guo6x/dsh-housekeeper

Environment housekeeper for DeepSeek Harness: toolchain inventory, safe cache cleanup, and machine rules editor in the Web GUI settings.

Bundle verified MIT JavaScript Unknown
Bundle verified

Listed

1

Dev

Bundle verified

โ˜… 1 View on GitHub
VersionUnknown
LanguageJavaScript
LicenseMIT
View on GitHub

Preview

Preview 1 of 2: guo6x/dsh-housekeeper
Preview 2 of 2: guo6x/dsh-housekeeper

What it does

Environment housekeeper for the agent: toolchain inventory (node/pnpm/git/gh/ffmpeg/browsers), scratch/cache scan with whitelist-guarded one-click cleanup, and the machine rules file (AGENTS.md) editor - all in the Web GUI settings.

Best for

  • DeepSeek Harness administrators who want a Web GUI inventory of Node, pnpm, Git, GitHub CLI, FFmpeg, and installed browsers.
  • Users cleaning agent-created project scratch directories and cache-root children through guarded controls.
  • Teams that maintain global AGENTS.md machine rules and want automatic backups and one-click restore.

Not ideal for

  • Arbitrary filesystem cleanup; deletion is restricted to approved project .tmp paths and direct cache-root children.
  • Environments without a DeepSeek Harness web profile or Node 22 or later.
  • Large automated cleanup batches requiring more than ten paths in one housekeeper_clean call.

README

๐Ÿงน dsh-housekeeper โ€” Environment Housekeeper

ไธญๆ–‡่ฏดๆ˜Ž ยท DeepSeek Harness plugin

Keep your agentโ€™s hands clean: toolchain inventory, safe one-click cache cleanup, and machine rules (AGENTS.md) editing โ€” all inside the DSH Web GUI settings. Zero runtime dependencies, one command install.

  • ๐Ÿ“‹ Toolchain inventory โ€” auto-detects node/pnpm/git/gh/ffmpeg/Edge/Chrome locations and versions
  • ๐Ÿ—‘๏ธ Honest cache cleanup โ€” scans the .tmp and cache directories agents leave behind: size / file count / mtime, 4000-file truncation markers, 30-day-untouched highlighting, click-to-expand content preview, check and delete
  • ๐Ÿ›ก๏ธ Whitelist protection โ€” only project .tmp dirs and cache-root children are deletable; .. escapes, symlink escapes, and system paths are rejected, with a realpath re-check before every delete
  • ๐Ÿ“ Machine rules editor with a safety net โ€” read/write ~/.dsh/AGENTS.md (the global rules every agent session loads), auto-backup of the previous version on every save, one-click restore, live on save
  • ๐ŸŒ Configurable โ€” scan roots default per platform (Windows: D:\github / D:\environment\cache), editable in the panel, overridable via env vars
  • ๐Ÿค– Agent tools โ€” housekeeper_report (inventory + disk report) and housekeeper_clean (same whitelist, max 10 paths per call)

Install

dsh plugin --profile web add dsh-housekeeper

Restart dsh web, then Settings โ†’ Plugins โ†’ ็Žฏๅขƒ็ฎกๅฎถ.

Requirements: DSH web profile, Node โ‰ฅ 22.

Security model

  • All routes accept loopback clients only (403 otherwise)
  • Cleanup whitelist โ€” a path is deletable only when ALL hold:
    • under <projects-root>\<repo>\ .tmp\, or a direct child of <cache-root>\
    • normalized path stays inside the whitelist root (no ..)
    • realpath still lands inside the whitelist root (no symlink escapes)
    • the whitelist roots and repo dirs themselves are never deletable
  • The rules endpoint reads/writes $DSH_HOME/AGENTS.md only; the path is fixed
  • No telemetry, no external network calls

How it works

GUI settings โ”€โ”€fetchโ”€โ”€โ–ถ /housekeeper/state|clean|rules (loopback) โ”€โ”€โ–ถ host plugin
                          โ”œโ”€ probe: candidate paths + PATH lookup + versions
                          โ”œโ”€ scan: rule-driven walk with sizes (4000-file cap)
                          โ”œโ”€ clean: whitelist + realpath check, then rm
                          โ””โ”€ rules: read/write $DSH_HOME/AGENTS.md (64KB cap)

Develop

pnpm install
node build.mjs         # esbuild โ†’ lib/index.js (host ESM) + lib/client.js (ModuleLoader bundle)
node tests/core.mjs    # 21 whitelist/scan/clean sandbox tests, no real environment needed

MIT licensed. Issues and ideas welcome.

Frequently Asked QuestionsFAQ

Use the verified command dsh plugin --profile default add github:guo6x/dsh-housekeeper in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.