Apache-2.0, Huawei Cloud-maintained DSH plugin that gives AI agents guided, safety-first Huawei Cloud operations with pre-run risk checks and sandbox deployment — every write needs user approval and secrets are auto-redacted.
DSH integration
Compatible
Author-claimed
Safety audit
Unaudited
Last verified
2026-09-05
License
Apache-2.0
01What can it help you accomplish?
Let AI coding agents use Huawei Cloud safely and accurately with cloud knowledge, CLI tooling, and safety guardrails
Step-by-step guidance for 20+ Huawei Cloud services with explicit-approval execution, redacted secrets, and pre-run risk checks
Developers and AI agents (DeepSeek Harness / DSH) that operate Huawei Cloud resources
Deploy and preview web apps on Huawei Cloud straight from a coding agent
A temporary cloud sandbox (DevStation) that runs web apps with an instant public URL preview
Teams that need ephemeral cloud runtimes to ship and demo web apps without managing infrastructure
02How to install into DeepSeek Harness
Prerequisites
- Node.js >= 22
Installation steps
- 01
$ npx --yes huaweicloud-devkit install --target dsh
- 02
Restart the DSH session after installation
- 03
$ npx --yes huaweicloud-devkit install-hcloud # optional: install KooCLI for CLI tooling
- 04
$ npx --yes huaweicloud-devkit auth init # sync AK/SK to KooCLI, OBS, and sandbox APIs
Verify the integration
Not specified by the author
03DSH integration and capability boundaries
Installs through `npx --yes huaweicloud-devkit install --target dsh`; DSH V1 connects via the existing MCP server (`@deepseek-ai/dsh-mcp-client`).
Guided cloud operations
natural-language requests for Huawei Cloud services→step-by-step guidance across 20+ services (ECS, OBS, VPC, RDS, GaussDB, FunctionGraph, APIG, CCE, …)
may create or modify cloud resources once the user approvesSafety-first execution
write or modify operations on Huawei Cloud→execution only after explicit user approval; credentials and secrets redacted from output
Pre-execution risk checks
planned operations→flags public exposure, credential leaks, and destructive operations before they run
Sandbox (DevStation)
web app project→temporary cloud runtime with instant public URL preview
provisions temporary cloud resources
04Who is it for? When not to use it?
Good for
- Developers and AI agents (DeepSeek Harness / DSH) that operate Huawei Cloud resources
- Teams that need ephemeral cloud runtimes to ship and demo web apps without managing infrastructure
Not for
- DSH V1 connects through the existing MCP server (`@deepseek-ai/dsh-mcp-client`). If the installer reports the client is not detected, add it manually with `npx @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-mcp-client`.
05Compatibility, maintenance and safety notes
- Requires Node.js >= 22 before running any `huaweicloud-devkit` command.
- DSH V1 connects through the existing MCP server (`@deepseek-ai/dsh-mcp-client`). If the installer reports the client is not detected, add it manually with `npx @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-mcp-client`.
- MCP-based agents need network access and project-level Huawei Cloud credentials set via `HW_ACCESS_KEY`/`HW_SECRET_KEY` in the MCP config `env` field.
Apache-2.0 · actively maintained (latest release v1.1.1-next.12, 2026-09-04)
06Frequently asked questions
How do I install HuaweiCloud DevKit for DeepSeek Harness (DSH)?
Run `npx --yes huaweicloud-devkit install --target dsh`, then restart the DSH session. If the installer reports the MCP client is missing, add it manually with `npx @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-mcp-client`.
How does DevKit connect to DSH?
DSH V1 reuses the existing MCP server through `@deepseek-ai/dsh-mcp-client`. DevKit is not a native DSH runtime — it exposes Huawei Cloud tools to the DSH agent over MCP.
What safety guarantees does it provide?
All write operations require explicit user approval, credentials and secrets are automatically redacted from output, and public exposure, credential leaks, and destructive operations are caught by pre-execution risk checks before they run.
Do I need KooCLI and Huawei Cloud credentials?
KooCLI is optional CLI tooling installed via `npx --yes huaweicloud-devkit install-hcloud`. For credentials, run `npx --yes huaweicloud-devkit auth init` to sync AK/SK to KooCLI, OBS, and the sandbox APIs in one step.
What are the prerequisites?
You need Node.js >= 22. China mainland users with slow npm downloads can switch to the Huawei Cloud npm mirror with `npm config set registry https://mirrors.huaweicloud.com/repository/npm/`.
07Related DSH workflows
ruflo
by ruvnet
🌊 The original agent meta-harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
reactive-resume
by amruthpillai
A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!
everos
by evermind-ai
One portable memory layer for every AI agent: local-first, Markdown-native, user-owned, and self-evolving across apps, tools, and workflows.
yao
by yaoapp
✨ All your agents and workspaces in one place, on every device you own. Track tasks on a board, accessible from desktop, mobile, browser, or API. Self-hosted.
08Data and sources
Supports OpenCode, Codex, CodeArts Agent, WorkBuddy, DeepSeek Harness (DSH), OfficeAce, Hermes, OpenClaw, and AtomCode.
DSH V1 reuses the existing MCP server through `@deepseek-ai/dsh-mcp-client`.
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-09-05. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
