DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Observe — DSH Plugin for DeepSeek Harness
← Plugins

dsh-observe

Observe

OpenTelemetry and Langfuse observability exporter for DeepSeek Harness: turn/step/tool/LLM spans, token and cost metrics, and sanitized LLM prompt/completion capture from the session/event stream, with async batching, bounded offline buffering, and retry

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add dsh-observe@0.2.14
READMECompatibilityVersions

Compatibility and provenance

Observe is published as dsh-observe and currently resolves to version 0.2.14. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
npm
Registry updated
9/20/2026

Versions

0.2.14
stable
9/19/2026
0.2.13stable
9/18/2026
0.2.12stable
9/12/2026
Show 18 more versionsCollapse versions
0.2.11stable
9/10/2026
0.2.10stable
9/9/2026
0.2.9stable
9/7/2026
0.2.8stable
9/7/2026
0.2.7stable
9/4/2026
0.2.6stable
9/4/2026
0.2.5stable
9/4/2026
0.2.4stable
9/2/2026
0.2.3stable
9/2/2026
0.2.2stable
9/1/2026
0.2.1stable
8/30/2026
0.2.0stable
8/26/2026
0.1.5stable
8/23/2026
0.1.4stable
8/22/2026
0.1.3stable
8/22/2026
0.1.2stable
8/21/2026
0.1.1stable
8/17/2026
0.1.0stable
8/16/2026

Related plugins

Loading related plugins…

Latest
0.2.14
DSH
*
HMR
Process restart
Tree shaking
Declares sideEffects: false
Unpacked size
596.6 kB
Files
92
Surface
any
License
Apache-2.0
Source
npm
GitHub
★ 7
Weekly downloads
533
Last push
9/19/2026
View source ↗Project homepage ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in

Related plugins

More verified plugins in models-usage.

Usage@linxin666/dsh-usageUsage statistics plugin for the dsh web GUI: per-provider balance and coding-plan quota detection plus a live token usage ledger, with a dedicated pet bubble for the current providerWhale Widgetdsh-whale-widgetDeepSeek balance whale widget in the bottom-right corner of the DSH Web interface: balance/today’s usage/peak-off-peak pricing, customizable bubble click sequence (text/balance/today/peak-off-peak/image/random phrases and parallel weighted selection), per-line styles and fonts, floating quick editinUsage Stats@ychris12138/dsh-usage-statsToken usage heatmap, provider balances, and subscription quotas for the dsh web GUICodex Connectdsh-codex-connectChatGPT OAuth and Codex models for DeepSeek Harness.

README

📊 dsh-observe

  • 1024 store channel: npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-observe (counts toward the deepseek1024.com install ranking).

OpenTelemetry and Langfuse observability exporter for DeepSeek Harness.

Turn session events into OTLP traces and Langfuse observations — sanitized, buffered, off by default.

English · 简体中文 · Español · Português · हिन्दी


Compatibility

SurfaceStatus
HarnessDeepSeek Harness dsh-v0.1.6-alpha.2 (adapted 2026-09-18): session format V3 embeds the assistant stream in assistant/message / assistant/attempt and represents the system prompt as surface node 0 (system/message); the plugin consumes only the live event stream and never reads session log files. The peer range >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 keeps every published line installable (full local gate chain; the compat workflow covers the profile install smoke).
Node^22.19.0 || >=24.0.0
BackendsOpenTelemetry OTLP/HTTP (traces + metrics, JSON encoding) and Langfuse (LLM observability) — either or both
ModelModel-agnostic: it exports the session/event stream; no model calls are made

What you get

dsh-observe turns the harness's session/event stream into standard observability protocols:

  • Spans — turn, step, tool-call (duration, status, retry derivation), and LLM generation spans, linked into per-turn traces with deterministic ids.
  • Metrics — per-provider/model token counters, USD cost counters (configurable pricing table), and the optional context-pressure gauge from ctx.tokenMeter.
  • Sanitized capture — prompt and completion bodies are redacted (structural key names + built-in secret patterns + your patterns) and truncated before anything is queued or sent.
  • Reliability — async batching (size- and timer-triggered), a bounded durable offline buffer (storage-domain) with oldest-first eviction, and deterministic exponential-backoff retries; undeliverable batches survive restarts.
  • Runtime kill switch — the optional Typert remote (observe/status, observe/setEnabled) lets a settings page stop and resume exporting without unmounting.
  • Off by default — enabled: true plus at least one backend is an explicit opt-in; nothing is captured or exported otherwise.
session/event stream
   │ collector (turn/step/tool/llm spans, metrics)
   │ sanitize (keys, secrets, budgets)
   ├──▶ pipeline "otlp"  ── queue ── flush ──▶ OTLP /v1/traces + /v1/metrics
   │         └─ retry/backoff ─┐
   ├──▶ pipeline "langfuse" ── queue ── flush ──▶ Langfuse ingestion
   │         └─ retry/backoff ─┤
   └────────── durable spool (offline buffer, bounded) ◀┘

Quick start

# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-observe#main"

# or from npm (published releases)
dsh plugin --profile web add dsh-observe

# 2. configure a backend in your profile patch (cordis.yml) and restart
dsh --profile web

Minimal OTLP configuration (the row ships commented out in cordis.patch.yml):

- insert:
    - id: dsh-observe
      name: dsh-observe
      config:
        enabled: true
        otlp:
          endpoint: http://localhost:4318

Then verify the row mounts:

dsh --profile web --dump-config | grep -A2 'id: dsh-observe'

Install & uninstall

  • git channel (latest main): dsh plugin --profile web add "github:PerryLink/dsh-observe#main" — the prepare script builds with production dependencies only.
  • npm channel (published releases): dsh plugin --profile web add dsh-observe.
  • tarball channel: pnpm pack in this repo, then dsh plugin --profile web add ./dsh-observe-<version>.tgz.
  • uninstall: dsh plugin --profile web remove dsh-observe (or remove the row from the profile patch).

If pnpm reports ERR_PNPM_IGNORED_BUILDS for this package (esbuild's harmless platform-binary validation), add allowBuilds: { esbuild: true } to your pnpm-workspace.yaml — the dsh CLI prints the exact snippet.

Configuration

All tunables are Schemastery Config fields (changeable from cordis.yml). An id-targeted override replaces the whole row — restate every key you need. cordis.patch.yml documents each key inline.

KeyDefaultMeaning
enabledfalseMaster switch; true plus at least one backend is the explicit opt-in
otlpnullOTLP backend config, or null to disable it
otlp.endpoint(required)OTLP base URL; /v1/traces and /v1/metrics are appended
otlp.serviceNamedeepseek-harnessservice.name resource attribute
otlp.serviceVersion(none)service.version resource attribute
otlp.headers{}Extra headers merged into every export request
otlp.timeoutMs10000Per-request timeout
langfusenullLangfuse backend config, or null to disable it
langfuse.baseUrlhttps://cloud.langfuse.comLangfuse base URL
langfuse.publicKey(required)Project public key
langfuse.secretKey(required)Project secret key
langfuse.release(none)Release tag stamped onto traces
langfuse.traceNamesession {session} turn {turn}Trace-name template; {session}/{turn} interpolate per trace
langfuse.tags[]Static tags stamped onto every trace
langfuse.timeoutMs10000Per-request timeout
capture.turnstrueTurn lifecycle spans

Tools & surfaces

This plugin registers no model tools — it is a background exporter. Its surfaces:

  • Consumes session/event (span/metric collection), session/flush (best-effort export kick — the durability checkpoint never waits on a remote backend), and session/disposed.
  • Optional remote service observe — observe/status returns the kill-switch state, configured backends, queue depths, and buffer occupancy; observe/setEnabled stops and resumes exporting at runtime.

Permissions & data

  • Permissions: network:outbound to the endpoints you configure, session:read for the event stream, storage:write for the offline buffer; no native code, no filesystem access.
  • Data: everything sent is derived from the session log and sanitized (redaction + truncation) before it is queued, buffered, or transmitted. The offline buffer stores only sanitized records, re-validated when read back.
  • Credentials: Langfuse public/secret keys travel only to the configured Langfuse endpoint; OTLP headers only to the configured OTLP endpoint. The plugin stores no credentials itself — keep them in credential references or environment-injected values.

Security boundaries

  • Off by default — nothing is captured or exported unless you opt in explicitly.
  • Sanitize before send — structural key redaction, built-in secret patterns (API keys, GitHub tokens, AWS keys, bearer credentials, private keys), your patterns, and character budgets all apply before any record leaves memory.
  • Durable boundary re-validation — records read back from storage are checked again before a sink can see them.
  • Failure loud, failure contained — export failures warn, count, retry, and finally spool; a failing session handler is caught and logged so observability can never break the harness hot path.
  • Model-visible ⟺ logged — prompt/completion exports project only the session surface (whose node 0 is the system prompt) and the logged header (call config and tools); the exporter invents no content.

Known limitations

  • npm 0.1.6-alpha.2 — the plugin is developed and tested against @deepseek-ai/dsh@0.1.6-alpha.2 (devDeps and CI's primary ruler); the peer range >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 keeps every published line installable, and the second ruler (typecheck:ci) plus the compat workflow cover the older baselines.
  • Audit events are not persisted — the exporter's own observe/* records are audit-only: on the current host line the session append gate admits surface events, so no observe/* event is written to the session log, and the plugin does not fake one with an unmarked append (that would make sessions unreadable). Treat /observe status output and the OTLP/Langfuse backends as the audit surface.
  • Metrics bypass the retry/spool path — OTLP metrics are aggregated cumulatively, so a lost flush self-heals on the next one (by design, not a bug).
  • No sampling — every enabled span family is exported; set capture.* switches and batch.maxBufferRecords for high-volume sessions.

Development

pnpm install        # node ^22.19 || >=24
pnpm run typecheck  # tsc: src + tests against the 0.1.6-alpha.2 devDeps (no tsconfig paths)
pnpm run typecheck:ci  # tsc against the published line (no paths)
pnpm run check:ruler-live  # canary: must fail to compile, proving the ruler is live
pnpm test           # vitest: 126 tests, 18 suites (real Context/Session/storage seam)
pnpm run test:coverage  # coverage gate (90/80/90/90)
pnpm run build      # tsdown bundle + tsc declarations (lib/)
pnpm run verify:self-contained  # dependency specs resolve from the registry
pnpm run verify:artifacts       # built ESM face + bundle patch present
node scripts/check-readme-sync.mjs  # five-language README sync gate
pnpm pack           # the published tarball

Topics

dsh, dsh-plugin, deepseek-harness, deepseek, cordis, observability, opentelemetry, otlp, langfuse, tracing

Contributors

  • @PerryLink — creator and maintainer: collector, pipelines, spool, OTLP/Langfuse sinks, sanitization, and the five-language docs.

PerryLink DSH Plugin Family

This project is one of the 40 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

PluginOne-liner
dsh-auto-reviewSecond-model auto-review on the approval chain, fail-closed by default
dsh-background-agentsDurable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budgetCost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-checkpoint-rewindClaude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-moveMigrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-clickCross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-historyTerminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-qualityDataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defendPrompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheckEngineering-discipline guard: requirements grill, test gates, adversary review
dsh-drawUnified static-image generation routing for DeepSeek Harness.

Install from the DSH Desktop Market

All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.

License

Apache License 2.0 © 2026 dsh-observe contributors

capture.stepstrueStep lifecycle spans
capture.toolstrueTool-call spans with sanitized arguments/results
capture.llmtrueLLM generation spans
llm.prompttrueCapture the sanitized request prompt (false = sizes only)
llm.completiontrueCapture the sanitized completion (false = sizes only)
metadata.sessionIdtrueSession id attribute
metadata.cwdfalseSession working directory (a local path — off by default)
metadata.agentPresettrueAgent preset id attribute
metadata.modeltrueProvider/model attributes
metrics.tokenstruePer-provider/model token counters
metrics.costtrueUSD cost counters (need pricing rules to match)
metrics.contextTokenstrueContext-pressure gauge (needs ctx.tokenMeter)
pricing[]Pricing table, first match wins: { provider?, model, inputPerToken, outputPerToken, cacheReadPerToken?, cacheWritePerToken? }
sanitize.enabledtrueRedaction master switch (false disables redaction, never truncation)
sanitize.redactKeys[]Extra key-name substrings (key/token/secret/password/authorization/credential/apiKey are always included)
sanitize.redactPatterns[]Extra secret regular expressions
sanitize.truncatePromptChars4000Prompt character budget
sanitize.truncateCompletionChars4000Completion character budget
sanitize.truncateToolInputChars2000Tool argument character budget
sanitize.truncateToolOutputChars2000Tool result character budget
sanitize.truncateAttributeChars512Span attribute string budget
batch.maxRecords256Flush once the queue holds this many records
batch.flushIntervalMs5000Timer flush interval
batch.maxQueueRecords2000In-memory queue bound; excess spills to the buffer
batch.maxBufferRecords10000Durable offline buffer bound; oldest records drop first
batch.bufferRetryIntervalMs30000Offline buffer retry interval
retry.maxAttempts5Attempts per batch, including the first try
retry.baseDelayMs1000First backoff delay
retry.factor2Backoff multiplier per consecutive failure
retry.maxDelayMs60000Backoff ceiling
remote.enabledfalseMount the observe Typert remote (kill switch)
dsh-fastRead-only performance diagnostics for DeepSeek Harness.
dsh-fund-researchDeterministic research reports for Chinese public mutual funds
dsh-githubGitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-researchIndustry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-libraryLocal document knowledge base for DeepSeek Harness.
dsh-local-aiLocal-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actionsLSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-maskPII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panelRead-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-mementoApproval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-output-stylesClaude Code outputStyles-equivalent runtime style switching
dsh-permission-rulesClaude Code-style declarative allow/deny/ask permission rules with audit
dsh-personal-directivePersonal directive injector with top-bar toggle (framework edition)
dsh-plugin-guidePlugin-development knowledge base as an on-demand agent skill
dsh-plugin-doctorZero-dependency static + sandbox smoke detector for DSH plugins
dsh-reachMulti-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-reportVerifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-scoreMulti-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pinPin sessions in the Web sidebar with durable ordering
dsh-session-syncCross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-securitySecurity-audit skill pack: secret scan, dependency and supply-chain review
dsh-talkVoice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-test-driveIsolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktickTickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translateVendor parameter translation and deterministic JSON repair for DeepSeek Harness.
dsh-wechatWeChat ↔ DSH bridge (Tencent iLink bot): text/image/file/voice, approvals in chat
dsh-autotierAutomatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-catalogDSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcpRead-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-kitOne-command starter pack that installs the core family
dsh-plugin-certificationCommunity certification registry with repro-checkable grades and badges
dsh-plugin-kitShared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-portalZero-dependency static portal rendering the whole plugin family as one page
dsh-plugin-upgrade-015Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-team-roomsCross-session team rooms: shared message bus, task board and timeline