Skip to content
dsh.fish
Bundle

dsh-housekeeper

Environment housekeeper for DeepSeek Harness: toolchain inventory, agent scratch/cache scan with safe one-click cleanup, and the machine rules file (AGENTS.md) view/edit - all in the Web GUI settings. Zero runtime dependencies.

Source
guo6x
stars
5 stars
License
MIT
Updated
Updated 3 days ago

Readme

# ๐Ÿงน dsh-housekeeper โ€” Environment Housekeeper

[ไธญๆ–‡่ฏดๆ˜Ž](README.zh.md) ยท [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) plugin

Keep your agent's hands clean: **toolchain inventory, two-step cache cleanup, and machine rules (AGENTS.md) editing** โ€” all inside the DSH Web GUI settings. Zero runtime dependencies, one command install.

- ๐Ÿ“‹ **Toolchain inventory** โ€” auto-detects node/pnpm/git/gh/ffmpeg/Edge/Chrome locations and versions
- ๐Ÿ—‘๏ธ **Honest cache cleanup** โ€” scans the `.tmp` and cache directories agents leave behind: size / file count / mtime, 4000-file truncation markers, 30-day-untouched highlighting, click-to-expand content preview; create a plan, then confirm deletion
- ๐Ÿ›ก๏ธ **Whitelist protection** โ€” only project `.tmp` dirs and cache-root children are deletable; `..` escapes, symlink escapes, and system paths are rejected, with a realpath re-check before every delete
- ๐Ÿ“ **Machine rules editor with a safety net** โ€” read/write `~/.dsh/AGENTS.md` (the global rules every agent session loads), **auto-backup of the previous version on every save**, one-click restore, live on save
- ๐ŸŒ **Configurable** โ€” scan roots default per platform (Windows: `D:\github` / `D:\environment\cache`), editable in the panel, overridable via env vars
- ๐Ÿค– **Agent tools** โ€” `housekeeper_report` (inventory + disk report), `housekeeper_plan` (review only), and `housekeeper_clean` (executes a single-use token)

## Install โ€” copy, paste, confirm

```sh
# Install from GitHub โ€” this is the supported release channel.
dsh plugin --profile web add github:guo6x/dsh-housekeeper
```

Restart a running `dsh web` process, then open **Settings โ†’ Plugins โ†’ ็Žฏๅขƒ็ฎกๅฎถ**. **Seeing the Toolchain inventory section means installation is complete.**

Requirements: the DSH web profile and Node โ‰ฅ 22. The plugin needs no account, API key, or extra service.

Developing from a checkout instead? Run `dsh plugin --profile web add .` from the repository directory. The committed `lib/` files mean GitHub installs do not run a build script.

## First safe pass in 60 seconds

**Nothing in this walkthrough deletes files or writes rules.**

1. Open **Settings โ†’ Plugins โ†’ ็Žฏๅขƒ็ฎกๅฎถ**.
2. Inspect the detected toolchain and cache candidates; click a row to preview its contents.
3. Do not select anything yet. You have verified the inventory and the candidate list without changing the machine.

For the same non-destructive proof through chat, paste:

> Run `housekeeper_report` and summarize the detected toolchain plus the largest cache candidates. Do **not** create a cleanup plan, delete files, or change machine rules.

When you are ready to clean, select only scratch directories you recognize and choose **Generate cleanup plan**. Read the approved and rejected paths; deletion remains impossible until you explicitly use that planโ€™s one-time confirmation action.

The same reviewed flow is available to an agent: ask for `housekeeper_report`, review `housekeeper_plan`, and only then allow the returned token to reach `housekeeper_clean`.

### If the panel is missing

- Confirm the plugin is installed in the **web** profile: `dsh plugin --profile web list dsh-housekeeper`.
- Restart the `dsh web` process after installing; a browser refresh alone cannot load new host code.
- Check that Node is version 22 or newer. The inventory can run without Edge, Chrome, or any cloud credential.

## Security model

- All routes accept loopback clients only (403 otherwise)
- **Cleanup whitelist** โ€” a path is deletable only when ALL hold:
  - under `<projects-root>\<repo>\ .tmp\`, or a direct child of `<cache-root>\`
  - normalized path stays inside the whitelist root (no `..`)
  - `realpath` still lands inside the whitelist root (no symlink escapes)
  - the whitelist roots and repo dirs themselves are never deletable
- **Two-step confirmation** โ€” a cleanup plan exists only in memory; its confirmation token expires after five minutes, is single-use, and every path is checked against the whitelist and `realpath` again immediately before deletion
- The rules endpoint reads/writes `$DSH_HOME/AGENTS.md` only; the path is fixed
- No telemetry, no external network calls

## How it works

```
GUI settings โ”€โ”€fetchโ”€โ”€โ–ถ /housekeeper/state|clean/planโ†’clean|rules (loopback) โ”€โ”€โ–ถ host plugin
                          โ”œโ”€ probe: candidate paths + PATH lookup + versions
                          โ”œโ”€ scan: rule-driven walk with sizes (4000-file cap)
                          โ”œโ”€ clean: whitelist + realpath โ†’ plan โ†’ single-use confirmation โ†’ re-check, then rm
                          โ””โ”€ rules: read/write $DSH_HOME/AGENTS.md (64KB cap)
```

## Develop

```sh
pnpm install
pnpm test              # build, safety regression suite, and release-package check
```

MIT licensed. Issues and ideas welcome.

Install

dsh plugin --profile web add github:guo6x/dsh-housekeeper

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script โ€” that is permission to run the packageโ€™s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source