# @deepseek-ai/dsh-base

> The shared dsh core as a profile bundle: every profile's first patch layer, inserting the base plugin rows over the empty profile root

Latest version **0.0.1-rc.1** (published 2026-08-10) · BSD-3-Clause license · 0 weekly downloads

## Install

```sh
npm install @deepseek-ai/dsh-base
pnpm add @deepseek-ai/dsh-base
yarn add @deepseek-ai/dsh-base
bun add @deepseek-ai/dsh-base
```

## Health

**Score 75/100 (B)** — status: active.

Positive: has types; esm support; no vulnerabilities; recently updated; high maintenance score; popular repo; extremely popular.

Warnings: low downloads; pre 1.0.

## Facts

| | |
|---|---|
| Version | 0.0.1-rc.1 |
| Published | 2026-08-10 |
| First published | 2026-08-10 |
| Weekly downloads | 0 |
| License | BSD-3-Clause |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 79 |
| Unpacked size | 34.1 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 232255 |
| Maintainers | imccyu, tianyicui-deepseek |

## Links

- npm: https://www.npmjs.com/package/@deepseek-ai/dsh-base
- Repository: https://github.com/deepseek-ai/deepseek-harness
- Homepage: https://github.com/deepseek-ai/deepseek-harness#readme
- Issues: https://github.com/deepseek-ai/deepseek-harness/issues
- npm.io page: https://npm.io/package/@deepseek-ai/dsh-base

## Dependencies (79)

- [@deepseek-ai/dsh-llm](https://npm.io/package/@deepseek-ai/dsh-llm.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-web](https://npm.io/package/@deepseek-ai/dsh-web.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-goal](https://npm.io/package/@deepseek-ai/dsh-goal.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-agent](https://npm.io/package/@deepseek-ai/dsh-agent.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-skill](https://npm.io/package/@deepseek-ai/dsh-skill.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tools](https://npm.io/package/@deepseek-ai/dsh-tools.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session](https://npm.io/package/@deepseek-ai/dsh-session.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-fs](https://npm.io/package/@deepseek-ai/dsh-tool-fs.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-bash-env](https://npm.io/package/@deepseek-ai/dsh-bash-env.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-commands](https://npm.io/package/@deepseek-ai/dsh-commands.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-fs-local](https://npm.io/package/@deepseek-ai/dsh-fs-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subagent](https://npm.io/package/@deepseek-ai/dsh-subagent.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-web](https://npm.io/package/@deepseek-ai/dsh-tool-web.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-fs-policy](https://npm.io/package/@deepseek-ai/dsh-fs-policy.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-llm-pi-ai](https://npm.io/package/@deepseek-ai/dsh-llm-pi-ai.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-llm-retry](https://npm.io/package/@deepseek-ai/dsh-llm-retry.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-plan-mode](https://npm.io/package/@deepseek-ai/dsh-plan-mode.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-bash](https://npm.io/package/@deepseek-ai/dsh-tool-bash.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-goal](https://npm.io/package/@deepseek-ai/dsh-tool-goal.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-pwsh](https://npm.io/package/@deepseek-ai/dsh-tool-pwsh.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-todo](https://npm.io/package/@deepseek-ai/dsh-tool-todo.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-agent-loop](https://npm.io/package/@deepseek-ai/dsh-agent-loop.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-fs-sandbox](https://npm.io/package/@deepseek-ai/dsh-fs-sandbox.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-permission](https://npm.io/package/@deepseek-ai/dsh-permission.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-ralph](https://npm.io/package/@deepseek-ai/dsh-tool-ralph.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-skill](https://npm.io/package/@deepseek-ai/dsh-tool-skill.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-tasks](https://npm.io/package/@deepseek-ai/dsh-tool-tasks.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-api-gateway](https://npm.io/package/@deepseek-ai/dsh-api-gateway.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-skill-badge](https://npm.io/package/@deepseek-ai/dsh-skill-badge.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-skill-local](https://npm.io/package/@deepseek-ai/dsh-skill-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-spill-local](https://npm.io/package/@deepseek-ai/dsh-spill-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tasks-local](https://npm.io/package/@deepseek-ai/dsh-tasks-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-token-meter](https://npm.io/package/@deepseek-ai/dsh-token-meter.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-bash-sandbox](https://npm.io/package/@deepseek-ai/dsh-bash-sandbox.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-command-goal](https://npm.io/package/@deepseek-ai/dsh-command-goal.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-goal-session](https://npm.io/package/@deepseek-ai/dsh-goal-session.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-llm-deepseek](https://npm.io/package/@deepseek-ai/dsh-llm-deepseek.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-pwsh-sandbox](https://npm.io/package/@deepseek-ai/dsh-pwsh-sandbox.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-spill-policy](https://npm.io/package/@deepseek-ai/dsh-spill-policy.md) ^0.0.1-rc.1
- [@deepseek-ai/cordis-plugin-hmr](https://npm.io/package/@deepseek-ai/cordis-plugin-hmr.md) ^1.0.16-rc.1
- [@deepseek-ai/dsh-compact-basic](https://npm.io/package/@deepseek-ai/dsh-compact-basic.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-sandbox-local](https://npm.io/package/@deepseek-ai/dsh-sandbox-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-title](https://npm.io/package/@deepseek-ai/dsh-session-title.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subagent-fork](https://npm.io/package/@deepseek-ai/dsh-subagent-fork.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-system-prompt](https://npm.io/package/@deepseek-ai/dsh-system-prompt.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-subagent](https://npm.io/package/@deepseek-ai/dsh-tool-subagent.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-workflow](https://npm.io/package/@deepseek-ai/dsh-tool-workflow.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-typert-loader](https://npm.io/package/@deepseek-ai/dsh-typert-loader.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-user-approval](https://npm.io/package/@deepseek-ai/dsh-user-approval.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-sandbox-policy](https://npm.io/package/@deepseek-ai/dsh-sandbox-policy.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-settings-local](https://npm.io/package/@deepseek-ai/dsh-settings-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subagent-codex](https://npm.io/package/@deepseek-ai/dsh-subagent-codex.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subagent-spawn](https://npm.io/package/@deepseek-ai/dsh-subagent-spawn.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-timeout-policy](https://npm.io/package/@deepseek-ai/dsh-timeout-policy.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-fs-search](https://npm.io/package/@deepseek-ai/dsh-tool-fs-search.md) ^0.0.1-rc.1
- [@deepseek-ai/cordis-plugin-timer](https://npm.io/package/@deepseek-ai/cordis-plugin-timer.md) ^1.1.3-rc.1
- [@deepseek-ai/dsh-command-compact](https://npm.io/package/@deepseek-ai/dsh-command-compact.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-typert-registry](https://npm.io/package/@deepseek-ai/dsh-typert-registry.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-attachment-local](https://npm.io/package/@deepseek-ai/dsh-attachment-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-command-feedback](https://npm.io/package/@deepseek-ai/dsh-command-feedback.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subprocess-local](https://npm.io/package/@deepseek-ai/dsh-subprocess-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-user-interaction](https://npm.io/package/@deepseek-ai/dsh-user-interaction.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-credentials-local](https://npm.io/package/@deepseek-ai/dsh-credentials-local.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-repeat-tool-guard](https://npm.io/package/@deepseek-ai/dsh-repeat-tool-guard.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-workspace-context](https://npm.io/package/@deepseek-ai/dsh-workspace-context.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-projection](https://npm.io/package/@deepseek-ai/dsh-session-projection.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-agent-default-model](https://npm.io/package/@deepseek-ai/dsh-agent-default-model.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-web-search-deepseek](https://npm.io/package/@deepseek-ai/dsh-web-search-deepseek.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-query-sqlite](https://npm.io/package/@deepseek-ai/dsh-session-query-sqlite.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-subagent-claude-code](https://npm.io/package/@deepseek-ai/dsh-subagent-claude-code.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-subagent-report](https://npm.io/package/@deepseek-ai/dsh-tool-subagent-report.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-subagent-control](https://npm.io/package/@deepseek-ai/dsh-tool-subagent-control.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-workflow-workerthread](https://npm.io/package/@deepseek-ai/dsh-workflow-workerthread.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-telemetry-otel](https://npm.io/package/@deepseek-ai/dsh-session-telemetry-otel.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-tool-str-replace-editor](https://npm.io/package/@deepseek-ai/dsh-tool-str-replace-editor.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-compact-tool-result-prune](https://npm.io/package/@deepseek-ai/dsh-compact-tool-result-prune.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-checkpoint-policy](https://npm.io/package/@deepseek-ai/dsh-session-checkpoint-policy.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-persistence-jsonl](https://npm.io/package/@deepseek-ai/dsh-session-persistence-jsonl.md) ^0.0.1-rc.1
- [@deepseek-ai/dsh-session-title-first-message-llm](https://npm.io/package/@deepseek-ai/dsh-session-title-first-message-llm.md) ^0.0.1-rc.1

## Recent versions

- 0.0.1-rc.1 (latest) — 2026-08-10
- 0.1.7-rc.2 (next) — 2026-09-24
- 0.1.7-alpha.2 (alpha) — 2026-09-22
- 0.1.7-rc.1 — 2026-09-23
- 0.1.7-alpha.1 — 2026-09-22
- 0.1.5-rc.3 — 2026-09-22
- 0.1.6-alpha.2 — 2026-09-17
- 0.1.6-alpha.1 — 2026-09-15
- 0.1.5-rc.2 — 2026-09-10
- 0.1.5-rc.1 — 2026-09-10
- 0.1.5-alpha.2 — 2026-09-09
- 0.1.5-alpha.1 — 2026-09-08
- 0.1.3-alpha.2 — 2026-09-07
- 0.1.2-rc.1 — 2026-09-03
- 0.1.2-alpha.5 — 2026-09-02
- … 13 more at https://npm.io/package/@deepseek-ai/dsh-base/versions

## README

# `@deepseek-ai/dsh-base`

English | [中文](README.zh.md)

The shared dsh core as a profile bundle: [`cordis.patch.yml`](cordis.patch.yml) inserts every base plugin row — model adapters, the shared [`agent-default-model`](../../core/agent-default-model/README.md) selection, tools, persistence, policy, settings/credentials, telemetry, and host-level subagent providers — over the empty profile root, as the first layer of every profile's `dsh.profile.bundles` list. Codex and Claude Code providers load dormant; Agent Presets independently decide whether their agent contributes either model-facing delegation tool. Later bundle layers (e.g. [`dsh-web-app`](../web-app/README.md)) and the user's profile `cordis.patch.yml` override these rows by id; a patch replaces a row's whole `config`, so mode-specific values live in mode bundles, not here. The package has no runtime API; the profile composer resolves the patch through the `dsh.bundle.patch` manifest field, never through code.

Windows hosts booting a shipped profile additionally receive [`windows.cordis.patch.yml`](windows.cordis.patch.yml): it disables the POSIX-only bash stack (`bash-sandbox`/`tool-bash`) and inserts the sandbox-confined PowerShell stack (`@deepseek-ai/dsh-pwsh-sandbox`, `@deepseek-ai/dsh-tool-pwsh`). The permission surface stays exactly as on POSIX: `sandbox`/`sandbox-policy` enforce the file-effect policy through the Windows ACL restricted-token runner (the win32 chain of `dsh-sandbox-local` → `@deepseek-ai/dsh-sandbox-windows-acl`), the permission switcher and the approval service run unchanged, and `fs-sandbox` keeps fencing `ctx.fs` writes — mounting `dsh-fs-local` alongside it would double-register `ctx.fs` and fail the load. The launcher applies the layer between the bundle layers and the user layers on win32 hosts; a Windows host that prefers the unconfined local pwsh executor or full access overrides these rows through its profile or home `cordis.patch.yml` (the bash-restore recipe must be complete: disable `pwsh-sandbox`/`tool-pwsh` AND re-enable `bash-sandbox`/`tool-bash` — both executor families register the same `bash` service, so an incomplete recipe fails loud at load). POSIX hosts never receive it.

The row set and its rationale are documented inline in the patch file; the [generated composition graph](../../../apps/cli/composition.md) renders it.

## Model Experience

Indirectly, through the inserted rows: this bundle selects the shipped persona-less prompt base, tool set, and DeepSeek adapter that mode bundles specialize, and contributes no model-visible text of its own.

#### KV Cache effect

None directly; each inserted row's package owns its effect.

## Known Limitations and Deferred Work

- **A patch replaces whole row configs** — profile overrides must restate every field a row keeps; there is no deep-merge layer.
- **Claude's SDK platform CLI remains in the Profile install closure** — the base bundle depends on the Claude provider, whose production path resolves the host `claude`; removing the SDK's unused optional payload is deferred to the product installation-closure follow-up.
- **The Windows temp grant is a private per-session subdirectory** — `workspace-write` confines writes to the workspace plus the session's own temp subdirectory (`<temp>\dsh-<hash>`, TMP/TEMP rewritten for confined children); `read-only` grants nothing. See `@deepseek-ai/dsh-sandbox-windows-acl`.

---
_Source: https://npm.io/package/@deepseek-ai/dsh-base · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
