dshbase

Plugin directory / Developer / dsh-docker

dsh-docker

Verified · install-tested on dsh STARDUSTLC666

✓ Actively maintained Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

4Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-16Last push
Cross-platformPlatform

What it does

DeepSeek Harness container management plugin: docker_ps/logs/inspect/exec/manage five tools, official subprocess service, argv no shell injection, exec approval gate, zero runtime dependencies. · Containers for DeepSeek Harness agents.

✅
Our take
Works — verified, early-stage project

DeepSeek Harness container management plugin: docker_ps/logs/inspect/exec/manage five tools, official subprocess service, argv no shell injection, exec approval gate, zero runtime dependencies. · Containers for DeepSeek Harness agents. It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

English

dsh-docker

你的 agent 会管容器了:六个工具覆盖容器/镜像列表、日志、详情、容器内执行与生命周期管理。

DSH(DeepSeek Harness)容器管理插件:走官方 subprocess 服务跑 docker CLI,argv 数组无 shell 注入,docker_exec 默认审批门,零运行时依赖。

npm version npm downloads license stars

Awesome DSH Plugin

安装

dsh plugin --profile web add @stardustlc/dsh-docker

需要本机装有 Docker(docker version 能出结果即可);不在 PATH 上时用 dockerPath 指定。

配置

- id: docker
  name: '@stardustlc/dsh-docker'
  config:
    # dockerPath: C:\Program Files\Docker\Docker\resources\bin\docker.exe
    dockerPath: docker     # 可选;也可用环境变量 DSH_DOCKER_PATH
    timeoutMs: 60000       # 单次操作超时(默认 60 秒,5 秒 - 10 分钟)
    # execApproval: false  # 关闭 docker_exec 审批门(默认 true)

工具一览

工具 作用 安全
docker_ps 列出容器(状态/镜像/运行态,可过滤) —
docker_images 列出本地镜像(仓库/标签/大小/创建时间,可只看悬空镜像) —
docker_logs 查看日志尾部(行数钳制,可短时 follow) —
docker_inspect 容器详情(镜像/状态/端口) —
docker_exec 容器内执行命令 审批门 + 容器名白名单校验
docker_manage start / stop / restart / rm 明确提示破坏性

示例

docker_ps {}
docker_ps { all: true, name: web }
docker_images { dangling: true }
docker_logs { container: web, tail: 200 }
docker_inspect { container: web }
docker_exec { container: web, command: 'df -h' }
docker_manage { container: web, action: restart }

安全设计

  • 无 shell:全部参数独立 argv 数组,命令注入不可能
  • 审批门:docker_exec 默认弹审批(对齐 dsh-email / dsh-sql),headless 无审批通道时拒绝
  • 容器名校验:只允许 [A-Za-z0-9][A-Za-z0-9_.:-]*,杜绝参数注入
  • 超时钳制:单次操作 5 秒 - 10 分钟;follow 模式额外限 30 秒
  • 日志钳制:tail 1-2000 行

开发

pnpm install
pnpm test       # 构建 + 24 个测试

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-docker for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:STARDUSTLC666/dsh-docker

Headless (CLI) profile:

dsh plugin --profile headless add github:STARDUSTLC666/dsh-docker

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7797 plugins →