What it does
Remote access for DeepSeek Harness: account/password auth + MFA (TOTP) login gate, signed session cookies, role-based access, in-browser directory picker, and a Settings page for account management.
Installation
dsh plugin --profile web add dsh-remote-3Install method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
ea4875bf83f72026-08-17ea4875bf83f7The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (7 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Scan findings · 5
- infoMakes network requests (fetch / axios)lib/client.js:237res = await fetch(path, {
- infoHardcoded IP addresslib/index.js:420const authority = `127.0.0.1:${webServer.port ?? "3080"}`;
- infoMakes network requests (fetch / axios)lib/login-page.js:307var res = await fetch("/auth/mfa/setup", {
- infoMakes network requests (fetch / axios)lib/login-page.js:350var res = await fetch("/auth/mfa/verify", {
- infoMakes network requests (fetch / axios)lib/login-page.js:401var res = await fetch(phase === "code" ? "/auth/mfa/login" : endpoint, {
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-17 · activity: Active
• Repo created: 2026-08-17
• Stars: ★ 4 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/xgone/dsh-remote
