DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Bash On Windows — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins

dsh-bash-on-windows

Bash On Windows

On Windows, the available bash tool is limited to Git Bash and PowerShell is disabled.

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add dsh-bash-on-windows@0.1.0
READMECompatibilityVersions

Compatibility and provenance

Bash On Windows is published as dsh-bash-on-windows and currently resolves to version 0.1.0. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
npm
Registry updated
9/11/2026

Versions

0.1.0stable
9/11/2026

Related plugins

Loading related plugins…

Latest
0.1.0
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
79.1 kB
Files
20
Surface
any
License
MIT
Source
npm
GitHub
★ 1
Weekly downloads
0
Last push
9/13/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in developer-tools.

Web App@deepseek-ai/dsh-web-appThe dsh browser-surface bundle: the web patch layer over dsh-base plus the runtime glue plugin (frontend dist serving, web-surface prompt, bash runtime variables, URL line)Sdk Minimal@deepseek-ai/dsh-sdk-minimalThe standalone minimal SDK profile bundle: JSON-RPC, one DeepSeek adapter, persistent shell, and JSONL sessionsSdk App@deepseek-ai/dsh-sdk-appThe dsh SDK profile bundle: stdio JSON-RPC serving and process lifecycle over dsh-baseSubagent Codex@deepseek-ai/dsh-subagent-codexOne-shot Codex subagent provider over the official app-server protocol

README

bash-on-windows

DeepSeek Harness 插件(bundle + agent preset):让 Windows 上可用的 bash 工具限制为 Git Bash,并禁用 PowerShell。

组件

组件说明
cordis.patch.ymlbundle patch(dsh.bundle.patch):宿主平面翻转——tool-bash 启用、tool-pwsh 禁用;执行器 bash-sandbox 启用、pwsh-sandbox 禁用;win32 沙箱默认 danger-full-access + 审批 never(带 DSH_PERMISSION_MODE 逃生口,非 Windows 不动);挂载 plugins/escalation-inert.mjs
plugins/escalation-inert.mjs独立插件:full-access 部署下对模型隐藏 shell/fs 工具的 sandbox_permissions/justification 升级字段,并把同模式升级回声运行时置为无操作——不修改任何官方包(等价于过去直接改 npx-cache 里 harness 核心的做法,现在以可安装插件交付)
presets/standard-bash code-bash cordis-bashbash-only 派生预设(官方预设 + 两行翻转),因为 bundle patch 无法修改 dsh 内置预设文件
scripts/install.ps1把三个预设以 junction 形式安装到 $DSH_HOME\.agent-presets\(支持 -Uninstall)
scripts/build-presets.mjs从 pristine @deepseek-ai/dsh 源重新生成派生预设(上游升级时用)
scripts/check-rows.mjs契约测试:预设与 patch 的 bash-only 不变量 + escalation-inert 的 strip/sanitize/族门逻辑

工作机制(三层)

  1. 宿主平面(bundle patch):exec_command/bash 工具的执行器是 bash-sandbox(内部 spawn 'bash',Windows 上即 PATH 里的 git bash);pwsh-sandbox 被禁用,PowerShell 在运行时不存在。
  2. 会话平面(派生预设):web 界面(dsh-web-app)把宿主平面的 tool-bash/tool-pwsh 同时禁用、让每个会话由 preset 挂载工具。所以模型侧"只看到 bash"必须由预设文件完成——这正是官方预设文件被本地改过的原因;本插件把它变成可分发、不依赖改官方文件的派生预设。
  3. 升级词惰性化(escalation-inert):danger-full-access 部署从不拒命令,sandbox_permissions/justification 是模型习惯性回声的噪音字段,且同模式回声曾导致每次调用硬失败("not strictly wider")。该插件在 system-prompt/assemble 里把这两个字段从模型可见目录剥离(参数是逐次 structuredClone,注册表 schema 不受影响),并在 tools/execute 里把同模式回声参数替换为净化副本——官方审批路径永远看不到无操作请求,而真实加宽请求(请求模式 ≠ 当前模式)原样走审批。等价于以前的 harness 核心补丁,但不改任何官方包、升级 dsh 不会丢。

安装

# 1) 宿主平面(bundle patch)
dsh plugin --profile web add github:bainianlaoyao/bash-on-windows   # GitHub 分发
dsh plugin --profile web add dsh-bash-on-windows                    # npm 分发(已发布;预构建安装免 allowBuilds)
#    或手动把 cordis.patch.yml 里的 6 行补进 profile 的 cordis.patch.yml

# 2) 会话平面(三个 bash-only 预设,junction 安装,不复制代码)
powershell -ExecutionPolicy Bypass -File scripts/install.ps1

# 3) 重启 dsh,新建会话,选择 standard-bash / code-bash / cordis-bash 预设

前置条件:已安装 Git for Windows(bash 在 PATH 中)。

npm 包名:dsh-bash-on-windows(仓库名 bash-on-windows;dsh.profile.bundles 里加入 "dsh-bash-on-windows" 后 pnpm install 亦可)。

卸载

powershell -ExecutionPolicy Bypass -File scripts/install.ps1 -Uninstall
# bundle 行从 profile 补丁层手动删除

测试

node scripts/check-rows.mjs   # 契约:三个预设 + patch 的 bash-only 不变量

升级 dsh 后

node scripts/build-presets.mjs --src <pristine agent-presets 目录> 重新生成派生预设并提交;宿主平面补丁行无需改动(目标行 id 由官方包提供)。

安全

见 SECURITY.md——重要:win32 默认沙箱为 danger-full-access 且审批为 never,这是 git bash cygwin 运行时的硬性要求。

许可

MIT。派生预设来自 DeepSeek Harness agent presets(MIT,Copyright (c) 2026 DeepSeek),各预设目录内附 LICENSE.deepseek-harness。