riesbri/dshline

C3

Terminal-native frontend for DeepSeek Harness with real scrollback; a direct, in-process consumer of Harness capabilities.

★ 10+ · riesbri/dshline source on GitHub · this plugin in the registry

riesbri/dshline is a DeepSeek Harness plugin rated C3 — powerful capability combined with sensitive behavior. It patches the dsh runtime, executes system commands, decodes base64 payloads, reads credential-class env vars.

Installable plugin — declares a dsh.bundle manifest

What it can do

CapabilityFlagEvidence
patches the dsh runtimeruntime_patch['./cordis.patch.yml', './presets/standard.patch.yml', './presets/minimal.patch.yml']
executes system commandsexec×39 in authored code, e.g. tools/capability-report.mjs:25, tools/capability-report.mjs:25
decodes base64 payloadsbase64_decode×1 in authored code, e.g. tools/harness-sync.mjs:302
reads credential-class env varstoken_envGH_TOKEN
powerful capability in test/example code onlydev_surfacein code that does not ship: system-prompt/assemble

Services it injects

agents cmdlineArgs commands llm tools tuiStartup userQuestions

Hooks it attaches

agent/assistant-stream agent/created agent/disposed agent/status approval/request commands/change credentials/record-updated credentials/reference-updated goal/activation-changed llm/adapters-updated permission-presets/catalog-changed session/event settings/document-updated subagent/end subagent/start tui/render user-questions/request workflow/agent-start workflow/end workflow/log workflow/phase

Outbound domains

api.github.com www.unicode.org astral.sh

Environment variables it reads

RELEASE_ROOT RELEASE_TAG CONSUMER_SMOKE_STORE_DIR TMUX GITHUB_STEP_SUMMARY PR_BODY_PATH GITHUB_OUTPUT GITHUB_API_URL GITHUB_REPOSITORY GH_TOKEN

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.