One line: DeepSeek Harness agent in WSL, chat in a Windows browser — install this kit when paths, proxy, clipboard, and “open that file” must cross the OS boundary.
This is a meta-repo (docs + install script + cordis.patch.yml). It does not ship plugin runtimes. Each plugin repo ships a homepage README.md (often Chinese-first for newer plugins) plus README.en.md / README.zh.md as needed.
The kit is not a runtime. install.sh loads Daily / GitHub / LLM / Full plugins into the dsh web profile. Chat stays on Windows; the agent and tools stay in WSL. A second tier of Linux/local capability plugins (inference, search, media, read-only DevOps, …) is not in install.sh — use link-linux-plugins.sh or dsh plugin add as needed. IM / Obsidian / Jev are likewise off install.sh.
flowchart TB
subgraph win [Windows]
browser["Browser :3081/?token="]
host["Clipboard / Explorer / default browser"]
vault["Obsidian vault (NTFS)"]
localLLM["Ollama / llama.cpp / vLLM"]
end
subgraph wslbox [WSL]
relay["port relay"]
dsh["dsh web :3080"]
subgraph kitPlugins [install.sh suites]
daily["Daily: env net fetch open clipboard path browser launch"]
guards["repeat-stop + tool-budget"]
more["GitHub / LLM / Full doctors"]
end
subgraph linuxOpt [Optional Linux local · not in install.sh]
infer["ollama · llamacpp · vllm · vecmem"]
media["media · search · secret · struct"]
devops["git · tmux · compose · k8s · helm · terraform · …"]
desk["playwright · mail · cal · pkg · rclone · db · glab"]
end
im["dsh-wsl-im — optional"]
obsidian["dsh-wsl-obsidian — optional"]
jev["dsh-wsl-jev — optional"]
end
api["DeepSeek API"]
chats["Feishu / WeCom / DingTalk / QQ / Slack / Discord / Telegram"]
browser --> relay --> dsh
dsh --> kitPlugins
dsh --> linuxOpt
dsh --> api
linuxOpt --> localLLM
kitPlugins --> host
chats --> im --> dsh
obsidian --> vault
dsh --> obsidian
dsh --> jev
| Boundary | Who owns it |
|---|---|
| Windows UI | Browser on :3081 with a one-shot ?token= (bare :3081 is 401; :3080 is WSL-only) |
| Agent | dsh web inside WSL, tools via plugin ctx |
| Cross-OS Daily | path / open / clipboard / browser / launch / net / fetch (KIT_SET=daily) |
| Linux local optional | Inference, media, sandboxed search, secrets, read-only DevOps — see docs/OPTIONAL_PLUGINS.md; bash scripts/link-linux-plugins.sh |
| IM | dsh-wsl-im outbound WS/Stream/Gateway → ctx.agents. One workspace per IM, one session per chat |
| Obsidian | dsh-wsl-obsidian: WSL agent ↔ Windows NTFS vault + obsidian:// |
| Jev | dsh-wsl-jev: System One (jev_ask / check / rank) via OpenRouter or TypeSafe |
Sibling checkout versions on 2026-09-18. Floors enforced by scripts/check-plugin-versions.sh are the minimum, not this snapshot.
Local dsh line: 0.2.0-rc.2 (npm @next, 2026-09-29). npm latest still points at the 0.1.7 line; @next carries 0.2.0. Scripts still assume dsh ≥0.1.2.
| Plugin | Version | Set |
|---|---|---|
| dsh-wsl-env | 0.3.0 | daily |
| dsh-wsl-net | 0.5.2 | daily |
| dsh-wsl-fetch | 0.1.2 | daily |
| dsh-wsl-open | 0.2.0 | daily |
| dsh-repeat-stop | 0.1.2 | daily |
| dsh-tool-budget | 0.1.2 | daily |
| dsh-wsl-clipboard | 0.1.0 | daily |
| dsh-wsl-path | 0.2.0 | daily |
| dsh-wsl-browser | 0.1.0 | daily |
| dsh-wsl-launch | 0.1.0 | daily |
| Plugin | Version | Set |
|---|---|---|
| dsh-wsl-github | 0.2.0 | github |
| dsh-wsl-cred | 0.2.0 | github |
| dsh-wsl-notify | 0.1.0 | github |
| dsh-wsl-im | 0.3.8 | not in install.sh |
| dsh-wsl-obscura | 0.1.0 | not in Daily |
| dsh-wsl-obsidian | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-jev | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-ollama | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-media | 0.2.0 | not in install.sh (optional) |
| dsh-wsl-search | 0.2.0 | not in install.sh (optional) |
| dsh-wsl-vecmem | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-k8s | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-secret | 0.2.0 | not in install.sh (optional) |
| dsh-wsl-llamacpp | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-vllm | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-struct | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-git | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-tmux | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-compose | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-systemd | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-helm | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-terraform | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-rclone | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-db | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-glab | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-playwright | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-mail | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-cal | 0.1.0 | not in install.sh (optional) |
| dsh-wsl-pkg | 0.1.0 | not in install.sh (optional) |
| Plugin | Version | Plugin | Version |
|---|---|---|---|
| gpu | 0.2.2 | port | 0.2.2 |
| distro | 0.2.0 | workspace | 0.2.0 |
| picker | 0.1.0 | tray | 0.2.4 |
| expose | 0.2.2 | hostsvc | 0.4.3 |
| clock | 0.2.0 | dns | 0.2.0 |
| mnt | 0.2.0 | editor | 0.1.0 |
| shot | 0.1.0 | docker | 0.2.2 |
| ssh-agent | 0.2.0 | encoding | 0.2.0 |
| wslconfig | 0.2.0 | download | 0.2.0 |
Shared helper dsh-wsl-common 0.1.0 is a library, not a KIT_SET entry.
| Piece | Status |
|---|---|
| dsh | This machine on 0.2.0-rc.2 (npm @next, 2026-09-29). npm latest still points at the 0.1.7 line, so @next is what carries 0.2.0. Kit scripts assume dsh ≥0.1.2 UI launch tokens (?token= on :3081). The whole plugin suite was re-verified against 0.2.0-rc.2: every lib/ entry point imports, the offline smoke set is green, and the tracked floor versions are unchanged — no plugin code change was needed. |
| DeepSeek V4.1 Flash | Official API model id is deepseek-flash. Legacy deepseek-v4-flash / deepseek-v4-flash-vision-exp temporarily route to V4.1 Flash. Not configured by this kit — set under llm-deepseek / default model in ~/.dsh/settings.yaml. |
| Agent Teams | Opt-in experimental package (@deepseek-ai/dsh-experimental-agent-team-profile, same line as your dsh). Not part of install.sh. Expect longer “Deep diving” turns; use a fresh non-Teams session to smoke-test models. |
| Plugins | Snapshot: Plugin versions (sibling checkouts 2026-09-16). Floor: scripts/check-plugin-versions.sh. Daily includes dsh-wsl-fetch ≥0.1.1. |
- This Compatibility section is the suite matrix. Each plugin README has a matching Compatibility table (EN + ZH): minimum dsh ≥0.1.2, pointer here for latest verified, kit set, and notes that cloud Flash / Agent Teams are not owned by WSL plugins.
- When dsh ships a new line (e.g.
0.1.5GA or0.1.6), update this kit table first, then refresh plugin “currently …” lines (or re-run the suite doc sync). Do not invent per-plugin “verified” dates without a smoke pass. - API-sensitive plugins (
net,fetch,port,expose,tray,hostsvc) carry an extra Scope paragraph; thinner Daily tools keep the shared table only.
No kit code change is required solely for V4.1 Flash — update model ids in settings if you still default to retired names.
Prereq: dsh works inside WSL (profile usually web). Prefer 0.2.0-rc.2 (@next) or newer from the same train.
curl -fsSL https://raw.githubusercontent.com/173787247/dsh-wsl-kit/master/install.sh \
| KIT_SET=daily bashThen:
- Restart via
scripts/restart-dsh-web.sh(starts dsh on:3080and the Windows relay on:3081) - In Windows open the URL printed by
restart-dsh-web.sh(dsh ≥0.1.2 includes?token=; bare:3081is 401. Not:3080). Token is also written to/tmp/dsh-ui-url(WSL). - Open a new session (old sessions keep the old toolset)
- Optionally merge
cordis.patch.ymlinto your profile (a later pluginconfigreplaces the whole object — restate every key you still need)
| Want | Command |
|---|---|
| Daily (recommended) | KIT_SET=daily bash install.sh |
| Daily + GitHub App / credentials | KIT_SET=github bash install.sh |
| Local LLM + network doctor | KIT_SET=llm bash install.sh |
| Everything | KIT_SET=full bash install.sh (or omit KIT_SET — same as before) |
From a local clone: KIT_SET=daily bash install.sh
NODE_USE_ENV_PROXY=1,OLLAMA_API_KEYdefaultollamaNO_PROXY=127.0.0.1,localhostonly (do not inherit Clash RFC1918NO_PROXYglobs — they make Node skip the proxy and timeout onapi.deepseek.com)- Optional:
source "$HOME/.dsh/dsh-wsl-github.env"yourself before start when using GitHub App plugins
| Pain | Tool | Plugin |
|---|---|---|
| Proxy / Node 24 blocks DeepSeek or npm | net_doctor |
dsh-wsl-net |
web_fetch TypeError: fetch failed (API works) |
Install dsh-wsl-fetch ≥0.1.1 + restart-dsh-web.sh |
dsh-wsl-fetch |
| Open a Linux path from chat on Windows | (clickable paths) | dsh-wsl-open |
Path convert / slow /mnt/c |
path_convert |
dsh-wsl-path |
| Windows clipboard | wsl_clipboard |
dsh-wsl-clipboard |
| Open a PR / docs URL in Windows | win_open_url |
dsh-wsl-browser |
| Agent forgets it is in WSL | (system prompt inject) | dsh-wsl-env |
Daily = table above + win_launch + dsh-repeat-stop + dsh-tool-budget + dsh-wsl-fetch.
Smoke: in a new session ask “run net_doctor” and “copy this path to the Windows clipboard”. Prefer model deepseek-flash for cloud; keep Agent Teams off for first smoke.
| Set | Includes | Who |
|---|---|---|
| Daily | env, net, fetch, open, repeat-stop, tool-budget, clipboard, path, browser, launch | Most WSL + Windows-browser users |
| GitHub day | Daily + github + cred + notify | Also need PR/Actions status and git push credential hints |
| LLM | env, net, fetch, hostsvc, docker, dns, clock, gpu, port, expose, tray, open, path, browser | Local Ollama / vLLM / Unsloth + connectivity |
| Full | Everything in install.sh — Daily + GitHub extras + doctors, plus read-only Windows host observation (perf, service, eventlog, registry, defender, power) |
GPU/Docker/clock doctors, tray, portproxy, etc. |
| Desktop | uia, winshot, winctl, wininput — KIT_SET=desktop |
Want the agent to read and drive the Windows desktop |
Do not start with Full — get Daily working, then add plugins for specific pains.
Desktop is a separate set on purpose. dsh-wsl-wininput types and clicks,
dsh-wsl-winctl moves and closes windows; dsh-wsl-uia and dsh-wsl-winshot
are the observation half of the same pair. That is a different power level from
reading counters and an event log, so full never pulls it in.
GitHub from WSL is credentials + API + browser open + proxy — not one mega-plugin. After KIT_SET=github:
- Create the App per dsh-wsl-github (read-only Metadata / PRs / Actions; webhooks off)
- Before start:
source "$HOME/.dsh/dsh-wsl-github.env" - New session →
github_app_hint/github_repo_status; never paste PEM / PAT into chat
export HTTP_PROXY=http://127.0.0.1:7890 # or Clash mixed port, e.g. 16006
export HTTPS_PROXY=http://127.0.0.1:7890
export NODE_USE_ENV_PROXY=1
# Prefer restart-dsh-web.sh so NO_PROXY stays loopback-onlyStill failing → ask the agent to run net_doctor.
- API works,
web_fetchfails → dsh-wsl-fetch (Daily already installs it). - Third-party Workers / Cloudflare 403 (1010) via Clash → add a DIRECT rule for that host (plugin cannot override site WAF).
Local OpenAI-compatible backends on Windows: add dsh-wsl-hostsvc, run host_reach, merge examples/local-llm-providers.settings.yaml.
Connectivity, UI token 401, Ollama ctx, and fetch faults: docs/TROUBLESHOOTING.md (中文: TROUBLESHOOTING.zh.md).
Order of play: host_reach → net_doctor → dns_doctor → clock_doctor → workspace/mnt → expose (LAN only).
Which file is generated and which is handwritten, what each of the thirty-two scripts does and when to run it, and the invariants that keep twenty-six plugin copies from drifting: docs/MAINTENANCE.zh.md.
Expand all plugins
| Plugin | Role |
|---|---|
| dsh-wsl-env | Inject WSL/Windows facts into the system prompt |
| dsh-wsl-net | net_doctor |
| dsh-wsl-fetch | Proxy-aware web_fetch (undici ProxyAgent) |
| dsh-wsl-open | Open Linux paths from chat on Windows |
| dsh-repeat-stop | Hard-stop identical tool loops |
| dsh-tool-budget | Cap tool calls per session |
| dsh-wsl-clipboard | wsl_clipboard |
| dsh-wsl-path | path_convert |
| dsh-wsl-browser | win_open_url |
| dsh-wsl-launch | win_launch (allowlisted) |
| Plugin | Role |
|---|---|
| dsh-wsl-github | github_app_hint / github_repo_status |
| dsh-wsl-cred | cred_hint (no secrets) |
| dsh-wsl-notify | win_notify |
| Plugin | Role |
|---|---|
| dsh-wsl-gpu | gpu_doctor |
| dsh-wsl-port | port_doctor |
| dsh-wsl-distro | distro_info |
| dsh-wsl-workspace | wsl_workspace |
| dsh-wsl-picker | wsl_picker |
| dsh-wsl-tray | wsl_tray |
| dsh-wsl-expose | wsl_expose |
| dsh-wsl-hostsvc | host_reach |
| dsh-wsl-clock | clock_doctor |
| dsh-wsl-dns | dns_doctor |
| dsh-wsl-mnt | mnt_doctor |
| dsh-wsl-editor | win_editor |
| dsh-wsl-shot | win_shot |
| dsh-wsl-docker | docker_doctor |
| dsh-wsl-ssh-agent | ssh_agent_hint |
| dsh-wsl-encoding | encoding_doctor |
| dsh-wsl-wslconfig | wslconfig_hint |
| dsh-wsl-download | win_download |
Related: session-contract. Awesome listing snippet: awesome-wsl-kit.md.
Awesome status (2026-09-24): ~35 Daily/tool plugins on awesome main (including jev / obsidian). The 22 Linux-optional plugins are in PRs #5783–#5790 (CI green, awaiting merge). Queue: docs/AWESOME_QUEUE.zh.md. This kit meta-repo is not submitted to awesome — install via this repo / install.sh.
Do not reopen work that already shipped (fetch 0.1.2, obscura, version floors, 401 health, hostsvc apiReady, :3081 token relay). A new repo only for a new product. DingTalk does not get one.
Plan (2026-09-24): Keep Daily stable; ship new products as optional Linux/local plugins (Chinese homepage + README.en.md; read-only / double-gated by default). Full catalog + batch link → docs/OPTIONAL_PLUGINS.md · bash scripts/link-linux-plugins.sh. Awesome queue → docs/AWESOME_QUEUE.zh.md.
| Track | Plan | Status |
|---|---|---|
| Feishu / WeCom / DingTalk / QQ / Slack / Discord / Telegram / Mattermost | Deepen dsh-wsl-im; not in install.sh. |
0.3.8; queue docs/ENHANCEMENT_QUEUE.zh.md |
| Obsidian / Jev | obsidian · jev; not in install.sh. |
On awesome main; deepening |
| Local inference | ollama · llamacpp · vllm · vecmem | Repos open; see OPTIONAL_PLUGINS; deepening |
| Media / search / secrets / struct | media · search · secret · struct | Same |
| Read-only DevOps | git · tmux · compose · systemd · k8s · helm · terraform · rclone · db · glab | Deepening (not “repo-only”) |
| Desktop helpers | playwright · mail · cal · pkg | Deepening |
| Remote bridges | remote-ssh · mac-companion · device-bridge | awesome #5873 |
| MCP / OpenClaw / Agent Teams | Upstream or separate runtimes | Out of kit |
| Thin UX | editor / shot / notify / picker | Deepening (ENHANCEMENT_QUEUE Wave M) |
- Plugins share your Harness permissions (files, network, Windows via PowerShell/
cmd). win_launchis allowlisted;cred_hint/ GitHub App never dump secrets into chat.win_notifyblocks on a MessageBox — keep text short and secret-free.- Keep
*.envunder~/.dsh/atchmod 600; never commit API keys.
deepseek-harness · dsh-plugin · wsl · windows · github-app
MIT — same as the individual plugins.