guo6x/dsh-housekeeper
Environment housekeeper for DeepSeek Harness: toolchain inventory, safe cache cleanup, and machine rules editor in the Web GUI settings.
Listed
1
Dev
Bundle verified
Preview
What it does
Environment housekeeper for the agent: toolchain inventory (node/pnpm/git/gh/ffmpeg/browsers), scratch/cache scan with whitelist-guarded one-click cleanup, and the machine rules file (AGENTS.md) editor - all in the Web GUI settings.
Best for
- DeepSeek Harness administrators who want a Web GUI inventory of Node, pnpm, Git, GitHub CLI, FFmpeg, and installed browsers.
- Users cleaning agent-created project scratch directories and cache-root children through guarded controls.
- Teams that maintain global AGENTS.md machine rules and want automatic backups and one-click restore.
Not ideal for
- Arbitrary filesystem cleanup; deletion is restricted to approved project .tmp paths and direct cache-root children.
- Environments without a DeepSeek Harness web profile or Node 22 or later.
- Large automated cleanup batches requiring more than ten paths in one housekeeper_clean call.
README
๐งน dsh-housekeeper โ Environment Housekeeper
ไธญๆ่ฏดๆ ยท DeepSeek Harness plugin
Keep your agentโs hands clean: toolchain inventory, safe one-click cache cleanup, and machine rules (AGENTS.md) editing โ all inside the DSH Web GUI settings. Zero runtime dependencies, one command install.
- ๐ Toolchain inventory โ auto-detects node/pnpm/git/gh/ffmpeg/Edge/Chrome locations and versions
- ๐๏ธ Honest cache cleanup โ scans the
.tmpand cache directories agents leave behind: size / file count / mtime, 4000-file truncation markers, 30-day-untouched highlighting, click-to-expand content preview, check and delete - ๐ก๏ธ Whitelist protection โ only project
.tmpdirs and cache-root children are deletable;..escapes, symlink escapes, and system paths are rejected, with a realpath re-check before every delete - ๐ Machine rules editor with a safety net โ read/write
~/.dsh/AGENTS.md(the global rules every agent session loads), auto-backup of the previous version on every save, one-click restore, live on save - ๐ Configurable โ scan roots default per platform (Windows:
D:\github/D:\environment\cache), editable in the panel, overridable via env vars - ๐ค Agent tools โ
housekeeper_report(inventory + disk report) andhousekeeper_clean(same whitelist, max 10 paths per call)
Install
dsh plugin --profile web add dsh-housekeeper
Restart dsh web, then Settings โ Plugins โ ็ฏๅข็ฎกๅฎถ.
Requirements: DSH web profile, Node โฅ 22.
Security model
- All routes accept loopback clients only (403 otherwise)
-
Cleanup whitelist โ a path is deletable only when ALL hold:
- under
<projects-root>\<repo>\ .tmp\, or a direct child of<cache-root>\ - normalized path stays inside the whitelist root (no
..) -
realpathstill lands inside the whitelist root (no symlink escapes) - the whitelist roots and repo dirs themselves are never deletable
- under
- The rules endpoint reads/writes
$DSH_HOME/AGENTS.mdonly; the path is fixed - No telemetry, no external network calls
How it works
GUI settings โโfetchโโโถ /housekeeper/state|clean|rules (loopback) โโโถ host plugin
โโ probe: candidate paths + PATH lookup + versions
โโ scan: rule-driven walk with sizes (4000-file cap)
โโ clean: whitelist + realpath check, then rm
โโ rules: read/write $DSH_HOME/AGENTS.md (64KB cap)
Develop
pnpm install
node build.mjs # esbuild โ lib/index.js (host ESM) + lib/client.js (ModuleLoader bundle)
node tests/core.mjs # 21 whitelist/scan/clean sandbox tests, no real environment needed
MIT licensed. Issues and ideas welcome.
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:guo6x/dsh-housekeeper in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.