DSH Marketplace

dsh-im

xmanrui/dsh-im

Connect IM bots to DeepSeek Harness by scanning QR codes (supports Feishu, Weixin, DingTalk, and more).

419JavaScriptMITSource

Install

Add dsh-im to DeepSeek Harness

via npm

Resolves a published tarball rather than cloning the repository, and installs without any extra setup. Swap `web` for your profile name if you run another one.

via GitHub · npm package

Installing from GitHub runs the project's build script, which pnpm blocks until you allowlist it — run the command once and pnpm prints the exact key to add under `allowBuilds` in ~/.dsh/profiles/web/pnpm-workspace.yaml.

What happened when we ran it

Installed cleanly when we ran it

Every command here is run in a throwaway container against a clean profile, and the result is whatever the harness recorded — not a guess from the source. Last run 3d ago.

Due diligence

Before you install dsh-im

  • Source of record: xmanrui/dsh-im — present in the community registry that DSH's own plugin market installs from.
  • Licensed under MIT.
  • A listing here is not a security review. Plugins run with your agent's permissions.

The AI take

What it is — dsh-im plugin connects IM bots to DeepSeek Harness by scanning QR codes or entering existing bot credentials, providing unified management for Feishu, WeChat, DingTalk, WeCom, QQ, Telegram, Discord, and WhatsApp bots.

Who it is for — When an AI assistant needs to be integrated into enterprise IM tools such as WeCom or DingTalk using DeepSeek Harness for user query handling and message exchange via persistent connections, this plugin supplies the required capabilities. If only a single IM platform is used with independent credentials and no need to manage multiple channels uniformly, another approach can be chosen.

Watch out — The plugin registers successfully in a fresh profile during sandbox testing. No obvious issues were observed.

The verdict — If unified management of multiple IM platform bots with existing QR code or credential setup is required, this plugin provides the necessary functionality; otherwise, it is not needed.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.

What dsh-im does

Abstract channels converge through supervised connections into isolated workspaces and session paths.

dsh-im is a DeepSeek Harness plugin that connects chat bots from multiple instant-messaging platforms to an agent through one settings page. DeepSeek Harness exposes an “IM bots” page where an operator can create or bind bots using QR codes, an App Manifest, or existing credentials. DeepSeek Harness then runs separate channel hosts, clients, RPC handlers, credential storage, connection supervision and chat-session mappings for Feishu, WeChat, DingTalk, WeCom, QQ, Slack, Telegram, Discord and WhatsApp.

The channel adapters use each platform’s documented transport: persistent connections, WebSocket, Socket Mode, Gateway, or long polling. Secrets and tokens are submitted only to the local Harness Host and stored in protected credential storage; RPC responses return redacted status rather than credentials. Each bot receives a workspace, initially set to the Host process’s process.cwd(), and supports /workspace, /workspacelist, /sessionlist and /session commands.

dsh-im suits developers who need to receive and answer Harness conversations from supported IM services without maintaining separate channel settings pages. It is a poor fit when a platform’s native bot access is unavailable or when the bot audience is not trusted: users within the platform-visible scope can run the workspace and session commands, and those commands may expose paths, session metadata or access to sessions and their available tools. WhatsApp uses a linked-device session stored under ~/.dsh/integrations/dsh-whatsapp/auth, while Telegram long polling cannot take over until an existing Webhook is removed.

dsh-im documentation

Configuring dsh-im

DeepSeek Harness provides one IM bots settings page for the nine built-in channels. QR-based setup is available for Feishu, WeChat, DingTalk, WeCom, QQ and WhatsApp. Slack uses an App Manifest plus a Bot Token (xoxb-) and App Token (xapp-); Telegram and Discord use Bot Tokens. Manually entered secrets are sent only to the local Harness Host and stored in protected credential storage. The browser receives QR codes, manifests and redacted status only.

Each bot records the Harness Host’s process.cwd() as its initial workspace. The path persists across Host restarts and can be changed from the bot card. For a Web profile exposed on a trusted local network, the README documents this optional setting:

- id: xmanrui-dsh-im
  config:
    rpcAuthority: trusted-host

trusted-host reuses Harness Host and Origin protection but does not provide user authentication.

dsh-im Commands

Command Function
/workspace <absolute path> Switches the current bot to an existing absolute directory.
/workspacelist Lists existing workspaces registered on the current Harness Host.
/sessionlist [workspace number or absolute path] Lists sessions registered for a workspace.
/session <Session ID> Binds the current chat to an existing session returned by /sessionlist.

Paths must be existing absolute directories. /session does not create or resume a session automatically; archived sessions can be bound, but child-agent sessions cannot.

How dsh-im behaves

Each bot has independent credentials, connections and session mappings. Platform replies follow channel rules: private messages generally receive replies directly, while group or server messages may require a mention or reply to the bot. New workspace mappings affect later messages; existing generated replies continue.

dsh-im access limits

Any user in the platform-visible bot scope who can message the bot may run the commands. Workspace and session data come from the global Harness Host registry and can include paths, sessions or metadata belonging to other bots or projects. A user able to bind a session may write to it or invoke its available tools. trusted-host should therefore be used only on a trusted network.

Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub

Same category

Alternatives to dsh-im

dsh-pocket

shaobeichen

80

Remote phone access to the DSH Web UI: scan a QR code for LAN or public (cloudflared tunnel) access with real-time sync, a mobile-adaptive layout, and a settings tab.

Installed cleanly when we ran it

npm packageJavaScript4d ago

AI review

dsh-pocket

What it is — DSH Pocket plugin provides remote phone access to the DeepSeek Harness Web UI. It supports scanning QR codes for LAN or public cloudflared tunnel access with real-time sync, and includes a mobile-adaptive layout.

Who it is for — When you need to check agent tasks running on your computer while out of the office or use the Harness to look up information outdoors without a remote desktop, you can install this plugin.
If you mainly operate the DeepSeek Harness on the same computer and do not need remote access, you do not need to install it.

Watch out — The sandbox test passed: it was installed in a fresh profile and registered into the harness profile. No obvious issues were found.

The verdict — I would install it because the plugin is available as a single npm package and the sandbox test confirmed successful registration in a fresh profile.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
Details
58

Desktop notifications for turn completions, with per-outcome controls and keyword rules.

Installed cleanly when we ran it

GitHub sourceJavaScript5d ago

AI review

dsh-notification

What it is — DeepSeek Harness session completions trigger browser desktop notifications

Who it is for — Users performing sessions in the DeepSeek Harness web GUI need to know when they complete even after switching tabs. Users who only run locally should not install it since it is a browser client plugin.

Watch out — Sandbox test passed: installed into fresh profile and registered by harness. Notifications require browser Notification permission and the page to remain open. Notifications only match the last turn content and use flat text body.

The verdict — I would install it because it provides UI-only notifications without affecting the model, with the premise that browser Notification permission must be granted and the page kept open.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details

Open DSH workspace directories in VS Code directly from the web GUI.

Did not install when we ran it

npm packageJavaScript5d ago

AI review

dsh-open-in-vscode

What it is — Adds an Open in VS Code menu to workspace rows in the DeepSeek Harness web GUI sidebar.

Who it is for — When managing workspaces in the DeepSeek Harness web GUI and needing to open a directory in VS Code, this plugin is suitable. Users who manage workspaces solely with command line tools without the web GUI do not need it.

Watch out — Sandbox test failed: after installation, Harness did not register the plugin into the profile. No other obvious pitfalls were found.

The verdict — Because the sandbox test shows it fails to register into the profile after installation, I would not install it until Harness can register it successfully.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details

plugin-notify

whyihaveyou

37

IM webhook and local notifications on turn completion, errors, or approval (Feishu/WeCom/DingTalk/Slack/Discord/custom).

No one-line install — this plugin lives inside a larger repository and publishes no npm package.

GitHub sourceHTML3d ago

AI review

plugin-notify

What it is — Sends notifications via IM webhooks and local systems when turns complete, errors occur, or approvals are pending.

Who it is for — When using DeepSeek Harness for turn completion, errors, or approval notifications, users needing instant results should install this plugin. If not involving external IM integration, users can skip this plugin.

Watch out — This is a subdirectory plugin with no single command install. Manual allowance of shell script execution is required from source builds. It executes shell commands and requires API key or token. No sandbox testing was conducted.

The verdict — I would install it because it handles notifications for turn completion and errors in agent workflows, but only if external IM integration is necessary.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Details

dsh-notifier

THEWOLFWALKER

35

Unified notification & remote control for DSH: one `notify()` API, 25+ channels (Telegram / DingTalk / Feishu / WeCom / QQ bot / WxPusher / PushPlus / ServerChan / Bark / Discord / Slack / ntfy / webhook...), level routing (timeSensitive / active / passive) with tiered retry, multi-channel inbound approval (Telegram buttons, Feishu cards, QQ, WxPusher, WeChat iLink), official QR login for QQ/DingTalk/Feishu, a local web admin console, multi-agent routing, desktop notifications — and a mobile command center: `!status` / `!stop` / `!retry` agent control from your phone plus actionable notifications (view result / retry / logs buttons that call back into the agent). Secrets redacted, tool rate-limited, zero runtime deps — plus an open event source: other plugins can inject the notifier service (ctx.notifier) and subscribe to dsh-notifier/sent events, reusing notification without coupling.

Installed cleanly when we ran it

npm packageJavaScript3d ago

AI review

dsh-notifier

What it is — DSH plugin providing notify() API and mobile remote command center.

Who it is for — When using DSH agent for notification push and remote control, this plugin applies. If you do not wish to integrate multi-channel inbound approval, this plugin is unnecessary.

Watch out — Sandbox test shows the plugin can be installed, but the protobufjs@7.6.5 build script is blocked by pnpm, users need to manually allow it to complete registration. No other obvious issues found.

The verdict — I would install it because it provides mobile command center and multi-channel notifications, but the build script must be manually allowed when installing from source.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details

dsh-lark

omdsh-dev

30

Lark/Feishu bot channel for DeepSeek Harness: each chat drives its own agent, and tool approvals, model questions, and plan reviews return as cards answered by a button or a reply. Switch workspace and model from the chat (`/cd`, `/model`, `/new`), and run several bots that keep separate sessions and can hand turns to each other in one group.

Installed cleanly when we ran it

npm packageTypeScript3d ago

AI review

dsh-lark

What it is — DeepSeek Harness Lark/Feishu plugin: integrates chats to drive agents with card-based approvals.

Who it is for — Users collaborating multiple DeepSeek Harness agents in one Lark/Feishu group chat benefit from independent sessions and turn handoff. Users who do not use Lark or Feishu as integration channels can skip this plugin because they lack the chat environment.

Watch out — No public server or callback configuration needed. Tested and registered successfully in a new profile. No obvious issues found.

The verdict — I would install it because no public server or callback configuration is required.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
Details