myYangyunfan/dsh_desktop
C3DeepSeek Harness (dsh) Windows desktop client - bundled Node.js + dsh CLI, one-click launch
★ 500+ · myYangyunfan/dsh_desktop source on GitHub · this plugin in the registry
myYangyunfan/dsh_desktop is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It runs code at install time, can rewrite the system prompt, can spawn subprocesses, executes system commands.
Installable plugin — declares a dsh.bundle manifest
What it can do
| Capability | Flag | Evidence |
|---|---|---|
| runs code at install time | install_script | postinstall: node scripts/install-kernel.mjs && node scripts/patch-deps.js |
| can rewrite the system prompt | prompt_surface | subprocess, systemPrompt, webServer, system-prompt/assemble |
| can spawn subprocesses | subprocess_service | inject: subprocess |
| executes system commands | exec | ×29 in authored code, e.g. dsh-desktop/scripts/check-syntax.js:12, dsh-desktop/scripts/check-syntax.js:12 |
| eval in build output only | eval_bundled | ×2 in build output only, e.g. dsh-desktop/assets/plugins/dsh-super-injector/lib/index.js:1438, dsh-desktop/assets/plugins/dsh-super-injector/lib/index.js:1494 |
| decodes base64 payloads | base64_decode | ×2 in authored code, e.g. dsh-desktop/scripts/desktop-backup.js:340, dsh-desktop/assets/plugins/dsh-better-sidebar/src/client/editor-load.ts:39 |
| network server in build output only | net_server_bundled | ×1 in build output only, e.g. dsh-desktop/assets/plugins/dsh-pocket/lib/proxy.mjs:717 |
| reads credential-class env vars | token_env | DASHSCOPE_API_KEY, DEEPSEEK_API_KEY, DSH_VISION_API_KEY, OPENCLAW_BRIDGE_QQ_TOKEN_URL, OPENCLAW_BRIDGE_TOKEN, OPENCODE_API_KEY |
Services it injects
agentDefaultModel agentLoop agents attachments commandUi connection conversation credentials invariants layout llm loader locale modelDirectories modules remote sessionLogDownload sessionProjections sessions settings settingsScope skills slots subprocess systemPrompt timer tools webRuntime webServer workspaceRegistry workspaces
Hooks it attaches
agent/created agent/inbox/claimed agent/inbox/inserted agent/pre-step agent/request agent/session-start agent/status internal/service llm/adapters-updated llm/stream session/created session/disposed session/event system-prompt/assemble
Outbound domains
api.deepseek.com open.bigmodel.cn opencode.ai api.github.com gitee.com gh-proxy.com api.openai.com api.anthropic.com deepseek1024.com ghfast.top
Environment variables it reads
DSH_HOME USERPROFILE DSH_LLM_DUMP_DIR DSH_CRASH_SHIELD_ARMED DEEPSEEK_BALANCE_URL DEEPSEEK_API_BASE CARDian_LOG_LEVEL APPDATA DSH_CLIENT_APP_DIR DSH_CLIENT_PLUGINS_DIR
How to read this
Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.
Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.