DSH Plugins
返回列表
⚙️

dsh-subprocess-inherit-environment

工作流 更新于 2026.08.15

在终端中运行以下命令:

dsh plugin install zhangzujian/dsh-subprocess-inherit-environment

将以下提示词粘贴到 DeepSeek Harness 对话框中:

运行 dsh plugin install 命令,将仓库 https://github.com/zhangzujian/dsh-subprocess-inherit-environment 克隆到本地并加入 DSH profile,即可启用环境变量继承插件。

插件介绍

By default, DeepSeek Harness (DSH) scrubs sensitive variables from child process environments: any entry whose name contains KEY, PASSWORD, SECRET, or TOKEN, along with DSH_* prefixed names, is removed before the subprocess starts. This credential isolation protects most workloads, yet it also blocks tools that legitimately depend on the full parent environment, such as certain MCP servers, package installers, or CLI utilities.

The dsh-subprocess-inherit-environment plugin wraps the three ctx.subprocess operations (resolveExecutable, spawn, spawnTerminal) and injects a complete copy of the current process.env as an explicit environment layer on every call. Caller-supplied entries are merged after a fresh spread of process.env each time, preserving the original semantics of explicit overrides and undefined tombstones without mutating the caller object. Upon disposal the plugin restores the original method descriptors, so any later wrapper still delegates correctly to the native DSH implementation.

This plugin is well suited for developers and researchers running trusted, single-user environments where CLI tools, MCP servers, or installer scripts need access to the full parent environment. A critical caveat: once loaded, any child process spawned through ctx.subprocess can read API keys, tokens, passwords, and other secrets. In shared deployments, untrusted repositories, or multi-user setups, prefer an exact variable allowlist or a dedicated isolation mechanism instead of forwarding the entire environment.

使用场景

  • MCP 服务器或 CLI 工具需要读取父进程完整的 API 密钥与代理配置
  • 本地包安装脚本依赖父环境的代理凭据才能正常执行
  • 单开发者调试时子进程脚本需要访问全部环境变量

适合人员

  • 在可信单人环境中运行 DSH 的开发者
  • 需要子进程读取完整环境变量的 MCP 或工具链工程师
  • 在隔离沙箱中验证环境透传行为的插件贡献者