gdgfd22/deepseek-harness-ssh

gdgfd22★ 1TypeScript最后同步: 2026-08-19

在 GitHub 打开

Safety-gated SSH development plugin for DeepSeek Harness and MCP, built for GPU and offline laboratory servers.

README 摘要

dsh-lab-ssh English 简体中文 Safety-gated SSH development tools for DeepSeek Harness and standard MCP clients. The plugin lets an agent running on a connected workstation use a laboratory server's GPU, runtime, and explicitly configured source workspace while the server remains isolated from the public internet. Version 0.3.0 is an experimental preview. Pin a tested DeepSeek Harness version before laboratory deployment. This is an independent community plugin and is not an official DeepSeek AI package. Why it exists Giving an agent a normal SSH terminal exposes arbitrary destinations, commands, and filesystem paths. This project inserts a deny-by-default policy layer: - fixed model-visible host aliases; - pinned OpenSSH SHA256 host-key fingerprints; - environment, local-key-file, or SSH Agent credential references; - per-host command allowlists, auto-approval rules, and deny rules; - bounded command output and timeouts; - alias-based remote directory roots with canonical containment checks; - bounded UTF-8 reads and atomic, hash-protected writes; - optional alias-based command working directories; - a disabled-by-default HTTPS artifact bridge for offline servers; - one JSON policy shar…

在 GitHub 查看完整 README →
工具/开发deepseek-harnessdeveloper-toolsdsh-plugingpumcpoffline-serversshtypescript

分类