acryldev/acryl
C3ACRYL - Agent Context Relay Yielding Lifecycles. One persistent workspace, one canonical context, any coding agent.
★ 100+ · acryldev/acryl source on GitHub · this plugin in the registry
acryldev/acryl is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, can rewrite the system prompt, can spawn subprocesses, gates tool execution.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| patches the dsh runtime | runtime_patch | ./cordis.patch.yml |
| can rewrite the system prompt | prompt_surface | subprocess, systemPrompt, webServer, system-prompt/assemble, tools/pre-execute |
| can spawn subprocesses | subprocess_service | inject: subprocess |
| gates tool execution | tool_gate | hook: tools/pre-execute |
| executes system commands | exec | ×38 in authored code, e.g. distribution/acryl-npm-launcher/bin.js:2, distribution/acryl-npm-launcher/bin.js:16 |
| decodes base64 payloads | base64_decode | ×1 in authored code, e.g. apps/acryl-desktop/src/native-ui/recovery/App.tsx:275 |
| reads credential-class env vars in development tooling the package does not ship | token_env_tooling | in development tooling the package does not ship: DEEPSEEK_API_KEY |
Services it injects
appExit appInstance commands connection desktopPnpmBootstrap desktopProfiles desktopRuntime greeter llm loader locale remote sessions settings settingsScope shortcuts sidebarRightTabs skills slots speller subprocess systemPrompt theme tools uiWorkspace webRuntime webServer workspaceTabs workspaces
Hooks it attaches
agent/pre-step agent/request example/hello llm/stream session/event settings/updated system-prompt/assemble theme/change tools/pre-execute webserver/index-inject
Outbound domains
electronjs.org www.dshdesktop.cn api.github.com acryl.dev
Environment variables it reads
DSH_HOME ACRYL_PROFILE ACRYL_SURFACE ACRYL_LOG_LEVEL DSH_TELEMETRY_DISABLED ACRYL_EXTENSION_DOCS ACRYL_PLUGIN_WATCH ACRYL_STAGE_DEBUG
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.