DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Bash Rtk — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins
B

@deeptrial/dsh-bash-rtk

Bash Rtk

DeepSeek Harness bash executor plugin that routes eligible commands through rtk (Rust Token Killer) to compress tool output and save tokens. Optional overlay: install, then enable via --patch.

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:DeepTrial/dsh-bash-rtk#810ec22075f0754b0f15a8bedd31ef8ba80d2bc5
READMECompatibilityVersions

Compatibility and provenance

Bash Rtk is published as @deeptrial/dsh-bash-rtk and currently resolves to version 0.1.1. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
github
Registry updated
8/24/2026

Versions

0.1.1stable
8/24/2026

Related plugins

Loading related plugins…

Latest
0.1.1
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
any
License
MIT
Source
github
GitHub
★ 12
Weekly downloads
0
Last push
8/25/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in developer-tools.

Web App@deepseek-ai/dsh-web-appThe dsh browser-surface bundle: the web patch layer over dsh-base plus the runtime glue plugin (frontend dist serving, web-surface prompt, bash runtime variables, URL line)Sdk Minimal@deepseek-ai/dsh-sdk-minimalThe standalone minimal SDK profile bundle: JSON-RPC, one DeepSeek adapter, persistent shell, and JSONL sessionsSdk App@deepseek-ai/dsh-sdk-appThe dsh SDK profile bundle: stdio JSON-RPC serving and process lifecycle over dsh-baseSubagent Codex@deepseek-ai/dsh-subagent-codexOne-shot Codex subagent provider over the official app-server protocol

README

dsh-bash-rtk

Route eligible shell commands through rtk (Rust Token Killer) inside the DeepSeek Harness (dsh) bash executor — compress tool output, save tokens, change nothing else.

中文版


Table of Contents

  • Quick Example
  • Requirements
  • Why
  • How it works
  • Install & enable
  • API / Configuration
  • Which commands are routed
  • Development
  • License

Quick Example

The plugin rewrites commands at the resolve() boundary — before anything runs:

Input (command)Resolved outputReason
git statusrtk git statusSimple + whitelisted
cargo build --releasertk cargo build --releaseSimple + whitelisted
git status | grep xgit status | grep xComplex shell — passthrough
ls -lals -laNot whitelisted — passthrough
git status (rtk absent)git statusBinary missing — identity fallback

Everything else — workdir, timeout, env, exit code, sandbox confinement — is inherited unchanged.

Requirements

  • Node.js: >= 20.0.0
  • rtk: rtk --version must exit 0 on PATH (install separately, e.g. cargo install rtk)

Why

LLM agents burn tokens on verbose tool output (git log, cargo build, pytest trails…). rtk already knows how to shrink those for 30–90%. This plugin bolts that filtering onto dsh's bash executor so every eligible command is auto-routed through rtk — with zero semantic change to what actually runs.

How it works

model → dsh bash tool → RtkBashExecutor.resolve()
                              │
              ┌───────────────┴────────────────┐
         eligible?                         not eligible
     (simple + whitelisted)           (complex / unknown)
              │                                │
      rtk <subcommand> …              command runs unchanged
   (rtk compresses output)            (byte-for-byte passthrough)

Three independent guards decide (see src/wrap.ts):

  1. Complexity — any shell metacharacter (| & ; < > \ $`) disqualifies the command. Wrapping those would silently alter what runs, so they pass through untouched.
  2. Whitelist — only known dev tools that rtk actually implements are eligible (map in wrap.ts).
  3. Availability — if the rtk binary is absent on PATH, the transform is the identity: the deployment behaves exactly like the stock local executor.

Versioning note

The plugin does not bundle or pin rtk. At dsh startup it probes rtk --version on PATH (see resolveRtk() in src/index.ts). Therefore:

  • When rtk ships a new release, any user who upgrades rtk on their machine automatically gets the new behavior — no plugin update required.
  • The plugin version (this repo) and the rtk version are independent; keep them separate. This README states the minimum rtk version tested against, not a lockstep number.

Requires: rtk on PATH (rtk --version exits 0). The plugin does not install or manage rtk — you must install and update rtk yourself (e.g. cargo install rtk or download a release binary). When rtk is absent the plugin is a silent no-op passthrough.

Compatibility & version alignment

This plugin depends on three @deepseek-ai/dsh-* packages that DeepSeek Harness publishes to npm independently from the dsh aggregate package. As of this release the versions are deliberately pinned (see peerDependencies in package.json):

PackagePinned version
@deepseek-ai/dsh-bash-local0.0.1-rc.1
@deepseek-ai/dsh-bash-sandbox0.0.1-rc.1
@deepseek-ai/dsh-shell0.0.1-rc.5
cordis^4.0.1-rc.1

The plugin's dsh.plugin.json declares "engines": { "dsh": "0.1.1-rc.2" }, i.e. it is verified against the dsh aggregate 0.1.1-rc.2.

Known version skew: dsh (the aggregate, what npx @deepseek-ai/dsh installs) and its @deepseek-ai/dsh-* sub-packages are on separate semver tracks — the aggregate can be 0.1.1-rc.2 while the published sub-packages are still 0.0.1-rc.1. This plugin pins to the published sub-package versions so a plain dsh plugin add resolves cleanly. If a future dsh release changes the LocalBashExecutor.resolve() / ShellExecSpec API surface, a sub-package bump on npm will be required before this plugin can track it. Watch the releases for a matching update.

Install & enable

The plugin is disabled by default — installing it does nothing until you opt in.

# 1) from a local checkout
dsh plugin --profile web add "<path-to-this-dir>"

# 2) or directly from the latest GitHub release tarball (no local clone needed)
dsh plugin --profile web add \
  "https://github.com/DeepTrial/dsh-bash-rtk/releases/latest/download/dsh-bash-rtk.tar.gz"

# enable it via an optional overlay — add to your profile's cordis.patch.yml:
#   - id: bash-sandbox
#     disabled: true
#   - id: bash-rtk
#     disabled: false

dsh web   # restart to apply

The bundled overlay snippet lives in cordis.patch.yml. It swaps the stock sandbox executor for RtkSandboxBashExecutor (file confinement preserved) and leaves the unconfined RtkBashExecutor available for danger-full-access setups.

API / Configuration

Both executors accept the same base config as their stock counterparts (LocalBashExecutor / SandboxBashExecutor) plus one optional field:

OptionTypeDefaultDescription
rtkAvailablebooleanresolveRtk() resultForce-enable or force-disable rtk wrapping. Useful for tests or deployments where the binary path is non-standard.

All other options — cwd, timeoutMs, graceMs, etc. — are inherited unchanged from the upstream executors.

Which commands are routed

The set of commands eligible for rtk-wrapping is defined by rtk itself — see the rtk command reference / README.md for the authoritative, maintained list. This plugin mirrors that list; when rtk adds a new subcommand, upgrade rtk (not this plugin) to pick it up.

Complex commands — pipelines, &&/;, redirects, $( ), env assignments — always run natively regardless of the whitelist.

Development

# 1. clone the plugin and its sibling harness
git clone https://github.com/DeepTrial/dsh-bash-rtk.git
git clone https://github.com/deepseek-ai/deepseek-harness.git

# 2. install harness deps and build the libraries the plugin links against
cd deepseek-harness && pnpm install && pnpm build:lib:host

# 3. install plugin deps and run checks
cd ../dsh-bash-rtk && pnpm install --ignore-scripts
pnpm run check        # typecheck + test + build
pnpm run test         # tests only
pnpm run typecheck    # tsc only

devDependencies use link: into the local deepseek-harness checkout; tests run inside that workspace (the @deepseek-ai/dsh-* packages must resolve).

License

MIT