dshbase

Plugin directory / Developer / dsh-subprocess-inherit-environment

dsh-subprocess-inherit-environment

Verified · install-tested on dsh zhangzujian

✓ Actively maintained

View on GitHub ↗ ← Back to plugin directory

2Stars
0Forks
0Open issues
JavaScriptLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

DSH plugin that forwards the complete Harness environment through ctx.subprocess

✅
Our take
Works — verified, early-stage project

DSH plugin that forwards the complete Harness environment through ctx.subprocess It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

dsh-subprocess-inherit-environment

A removable DeepSeek Harness / DSH plugin that deliberately forwards the
Harness process's complete environment through the ctx.subprocess service.

Security warning

This plugin disables DSH's subprocess credential isolation. Every caller
that uses the wrapped subprocess service can pass the Harness process's API
keys, tokens, passwords, secrets, cookies, proxy credentials, and other
environment values to child processes. Model-generated commands, repository
scripts, package installers, CLIs, MCP servers, and terminal programs may read
or exfiltrate those values.

Do not install this plugin on a shared or untrusted Harness deployment. Prefer
a dedicated tool or an exact variable allowlist whenever possible.

The plugin never logs environment names or values by itself. That does not
prevent a child process from printing or transmitting them.

Behavior

DSH normally starts subprocesses from a scrubbed parent environment. Variable
names matching KEY, PASSWORD, SECRET, or TOKEN, plus ambient DSH_*
names, are removed before explicit request entries are merged.

This plugin wraps the three ctx.subprocess operations and supplies an
explicit environment layer built from process.env:

  • resolveExecutable(command, env, signal)
  • spawn(spec)
  • spawnTerminal(spec)

All three operations must be functions. Own method descriptors must be
configurable; inherited methods and an absent installation marker require an
extensible runtime; an existing marker slot must be configurable. Apply checks
that complete replacement contract before mutation. If defining the marker or
any method still fails, or Cordis rejects effect registration, apply rolls back
the marker and every installed method descriptor before rethrowing the error.

Caller-provided entries are merged after a fresh process.env spread on every
call, so explicit overrides and undefined tombstones retain their original
meaning. The plugin does not mutate caller-owned requests.

Disposal first makes every installed wrapper inactive, then restores previous
method descriptors when the plugin still owns them. A later wrapper that
captured and delegates to a plugin method therefore reaches the original DSH
method with the caller's exact arguments after disposal, without environment
injection. Later method replacements are not overwritten. Installing this
plugin more than once on the same subprocess runtime is rejected while the
first installation is active, avoiding ambiguous out-of-order teardown.

The plugin covers consumers that route process creation through
ctx.subprocess. It cannot affect code that bypasses that service and calls
Node.js process APIs, worker APIs, or an SDK-owned spawn directly.

Install into a DSH profile

Until this package is published to npm, clone it and add the local directory:

git clone https://github.com/zhangzujian/dsh-subprocess-inherit-environment.git
cd dsh-subprocess-inherit-environment
npx @deepseek-ai/[email protected] plugin --profile web add "$PWD"

The package declares a DSH bundle, so dsh plugin adds its patch layer to the
profile automatically. Restart DSH if the active profile does not hot-reload
server plugins.

To remove it and restore DSH's default credential scrub:

npx @deepseek-ai/[email protected] plugin --profile web remove @zhangzujian/dsh-subprocess-inherit-environment

For a local file URL overlay:

- insert:
    - id: subprocess-inherit-environment
      name: file:///absolute/path/to/dsh-subprocess-inherit-environment/index.mjs

Test

Unit tests require Node.js 22 or newer:

npm test

Integration tests run against an installed DSH tree and verify the original
scrub, inherited environment, and disposal restoration without printing any
secret value:

DSH_INSTALL_DIR=/path/to/dsh/install npm run test:integration

DSH_INSTALL_DIR is the directory containing node_modules/@deepseek-ai.

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-subprocess-inherit-environment for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:zhangzujian/dsh-subprocess-inherit-environment

Headless (CLI) profile:

dsh plugin --profile headless add github:zhangzujian/dsh-subprocess-inherit-environment

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7797 plugins →