dsh-reach
English | 简体中文 | Español | Português | हिन्दी
Multi-channel decision & remote-control bridge for DeepSeek Harness (DSH): pushes any workspace's approval/question cards to IM channels (WeChat iLink, Telegram, Feishu — plus QQ/DingTalk/WeCom v2 drop-in foundations) and answers them from chat, with a session console, per-channel security, and an open push service.
Status: Phase 1–3 complete (WeChat + Telegram + Feishu channels, v0.1.10); v2 channel foundations (QQ/DingTalk/WeCom) on the open reachChannels registry.
The design plan, competitor research, official contract verification, and
phased roadmap live in
docs/design/03-rebuild-direction-and-plan.md.
Release (GitHub repo + npm publish) follows in a dedicated session.
Compatibility
| Surface | Status |
|---|
| Harness | DeepSeek Harness dsh-v0.1.6-alpha.2 (GitHub tag). Peer range >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0; the dev/test pins deliberately stay on the published 0.1.5-rc.2 line, which is the face the typecheck:ci ruler measures (the plain typecheck ruler measures the checkout through tsconfig.json paths). Verified 2026-09-18 with the full gate chain; the bare-import + scratch-profile + keyless smoke run in the Compat workflow on every PR. |
| Node | ^22.19.0 || >=24.0.0 |
Features (Phase 1)
- Cross-session decision push: approval/question cards from ANY workspace
are mirrored to WeChat (iLink/ClawBot) with stable
#token ids and P{n}
numbering; reply 1/2, P1=1 P2=2, P1=Q1=2, or /rp /rq — answered
through the native pending waterfall (first reply wins with the GUI).
- Fail-closed security: first sender becomes the owner; empty allowlists
deny everyone; unknown senders are audited and never answered.
- Session console:
/status /silent /notify /tasks /enter /history /stop /next /help plus native DSH command passthrough.
- Proactive push: the
reach_send tool with an outbound file fence; rate
budget + FIFO re-queue; silent mode; background completion notices.
- Settings tab: Settings → Plugins → IM Bridge (status, switches,
re-scan/logout).
- Open channel registry: third-party plugins register a channel via
ctx.get('reachChannels').registerChannel({ id, adapter, priority, ownsChatId, startMonitor }); routing, outbound, and monitor lifecycle are
all bridge-owned (QQ/DingTalk/WeCom ride this same path).
Install
# npm channel (published releases)
dsh plugin --profile web add dsh-reach
# git channel (latest main)
dsh plugin --profile web add "github:PerryLink/dsh-reach#main"
# alternates
npx @deepseek-ai/dsh plugin --profile web add dsh-reach
dsh1024 plugin --profile web add dsh-reach
Restart DSH after installation (bundle patches apply at startup).
Configuration
The profile row accepts these keys (Schemastery-validated; invalid values fail
the load loudly):
| Key | Default | Description |
|---|
crossSessionNotify | true | Push decision cards from ANY workspace/session (master switch) |
notifyTaskEvents | false | Background task finished/errored notifications |
cardTimeoutSec | 1800 | Decision-card soft timeout in seconds (0 = wait forever) |
approvalOnTimeout | delegate | Timed-out card policy: delegate (GUI chain) / reject / wait |
textChunkLimit | 4000 | Long reply chunk limit per message, in characters |
silent | false | Only final replies, no per-step streaming |
cwd | '' | Default working directory for new IM sessions ('' = host cwd) |
baseUrl / cdnBaseUrl / botType | iLink defaults | WeChat gateway, media CDN, bot type |
allowFrom | [] | Sender allowlist (empty = fail-closed; first sender = owner) |
queueMode | queue | Busy delivery: queue or steer |
maxQueue / sendBudget / windowSec | 50 / 10 / 60 | Queue cap, per-window send budget, window seconds |
denyUnauthorized | false | Silently ignore (true) or notice (false) unknown senders |
authCode | '' | Shared secret the IM side must present before a message is accepted |
digestSec | 300 | Digest window in seconds (0 disables the digest) |
pushToken |
Development
pnpm install
pnpm run typecheck && pnpm run typecheck:ci && pnpm test
pnpm run build && pnpm run verify:self-contained && pnpm run verify:artifacts
pnpm run check:readmes && pnpm pack
Install from the DSH Desktop Market
All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.
PerryLink DSH Plugin Family
This project is one of the 40 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:
| Plugin | One-liner |
|---|
| dsh-auto-review | Second-model auto-review on the approval chain, fail-closed by default |
| dsh-background-agents | Durable background child agents with a Web UI sidebar, messaging and interrupt |
| dsh-budget | Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel. |
| dsh-checkpoint-rewind | Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore |
| dsh-claude-move | Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH |
| dsh-click | Cross-platform native desktop control for DeepSeek Harness — Windows first. |
| dsh-composer-history | Terminal-style input history for the web composer: arrows, Ctrl+R search |
| dsh-data-quality | Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here) |
| dsh-defend | Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness. |
| dsh-doublecheck | Engineering-discipline guard: requirements grill, test gates, adversary review |
| dsh-draw | Unified static-image generation routing for DeepSeek Harness. |
Install from the DSH Desktop Market
All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.
License
Apache-2.0. Third-party notices in THIRD_PARTY_NOTICES.md.