Bundle
dsh-housekeeper
Environment housekeeper for DeepSeek Harness: toolchain inventory, agent scratch/cache scan with safe one-click cleanup, and the machine rules file (AGENTS.md) view/edit - all in the Web GUI settings. Zero runtime dependencies.
- Source
- guo6x
- stars
- 5 stars
- License
- MIT
- Updated
- Updated 3 days ago
Readme
# ๐งน dsh-housekeeper โ Environment Housekeeper
[ไธญๆ่ฏดๆ](README.zh.md) ยท [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) plugin
Keep your agent's hands clean: **toolchain inventory, two-step cache cleanup, and machine rules (AGENTS.md) editing** โ all inside the DSH Web GUI settings. Zero runtime dependencies, one command install.
- ๐ **Toolchain inventory** โ auto-detects node/pnpm/git/gh/ffmpeg/Edge/Chrome locations and versions
- ๐๏ธ **Honest cache cleanup** โ scans the `.tmp` and cache directories agents leave behind: size / file count / mtime, 4000-file truncation markers, 30-day-untouched highlighting, click-to-expand content preview; create a plan, then confirm deletion
- ๐ก๏ธ **Whitelist protection** โ only project `.tmp` dirs and cache-root children are deletable; `..` escapes, symlink escapes, and system paths are rejected, with a realpath re-check before every delete
- ๐ **Machine rules editor with a safety net** โ read/write `~/.dsh/AGENTS.md` (the global rules every agent session loads), **auto-backup of the previous version on every save**, one-click restore, live on save
- ๐ **Configurable** โ scan roots default per platform (Windows: `D:\github` / `D:\environment\cache`), editable in the panel, overridable via env vars
- ๐ค **Agent tools** โ `housekeeper_report` (inventory + disk report), `housekeeper_plan` (review only), and `housekeeper_clean` (executes a single-use token)
## Install โ copy, paste, confirm
```sh
# Install from GitHub โ this is the supported release channel.
dsh plugin --profile web add github:guo6x/dsh-housekeeper
```
Restart a running `dsh web` process, then open **Settings โ Plugins โ ็ฏๅข็ฎกๅฎถ**. **Seeing the Toolchain inventory section means installation is complete.**
Requirements: the DSH web profile and Node โฅ 22. The plugin needs no account, API key, or extra service.
Developing from a checkout instead? Run `dsh plugin --profile web add .` from the repository directory. The committed `lib/` files mean GitHub installs do not run a build script.
## First safe pass in 60 seconds
**Nothing in this walkthrough deletes files or writes rules.**
1. Open **Settings โ Plugins โ ็ฏๅข็ฎกๅฎถ**.
2. Inspect the detected toolchain and cache candidates; click a row to preview its contents.
3. Do not select anything yet. You have verified the inventory and the candidate list without changing the machine.
For the same non-destructive proof through chat, paste:
> Run `housekeeper_report` and summarize the detected toolchain plus the largest cache candidates. Do **not** create a cleanup plan, delete files, or change machine rules.
When you are ready to clean, select only scratch directories you recognize and choose **Generate cleanup plan**. Read the approved and rejected paths; deletion remains impossible until you explicitly use that planโs one-time confirmation action.
The same reviewed flow is available to an agent: ask for `housekeeper_report`, review `housekeeper_plan`, and only then allow the returned token to reach `housekeeper_clean`.
### If the panel is missing
- Confirm the plugin is installed in the **web** profile: `dsh plugin --profile web list dsh-housekeeper`.
- Restart the `dsh web` process after installing; a browser refresh alone cannot load new host code.
- Check that Node is version 22 or newer. The inventory can run without Edge, Chrome, or any cloud credential.
## Security model
- All routes accept loopback clients only (403 otherwise)
- **Cleanup whitelist** โ a path is deletable only when ALL hold:
- under `<projects-root>\<repo>\ .tmp\`, or a direct child of `<cache-root>\`
- normalized path stays inside the whitelist root (no `..`)
- `realpath` still lands inside the whitelist root (no symlink escapes)
- the whitelist roots and repo dirs themselves are never deletable
- **Two-step confirmation** โ a cleanup plan exists only in memory; its confirmation token expires after five minutes, is single-use, and every path is checked against the whitelist and `realpath` again immediately before deletion
- The rules endpoint reads/writes `$DSH_HOME/AGENTS.md` only; the path is fixed
- No telemetry, no external network calls
## How it works
```
GUI settings โโfetchโโโถ /housekeeper/state|clean/planโclean|rules (loopback) โโโถ host plugin
โโ probe: candidate paths + PATH lookup + versions
โโ scan: rule-driven walk with sizes (4000-file cap)
โโ clean: whitelist + realpath โ plan โ single-use confirmation โ re-check, then rm
โโ rules: read/write $DSH_HOME/AGENTS.md (64KB cap)
```
## Develop
```sh
pnpm install
pnpm test # build, safety regression suite, and release-package check
```
MIT licensed. Issues and ideas welcome.
Install
dsh plugin --profile web add github:guo6x/dsh-housekeeper
Profile: web
With the hub plugin installed, ask your agent to install it by name โ it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-housekeeper from the hub
- This package builds from source on install. pnpm will ask you to allow its build script โ that is permission to run the packageโs code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.