dsh-direnv
Workspace-aware direnv environment injection for DeepSeek Harness, with user-approved .envrc authorization 适合需要在不同项目目录中自动加载并隔离环境变量,且需用户授权的安全场景。
同名パッケージの別リポジトリ
インストール
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:snylonue/dsh-direnvドキュメント
README 全文を読む ↗Configuration
- id: direnv
name: dsh-direnv
config:
executable: direnv # bare PATH name or absolute path
enabled: true # master switch
probeTimeoutMs: 10000 # budget for one direnv run
notifyOnBlocked: true # append the actionable notice to results
restrictAllowToWorkspace: true # direnv_allow may only name a file inside the agent's workspace
followWorkdir: true # the command's own directory selects the .envrc
cache: true # resolve each directory once; reload on demand
previewBytes: 2048 # bounded preview shown in the approval prompt
| Field | Default | Meaning |
|---|---|---|
executable | direnv | The direnv binary; must be on PATH or absolute. |
enabled | true | When off, the adapter is inert and no probe runs. |
probeTimeoutMs | 10000 | One direnv export json run is killed past this. |
notifyOnBlocked | true | Off keeps results byte-identical to an un-instrumented run. |
restrictAllowToWorkspace | true | On, direnv_allow refuses any path outside the agent's workspace, including via .. or a symlink. |
followWorkdir | true | On, a command run in /packages/api picks up that .envrc. Off, every command uses the session workspace root. |
cache | true | Resolve each directory once and reuse the result. The cache refreshes itself when the .envrc changes or when direnv's allow/deny store is rewritten, and direnv_reload forces a refresh. Off, every command pays the probe (about 35 ms for an allowed .envrc). |
previewBytes | 2048 | How much of the .envrc the user sees. 0 shows only the hash. |