DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

beartackler /

beartackler/dsh-bridge

Verified

Your harness muscle memory, verified and installed into DeepSeek Harness - familiar commands, connectors flow, and a trust-verified plugin catalog

★ 1 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHubProject homepage
READMESource: main@e367b00a
██████╗ ███████╗██╗  ██╗  ██████╗ ██████╗ ██╗██████╗  ██████╗ ███████╗
██╔══██╗██╔════╝██║  ██║  ██╔══██╗██╔══██╗██║██╔══██╗██╔════╝ ██╔════╝
██║  ██║███████╗███████║  ██████╔╝██████╔╝██║██║  ██║██║  ███╗█████╗
██║  ██║╚════██║██╔══██║  ██╔══██╗██╔══██╗██║██║  ██║██║   ██║██╔══╝
██████╔╝███████║██║  ██║  ██████╔╝██║  ██║██║██████╔╝╚██████╔╝███████╗
╚═════╝ ╚══════╝╚═╝  ╚═╝  ╚═════╝ ╚═╝  ╚═╝╚═╝╚═════╝  ╚═════╝ ╚══════╝

Familiar harness commands for DeepSeek Harness, with every plugin audited first.

CI License: MIT Node

dsh-bridge connectors flow: credential detection resolves into a masked detection matrix, then a trust report card for @liustack/modlens showing grade B with file-and-line evidence.

Rendered from the specs rather than a running build. Stills: detection matrix (light) · trust card (light).

What

dsh-bridge is a DeepSeek Harness plugin for people arriving from Claude Code, Codex CLI, OpenCode, or Jcode. It ports the slash commands you already know onto DSH-native seams, adds a guided connectors flow, and refuses to recommend a community plugin until an adversarial review has graded it.

Why

  • Language. The DSH plugin ecosystem skews non-English. The catalog and command surface here are English-first.
  • Trust. Plugins are arbitrary code. Every recommendation ships a report card citing file-and-line evidence you can re-check.
  • Muscle memory. /model, /resume, /memory, /mcp, /review behave the way your previous harness taught you.

Install

One command, from a machine with nothing installed:

curl -fsSL https://raw.githubusercontent.com/beartackler/dsh-bridge/main/scripts/install.mjs | node -

Piping a script into an interpreter means trusting what is on the other end. If you would rather read it first, that is the same file:

curl -fsSLO https://raw.githubusercontent.com/beartackler/dsh-bridge/main/scripts/install.mjs
less install.mjs && node install.mjs

Add --dry-run to print every command and every file write without executing any of them.

The script checks Node and pnpm, installs the DSH runtime if it is missing, creates an isolated DSH_HOME so your real ~/.dsh is untouched, pre-creates .credentials.yaml at mode 600 (the harness refuses to boot otherwise), installs dsh-bridge into the web profile, and prints the exact command to boot. Re-running it is safe: every step reports "already done" rather than repeating work, and it never overwrites a file it did not create.

What it cannot do for you. DSH ships no model. You supply a provider endpoint and an API key, and the script leaves you at /bridge-setup inside the UI, which walks through connecting one.

Requirements

Requirement Why
Node 22 or newer The harness runtime targets it
pnpm 10 or newer dsh plugin manages profile dependencies through it
A provider endpoint and API key Nothing answers until a model route is connected

Manual install

If DSH is already set up and you only want the plugin:

dsh plugin --profile web add github:beartackler/dsh-bridge
dsh --profile web        # serves http://127.0.0.1:3080

This assumes DSH is installed, a DSH_HOME you are happy to write to, .credentials.yaml at mode 600, and a model route already connected. If any of those are not true, use the installer above or the full walkthrough in docs/getting-started.md, which includes a working custom OpenAI-compatible provider configuration.

The repository ships its compiled dist/ output, so nothing builds on your machine at install time and dsh asks for no build-script permission. To make sure a later push cannot silently change what runs, pin a commit:

dsh plugin --profile web add "github:beartackler/dsh-bridge#<commit-sha>"

The installer takes the same pin as --ref <commit-sha>.

Then use /bridge-help inside DSH.

Verified against @deepseek-ai/dsh 0.1.1-rc.2: a fresh install from a git checkout activates the bundle with no warnings and all 17 commands register (how this was verified).

Verified catalog

docs/catalog/INDEX.md lists every plugin that has completed a trust review, with the audited commit and a linked report card.

Grades: A verified-clean · B safe with documented behavior · C use with awareness · D risky · F do not install. A grade is an evidence-backed opinion over one pinned commit, not a safety guarantee.

Trust report card for @liustack/modlens: grade B, with subject commit, sha512 integrity, npm attestation, MIT license, and per-capability findings for network, exec, telemetry, credentials, and filesystem writes.

Commands

All seventeen commands are implemented and verified end-to-end against @deepseek-ai/dsh 0.1.1-rc.2 (42 live invocations, see the verification report).

Command Does
/help Lists the bridge surface and the DSH-native equivalent of each command.
/init Onboards a repository and generates its instruction file.
/connect Detects existing provider credentials, configures routes, smoke-tests them.
/model Switches the active model or route without editing profile YAML.
/status Reports session, profile, and route state already known. Probes nothing.
/doctor Runs environment health checks and prints only what it actually observed.
/memory Reads and edits persistent user and project memory.
/compact Compacts conversation context on demand.
/resume Picks a recent session to resume or fork.
/review Reviews working-tree or pull-request changes.
/improve Proposes and applies targeted improvements to selected code.
/mcp Adds, inspects, and removes MCP servers.
/browse Browses the verified catalog with grade and trust filters.
/trust Prints a plugin's trust report card with its evidence.
/install Installs a plugin, preferring verified builds and requiring explicit risk consent.
/suggest Handles the dead end: scaffolds the plugin that does not exist yet.
/refactor Plans and applies behavior-preserving restructuring, tests-green gated.

Naming caveat: shipped names will be either /bridge:<name> or /bridge-<name>, pending an open DSH parser question.

Docs

  • Architecture — how the plugin sits on the Cordis kernel.
  • Trust pipeline — grading bands, heuristics, provenance checks.
  • Command specs · Plugin author guide · Glossary · FAQ
  • Charter · Contributing · Security · Roadmap

Status

Under active development. Research and audit artifacts land in docs/ as they are produced.

Milestone State
Capability research in progress
Adversarial audit of DSH built-ins in progress
MVP plugin (commands, connectors) shipped - 17 commands e2e-verified in dsh 0.1.1-rc.2
Trust report card pipeline shipped - 24 plugins graded (7 B, 16 C, 1 D)
Onboarding wizard UI planned

Principles

  1. Trust over speed. Every security claim cites evidence.
  2. English-first, i18n-ready.
  3. Minimal code. Shortest correct implementation, no speculative features.
  4. You own your machine. No telemetry without opt-in.

Provenance

Cross-reviewed by design: adversarial reviews are performed by models that did not write the artifact under review. Quality gates are documented in CONTRIBUTING.md.

Not affiliated with DeepSeek. Built on their MIT-licensed groundwork with gratitude.

—/ 5

No ratings yet

Verified DSH bundle

Commit e367b00acd33

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout