右上角添加主机,填 IP/地址、端口(默认 22)、账号、密码(可勾选"显示密码"核对),保存即可。
之后在列表里可以:测试(真的连一次验证密码)、编辑、删除、停用。编辑时密码留空表示保持不变。
方式二:让 Agent 从文件导入
你:这是我的主机清单 /path/to/hosts.txt,帮我导进去
Agent 会读取文件、解析出 IP/账号/密码,然后调用 ssh_host_apply:它先把新增和修改逐项列出来(含标签变化,但不含密码)向你确认,你确认后才写入。文件格式不限,CSV、表格、纯文本都可以;某条信息不全时 Agent 会追问。
对应的工具入参形如:
{
"hosts": [
{ "host": "192.0.2.10", "username": "deploy", "password": "文件里的密码", "name": "staging" },
{ "host": "192.0.2.11", "username": "root", "password": "另一个密码", "port": 2222 }
]
}
ssh_host_apply 会先整体校验再原子写入,避免"只写进去前 5 台"这种半成品状态。只想改一台时,用 ssh_host_create 或 ssh_host_update。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
shaobeichen/dsh-pocket
ningbainb/deepseek-harness-desktop
chokwinlee/deepseek-harness-desktop
SCSpotato/dsh-remote
dclichang2022/dsh-green-meter
omdsh-dev/dsh-notification
mrRisega/dsh-remote
Clarklevis1995/dsh-plugin-mobile-gateway