snylonue/dsh-direnv ↗★ 0

dsh-direnv

Workspace-aware direnv environment injection for DeepSeek Harness, with user-approved .envrc authorization 适合需要在不同项目目录中自动加载并隔离环境变量,且需用户授权的安全场景。

패키지
dsh-direnv
호환성
미검증
Harness peer 범위
^0.1.5-rc.2
Cordis peer 범위
^4.0.2
버전
0.1.0
라이선스
MIT
최근 업데이트
2026. 9. 25.

같은 패키지 이름의 다른 저장소

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:snylonue/dsh-direnv

Configuration

- id: direnv
  name: dsh-direnv
  config:
    executable: direnv          # bare PATH name or absolute path
    enabled: true               # master switch
    probeTimeoutMs: 10000       # budget for one direnv run
    notifyOnBlocked: true       # append the actionable notice to results
    restrictAllowToWorkspace: true  # direnv_allow may only name a file inside the agent's workspace
    followWorkdir: true         # the command's own directory selects the .envrc
    cache: true                 # resolve each directory once; reload on demand
    previewBytes: 2048          # bounded preview shown in the approval prompt
FieldDefaultMeaning
executabledirenvThe direnv binary; must be on PATH or absolute.
enabledtrueWhen off, the adapter is inert and no probe runs.
probeTimeoutMs10000One direnv export json run is killed past this.
notifyOnBlockedtrueOff keeps results byte-identical to an un-instrumented run.
restrictAllowToWorkspacetrueOn, direnv_allow refuses any path outside the agent's workspace, including via .. or a symlink.
followWorkdirtrueOn, a command run in /packages/api picks up that .envrc. Off, every command uses the session workspace root.
cachetrueResolve each directory once and reuse the result. The cache refreshes itself when the .envrc changes or when direnv's allow/deny store is rewritten, and direnv_reload forces a refresh. Off, every command pays the probe (about 35 ms for an allowed .envrc).
previewBytes2048How much of the .envrc the user sees. 0 shows only the hash.