dsh-pocket-console
Step out — the task won't stall.
You drop a task on DeepSeek Harness before heading out, expecting to review the result when you get back — and it is stuck on the plan-confirmation question.
dsh-pocket-console exists for that: it keeps a stalled session moving while nobody is at the desk.
It turns the two moments that need a human — tool-call approvals and ask_user_question prompts — into Feishu cards on your phone once the desktop has had its chance to answer; one tap and the agent continues. The phone gets that one decision and nothing else: approve, reject, or answer. The desk, the session, the settings and the credentials stay where they are, and one outbound long connection is all it takes — no public IP, no domain, no tunnel.
English · 简体中文
Install and uninstall
The published tarball carries its Feishu transport inside it, so the install resolves nothing that needs a build permission and runs no install-time script:
dsh plugin --profile web add dsh-pocket-console
Then restart dsh web and open Settings → Plugins → Plugin configuration → Pocket console:
- Click Scan to create an app. If you already have one, click Use an existing app and enter its App ID and App Secret.
- Scan the QR code with Feishu (the link is valid for 10 minutes and can be used once).
- The card reports Bound and lists the App, the Recipient and the Connection (established / dropped, reconnecting…).
Credentials and the recipient live in the credentials store, so every later dsh start reconnects the long connection by itself — no settings visit, no second scan. Use another app switches apps; Unbind stops the phone side. Installing straight from GitHub needs one build script allowed through, which troubleshooting covers.
To remove it:
dsh plugin --profile web remove dsh-pocket-console
Tuning it
It works out of the box: the Settings card exposes three settings and nothing else.
| Setting | Default | Meaning |
|---|---|---|
| Desktop head start (seconds) | 120 |
The request goes to the phone only if the desktop has not answered by then. 0 sends it immediately |
| Title prefix | DSH |
Prefix on every phone message title |
| Result notices | When idle |
After a session stops, the turn result goes to the phone with a box you can reply in. Its send delay reuses the desktop head start above |
Every row can be Reset, and an edit has to be saved (the card marks it Unsaved first).
Anything the card does not show belongs to the deployment. The channel, the interface language, the mirror lifetime and the like stay out of the card and are overridden in the profile layer — a patch replaces the row's entire config, so restate every key you want to keep:
$DSH_HOME/profiles/web/cordis.patch.yml
- id: pocket-console
config:
channel: dsh-pocket-console/providers/feishu.js
channelConfig: {}
delaySeconds: 120
titlePrefix: DSH
resultNotify: idle
resultNotifyCooldownSeconds: 0
mirrorTtlSeconds: 60
locale: zh
That is every key at the value the code already ships, so copying it changes nothing. Every setting documents the rest.
Security
An approval card is a remote code-execution authorization channel, so it is built like one:
- Grants are single-use.
allowed-onceapplies to that call only; the random id that carries it dies the moment the request settles. - The blast radius of a lost phone is one answer. The card is itself a credential, so only the bound recipient can press: a private chat only binds an unbound deployment, and group messages never bind.
- Secrets never go in environment variables. Every command the agent runs inherits the process environment, so credentials live in
$DSH_HOME/.credentials.yaml. - The app asks for the minimum. Three permissions, one event and one callback, from the minimum base rather than the default template's cloud-doc permissions.
- There is no server of ours in the path. Feishu sees the card, because Feishu is the transport.
Full invariants, threat model and reporting: SECURITY.md.
What it deliberately does not do
- No GUI mirroring. Moving the interface would move the workspace, the session, the settings and the credentials — so you also cannot keep working from the phone.
- No push to the phone by default. A card goes out only when the desktop has not answered in time.
- No auto-approval, ever. The plugin never decides in your place: silence never approves.
- No inbound listener. No port, tunnel, relay or third-party server — so also no "reachable from anywhere".
- No changes to DSH. It ships as a
dsh.bundleprofile layer and registers on two documented waterfalls. Nothing in the harness is patched or forked, and a DSH upgrade cannot break it.
How it breaks
These are honest gaps, not choices.
- Mirroring to the desktop needs the page open. After a phone answer, the open page settles the way a click there would; with no page open the answer still reaches the model and the session log, but a page opened later will not replay it — the mirror is valid for one minute.
- One Feishu app serves one DSH instance. Long-connection events are not broadcast, so two instances sharing one bot send approvals to a random side.
- Card text is limited by bytes, not characters. A card request body caps at 30 KB and a CJK character costs 3, so text is held under 9 KB and truncated explicitly. A very long plan arrives as its opening section; the buttons still work.
Which of these is this?
| Transports | Phone gets | You must operate | Fits | |
|---|---|---|---|---|
| Desktop GUI mirroring — dsh-pocket, ds-harness-remote, dsh-zen-remote | the whole Web GUI over LAN, tunnel, P2P or hosted relay | the full interface: workspaces, sessions, settings, credentials | a tunnel, a relay, a domain, or trust in someone's relay | working away from the computer |
| IM console — dsh-im, dsh-lark-bot | chat platform long connections | sessions, workspaces, models, permissions; several channels | a bot app, often a developer-console walkthrough | driving the agent from chat |
| Notification only — dsh-turn-notify, @dsh-suite/plugin-notify | toast, browser, webhook, Bark, ServerChan | a message it cannot answer | per-channel webhook or key | knowing when something happened |
| dsh-pocket-console | one outbound WebSocket | one decision, single-use — approve, reject, or answer | nothing | an agent that must not stall while you are away from the desk |
If you want the computer in your hand, install one of the first three. This plugin is for the other case: the computer stays where it is, and only the decision travels.
For developers
- Shape: a
dsh.bundleprofile layer, plain ESM, no build step; the published package is about 4 MB because the Feishu transport and its dependencies are bundled inside the tarball. - Tests:
npm test. No install, no network and no credentials — the production dependencies are replaced by in-repo stubs. - Gates:
npm run check:parity(one setting has to agree in six places) andnpm run e2e(installs the packed artifact into a realdsh webto prove it activates). That is what CI runs:verifyon two Node versions,real composition,publish payload. - Before changing something: docs/decisions/ records why it is shaped this way; docs/development.md covers the suite and debugging.
- How a change lands: CONTRIBUTING.md; what changed when is in CHANGELOG.md. Writing a transport other than Feishu: the channel contract.
Going further
| Doc | What is in it |
|---|---|
| Configuration | Every option, its default, and which ones the Settings card changes at runtime |
| Troubleshooting | Install, binding, and cards that never arrive |
| docs/decisions/ | Why the plugin is shaped this way — one record per decision |
| SECURITY.md | The security invariants this plugin claims |
| CONTRIBUTING.md | How a change lands: issue, branch, pull request, the four checks |
| CHANGELOG.md | What changed in each version |
No comments yet. Be the first to write one.