deepseek-harness
deepseek-ai
DeepSeek Harness: Everything is a Plugin.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:zetaluolang-cyber/deepseek-harness-phone-remote
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
Don't watch your agent. Keep its pulse.
A secure, zero-app remote workspace for DeepSeek Harness. Reach the real Harness web UI from your phone over Tailscale (or LAN), manage files and workspaces, and keep an ambient eye on your agents through Agent Presence — the floating Orb, Task Board and notifications.
sessions.open — never a replacement session).This project does not replace the Harness UI. It turns Harness itself into a remote work environment: the phone opens the real DeepSeek Harness web UI over Tailscale (or your LAN), and a persistent plugin bridges the gaps a browser can't close remotely — authenticated file/workspace access and Agent Presence (Orb / Task Board / notifications).
[!WARNING] Device pairing authenticates this plugin's
/remfsand protected/api. Treat tailnet/LAN reachability as access to the Harness control plane; keep walk-on-LAN off unless needed and restrict Tailscale ACLs to trusted devices.
English | 中文 · Architecture · Security · Contributing
127.0.0.1 — a deliberate, sane default. The Harness process
itself stays loopback-bound; only the opt-in forwarders (Tailscale IP and,
when enabled, the LAN IP) expose selected interfaces.flowchart LR
P[Phone / remote browser] -->|Tailscale HTTPS| S[tailscale serve]
P -->|Tailscale IP| T[TCP forwarder]
P -->|same Wi-Fi: LAN IP| L[LAN forwarder]
S --> H[DeepSeek Harness Web<br/>127.0.0.1:3080]
T --> H
L --> H
H --> R[/remfs RPC channel<br/>trusted-host fence/]
R --> A[Device authentication<br/>pairing + per-device credential]
A --> F[Filesystem capability layer<br/>allowlist + protected paths + realpath]
F --> W[(Approved workspace)]
Three independent layers:
trusted-host and the tailnet are transport trusts. They are not
authentication. Pairing and the filesystem capability layer are.
install.ps1 validates/upgrades Node
(^22.19 || >=24), installs missing Node.js / Tailscale (winget), runs the
real one-time Tailscale device login, installs a private DSH runtime under
~/.dsh/runtime (never an incidental npx cache), creates the web profile,
installs the plugin, writes the launcher, registers auto-start, then starts
and health-checks Harness plus the plugin route before printing DONE.%USERPROFILE%\.dsh\lan-on
(or set DSH_REMFS_LAN=1) to trust the LAN IP and start the LAN forwarder;
on the same Wi-Fi the phone can then skip Tailscale (http://192.168.x.x:3080).
/remfs stays device-authenticated. Enabling it widens the network exposure,
so it is an explicit choice.scripts/orb-widget.ps1 (double-click
scripts/start-orb-widget.cmd, deployed to ~/.dsh/launcher): a
zero-dependency, per-pixel-alpha WinForms orb that stays above every window
with no rectangular backing card. Hover it for the current state and task
title; drag uses native compositor movement for smooth, flicker-free motion
(position persists across monitors). State-aware orbital sparks, comet
trails, bursts and energy rings animate the orb. Click it for a companion
panel with the current task, summary, refresh/log actions, and an Open
Harness button. The browser has no duplicate floating ball; its Task Board
is a normal header action. Polls the same task DTOs
(/remfs-presence.json).
install.ps1 also registers auto-start at logon (a Startup-folder
entry; single-instance, so the auto-start and the .cmd never stack —
remove dsh-orb-widget.cmd from the Startup folder to disable)./remfs-sw.js) and, once
paired, subscribes with the host's VAPID key. The host pushes
NEEDS_USER/FAILED (and DONE when enabled) transitions even with the tab
closed. RFC 8291 encryption implemented from scratch (zero deps), verified
against the official RFC test vector. HTTPS required (Tailscale HTTPS or
localhost). See docs/presence-push.md.Windows, System32, SysWOW64)
and credential/key files (.credentials.yaml, .ssh, .aws, .gnupg,
.env, id_rsa, *.pem …).AppData, Program Files,
ProgramData and private data dirs (WeChat/WPS). These are privacy
boundaries, not credential boundaries; registering such a folder is a local
decision only the PC user can make, and it never unlocks the hard-denied
files underneath./remfs only, not the native Harness /api. The GUI's
own API surface has no user login; keep the network boundary (tailnet / LAN)
tight and review which devices can reach it.C:\, new drives) requires editing
.remfs-roots.json on the PC.../UNC are rejected, and
the canonical realpath must stay inside the allowlist (symlink/junction
escapes fail).pocketStrict: true in ~/.dsh/remfs-options.json requires a valid device
credential for every browser /pocket call. The desktop companion uses a
separate 256-bit local, read-only presence token; its token file is remotely
hard-denied.~/.dsh/remfs-push.json (never in the repo).This project is a secure remote workspace & filesystem bridge for DeepSeek Harness: it keeps the native web UI and adds authenticated remote access plus a capability-bounded file/workspace layer. It is not a UI replacement, skin, or alternative frontend — the ecosystem has other community projects for those directions, and they are complementary rather than competing.
Advanced users (npm):
dsh plugin --profile web add @zetaluolang/remfs-persistent
# append to %USERPROFILE%\.dsh\profiles\web\cordis.patch.yml:
# - insert:
# - id: remfs-persistent
# name: '@zetaluolang/remfs-persistent'
# inject: [connection, fs, sandboxPolicy, workspaceRegistry]
# restart dsh web
Windows users (one-click): download/extract the repository, then double-click
一键部署.cmd. Internet access is required. The installer handles Node,
Tailscale, a project-owned DSH runtime, profile/plugin setup, launcher,
watchdog and first start. A Tailscale/UAC prompt is the only intentional human
step. DONE is printed only after the local Harness and plugin route pass a
live health check; the printed phone URL is therefore ready to open. HTTPS may
still require enabling certificates once in the Tailscale admin console.
The floating Orb is the post-install daily surface, not an installer: it shows
agent health and starts at login, while deployment/repair remains transactional
and visible in install.ps1.
https://<pc-name>.<tailnet>.ts.net, or the LAN URL when
walk-on-LAN is enabled and you are on the same Wi-Fi).%USERPROFILE%\.dsh\remfs-pairing.txt (or the harness log).install.ps1 registers a Task Scheduler task (dsh_harness_watchdog, every
5 minutes, current user, hidden window) that runs
%USERPROFILE%\.dsh\launcher\watchdog.ps1. Each run:
127.0.0.1:3080 — the owning
process's command line must contain the deployed dsh bin path (the watchdog
reuses the launcher's Get-OwnedHarnessPid ownership check; a bare open
port is never trusted, so an unrelated localhost service is never
mistaken for the harness).restart_harness_once.ps1 (DSH_HEADLESS=1 — no browser, no dialogs) and
appends every step to %USERPROFILE%\.dsh\launcher\watchdog.log.Re-run install.ps1 (or 一键部署.cmd) to update the task definition; the
watchdog itself checks in with one log line every 5 minutes when healthy.
We defend against: unauthenticated RPC, remote allowlist widening, path escape, credential theft at rest, accidental LAN/public exposure of the GUI.
We do not (yet) defend against: the harness GUI /api itself having no user
login (pairing protects /remfs, not the GUI — keep the network boundary
tight), a compromised host, or a compromised Tailscale account. Details in
SECURITY.md.
| Symptom | Fix |
|---|---|
| Phone shows the pairing screen forever | Read the code from %USERPROFILE%\.dsh\remfs-pairing.txt; codes expire after 10 min — restart the harness to generate a new one |
| Device revoked / re-pairing fails | Pairing codes are single-use; restart the harness for a fresh code |
| Phone gets 403 | Use the printed HTTPS/Tailscale/LAN URL; the GUI must run with those hosts trusted (one-click deploy does it) |
| LAN URL unreachable | Phone must be on the same Wi-Fi; re-run the launcher so the current LAN IP is detected |
npm.ps1 blocked by execution policy |
Use npm.cmd, or Set-ExecutionPolicy -Scope CurrentUser RemoteSigned |
npm view 404s right after a publish |
CDN edge cache — wait a minute or query with Cache-Control: no-cache |
Plugin never appears after dsh plugin add |
You must also append the loader row and restart dsh web |
| PC sleeps | keep_awake + power plan are handled by the deploy; see keep_awake.ps1 |
| Harness keeps dying / phone unreachable | Check %USERPROFILE%\.dsh\launcher\watchdog.log; re-run install.ps1 to (re)register the watchdog task |
Orb widget shows ? / "Disconnected" |
The harness or the forwarder is down — check the watchdog log and 127.0.0.1:3080 |
| Push toggle disabled ("needs HTTPS") | Open the harness via Tailscale HTTPS or http://localhost:3080; plain-LAN HTTP can't host a service worker — see docs/presence-push.md |
| No phone push with the page closed | See docs/presence-push.md → Troubleshooting |
docs/device-tests/.~/.dsh/remfs-options.json)MIT
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: 无有效分类标签。