DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Coding Remote Kit — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-coding-remote-kit

Coding Remote Kit

DeepSeek Harness 移动配对远程插件:通过双平面允许列表 RPC(LAN / Tailscale / 可选 Cloudflare Quick Tunnel 或自托管 rendezvous)提供 E2EE 配套服务。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:lninghaha/dsh-coding-remote-kit#43703e3decf6615b58c7326892212ee2ceba7be7
README兼容性版本
Desktop settings — pairing offer with QR and PINDesktop settings — channel status and paired devices

兼容性与来源证明

Coding Remote Kit 以 dsh-coding-remote-kit 发布,当前版本为 0.7.1。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
github
Registry 更新时间
2026/9/20

版本

0.7.1stable
2026/9/12
0.7.0stable
2026/9/12
0.6.0stable
2026/9/10
查看其余 9 个版本收起版本
0.5.2stable
2026/9/2
0.5.1stable
2026/8/28
0.4.1stable
2026/8/22
0.4.0stable
2026/8/22
0.3.0stable
2026/8/19
0.2.2stable
2026/8/19
0.2.1stable
2026/8/19
0.2.0stable
2026/8/19
0.1.0stable
2026/8/19

相关插件

正在加载相关插件…

最新版
0.7.1
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
web
许可证
MIT
发布源
github
GitHub
★ 1
周下载
203
最近提交
2026/9/12
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

dsh-coding-remote-kit

v0.7.1 · DeepSeek Harness 0.1.1-rc.2 / 0.1.5-rc.2 · GitHub dsh-coding-remote-kit

Remote phone access for DeepSeek Harness. Pair a phone to the desktop that already runs dsh web, then observe sessions and perform a narrow set of writes — without exposing the full Web API.

English · 中文版 · 日本語 · 한국어 · Português (BR) · Español · Français · Deutsch · Русский


Upgrade / 升级: Follow the versioned steps in INSTALL.md. 0.7.1 adds DSH 0.1.5-rc.2 support through the host sessionController service — session list, history paging, prompt, cancel, live events, phone approvals and user questions, and assistant streaming — while 0.1.1-rc.2 keeps working through the legacy apiProxy path; 0.6.0 added mobile Queue/Steer, activity strip, history paging, and optional offline push; 0.5.2 added CSP/pairing hardening and sessionStorage secrets; 0.5.1 fixes install→start without reloading dsh-web after Settings installs cloudflared; 0.5.0 added connection diagnostics, Quick Tunnel disclaimer gating, and pinned cloudflared verify; keep profile/storage/pairing files and restart one existing DSH Web process only after all selected plugins are updated. dsh-coding-oauth-core@0.1.2 remains the Hub/Subscription shared npm dependency, not a separate DSH plugin.


Community plugin. Not affiliated with, and not endorsed by, DeepSeek. Product intent is closer to Orca Mobile Companion than to a second copy of the desktop IDE.

Read AGENTS.md before changing this repo: do not restart the production DSH Web process or its local service wrapper yourself. Prepare the tarball; the operator restarts it through the machine's own process manager.

Names

Developed first as GitHub dsh-mobile-remote. The npm name dsh-mobile-remote is a different project (a WeChat remote-control plugin). This plugin publishes as dsh-coding-remote-kit.

Use thisNotes
npmdsh-coding-remote-kit@0.7.1dsh plugin --profile web add dsh-coding-remote-kit@0.7.1
GitHublninghaha/dsh-coding-remote-kitprevious checkout name dsh-mobile-remote
Cordis plugin idmobile-remoteunchanged
Settings HTTP/api/mobile-remote/*unchanged
Storage$DSH_HOME/storages/mobile-remote/unchanged

Do not dsh plugin add dsh-mobile-remote — that installs the unrelated WeChat plugin.

Status

MilestoneStatus
Research (Orca / DSH ecosystem)done — docs/research/
M1 plugin skeleton + ADR / threat modeldone
M2 pairing / LAN data planedone
M3 narrow RPC / approvalsdone
M4 signed HTTPS / native appnot started
M5 self-hosted rendezvous Workerdone — docs/05-cloud-relay.md

Features

  • Bilingual UI — Chinese and English for desktop Settings and the phone companion (?lang= / in-app switch; defaults from navigator.language).
  • Pair once — desktop shows a QR code or 8-digit PIN; the phone pins the desktop X25519 public key and holds a deviceToken (server stores SHA-256 only).
  • Dual plane — management routes stay on loopback dsh web; the mobile data plane is a dedicated port (default 6879) with an RPC allowlist.
  • E2EE after handshake — tweetnacl secretbox on /m/ws; unauthenticated sockets never see session content.
  • Narrow writes — observe sessions, answer approvals/questions, short replies; heavy editing stays on the desktop.
  • Private-network first — LAN / Tailscale preferred. Optional Cloudflare Quick Tunnel exposes only the data plane, never port 3080. Optional self-hosted rendezvous Worker: desktop and phone both outbound; business frames stay E2EE.
  • Standard plugin shape — one Cordis server plugin + classic-script Settings page. dsh plugin --profile web add a file tarball, never a link: working tree.

Screenshots

Desktop settings — pairing offer with QR and PIN   Desktop settings — channel status and paired devices

Desktop Settings → Mobile Remote: create a pairing offer (left) · channel status & devices (right)

Phone pairing screen    Phone session list

Phone companion: enter PIN / scan (left) · session list after pairing (right)

Problems this plugin solves

You searched / sawWhat was actually brokenWhat this plugin does
“Orca-style phone companion for DSH”Official DSH has no first-class paired mobile appSemantic companion: pair + E2EE + allowlisted RPC
dsh-pocket / dsh-web-remote on a phoneFull dsh web surface on LAN/publicDual plane; unknown RPC methods are forbidden
Phone on cellular, desktop on LANRaw LAN HTTP page can be MITM’dPrefer Tailscale; optional Quick Tunnel (TLS at the edge, localhost origin)
Plugin import failed and port 3080 diedDSH fail-fasts the whole plugin treeSandbox gate + packed tarball copied outside the repo; no link:

Quick start

dsh plugin --profile web add dsh-coding-remote-kit@0.7.1

Then the operator restarts the existing dsh web process in their own window. Open Settings → Mobile Remote, create a pairing offer, scan the QR (or type the PIN) on the phone.

From a source checkout (development):

pnpm test:sandbox
pnpm pack
mkdir -p "$HOME/.dsh/packages"
cp dsh-coding-remote-kit-0.7.1.tgz "$HOME/.dsh/packages/"
dsh plugin --profile web add "$HOME/.dsh/packages/dsh-coding-remote-kit-0.7.1.tgz"

Do not dsh plugin add ./ from this working tree. pnpm 11 treats some file: tarball paths as link: source, and a bad entry import takes down the whole GUI.

Table of contents

  • Names
  • Status
  • Features
  • Screenshots
  • Problems this plugin solves
  • Quick start
  • Install
  • How it works
  • Settings page
  • Mobile RPC
  • Public tunnel
  • Security
  • Architecture
  • Documentation
  • Related
  • Contributing
  • License

Install

Requires DeepSeek Harness 0.1.1-rc.2 (pinned) and Node.js 22.19+. Unverified candidates such as 0.1.5-rc.1 are recorded in the BOM only — see INSTALL.md.

Development:

pnpm install && pnpm build && pnpm test   # inside the Docker sandbox, not on a live GUI host
pnpm test:sandbox                         # Dockerfile targets check / isolated-install / verify

Build outputs:

  • lib/server/index.js — Cordis entry (name / inject / Config / apply)
  • lib/client.js — Settings classic-script
  • lib/mobile/ — phone page served at /m

How it works

Settings (loopback)          Phone browser
        │                            │
        │  QR / PIN  ────────────────┤
        ▼                            ▼
 /api/mobile-remote/*          GET /m  +  WS /m/ws
   (dsh web, :3080)            (data plane, :6879, E2EE)

Management stays behind the host Web loopback fence. The data plane is a separate node:http + ws server. Pairing may rebind it from 127.0.0.1 to 0.0.0.0 so LAN clients can connect; an active Quick Tunnel advertises its HTTPS origin instead of widening.

Settings page

Open Settings → Mobile Remote:

  • status (bind, port, listening, active devices, tunnel, rendezvous)
  • LAN / Quick Tunnel / rendezvous channels
  • create offer → QR + 8-digit PIN
  • device list and revoke
  • optional official cloudflared install (never runs at plugin apply())
  • connection diagnostics (sanitized network candidates, cloudflared pin/verify, disclaimer version)
  • Quick Tunnel disclaimer checkbox (required before Start)

Mobile RPC

Allowlisted methods (everything else is forbidden):

status.get · session.list · session.history · session.subscribe · session.unsubscribe · host.subscribe · session.prompt · session.cancel · session.create · respond · device.name

Pushes include session events plus approval.requested / question.requested (with rpcId for respond). Wire format: docs/03-protocol.md.

Public tunnel

Default off. Start from Settings only after accepting the disclaimer (disclaimerAccepted: true). cloudflared Quick Tunnel points only at 127.0.0.1:<data-plane-port>. /m becomes reachable on a https://<random>.trycloudflare.com URL; pairing still needs the fragment token (or PIN) and E2EE. The child process is killed on plugin unload / Stop.

Never tunnel port 3080 / dsh web. A self-hosted rendezvous Worker (desktop and phone both outbound, business frames still E2EE) is optional; see docs/05-cloud-relay.md. It needs a Cloudflare Workers Paid plan and is not a public relay operated by this project.

Security

Invariants (full model: docs/04-threat-model.md):

  1. Unauthenticated connections handle handshake only.
  2. deviceToken is stored as SHA-256; keys and registry files are 0600.
  3. RPC allowlist, default deny; writes are audited to deviceId.
  4. Management plane is loopback + Host + CSRF.
  5. The plugin does not weaken dsh web /api and does not take over api-proxy providers.

Honest v0 boundary: the first HTTP download of /m on a raw LAN can be MITM’d. Prefer an overlay VPN. /m responses include a Content-Security-Policy (script-src 'self', frame-ancestors 'none') that bounds post-load injection; it does not close the first-download MITM gap.

Prohibitions:

  • Do not share another person's credentials.
  • Do not monitor accounts you are not authorized to access.
  • Do not bind the data-plane port on 0.0.0.0 to the public Internet (Quick Tunnel is an explicit, user-started exception).
  • Do not imply DeepSeek official endorsement.

Examples in docs use example.com, 127.0.0.1, and YOUR_TOKEN only.

Architecture

Dual plane, module map, storage, and handshake: docs/02-architecture.md · 中文.

MVP decision (route B): docs/01-mvp-scope.md.

Documentation

DocPurpose
INSTALL.mdInstall, pair, tunnel
CHANGELOG.mdRelease history
docs/00-project-rules.mdVersioning, publish vs local-only, host DSH boundary
docs/01-mvp-scope.mdADR: MVP scope (Chinese)
docs/02-architecture.mdInternal architecture · 中文
docs/03-protocol.mdRPC allowlist and push envelopes (Chinese)
docs/04-threat-model.mdAssets, attackers, invariants (Chinese)
docs/05-cloud-relay.mdSelf-hosted rendezvous Worker (M5)
docs/06-dsh-alpha-smoke.mdIsolated smoke on unverified DSH candidates (0.1.2-alpha.*, 0.1.5-rc.1)
CONTRIBUTING.md

Related

  • dsh-coding-subscription-oauth — sibling plugin; documentation layout is modelled on it.
  • GitHub: lninghaha/dsh-coding-remote-kit.
  • This plugin is independent of the usage-centre plugin dsh-hub-oauth-gateway.
  • It does not replace @deepseek-ai/dsh.

Contributing

Issues and PRs welcome. See CONTRIBUTING.md for the Docker sandbox, commit conventions, and the document layers.

License

MIT.

Contribution guide
AGENTS.mdAgent/operator rules (no production restart)