dsh-minato (formerly DeepSeek Harness Toolkit): a toolbox that tends the oven for people who don't want to mind the stove

dsh-minato whale girl
Introduction
DeepSeek Harness (dsh) is DeepSeek's official tool. The officially recommended usage is not actually hard, but it's very "kitchen-like": first prep the ingredients (install Node.js), then light the fire (type two commands), and from then on every time you want to use it you have to hover around the stove.
But there are always people who just want to eat bread, not mind the stove.
So this project came to be — DeepSeek Harness Toolkit. Now it has its own short name: dsh-minato ("gather," and also "harbor" — a place where things come ashore). It gathers installation, startup, monitoring, backup, restore, checkup, and uninstall all into one double-clickable window, as if packing all the work of the whole back kitchen into a small baking tray.
In October it officially graduated: the first stable release of 3.0. Starting with this version, it is no longer just an exe on Windows, but a cross-platform toolbox for Windows / Linux — a command-line core plus a graphical window with ten pages.
What 3.0 looks like: one window, two platforms
The graphical interface is written with Avalonia (works on Windows / Linux), with a row of ten pages on the left:
| Page | What it does |
|---|---|
| Overview | See at a glance: what's installed, what's running, what's outdated |
| Dashboard | Session count / cache hit rate / token count, one-click start/stop |
| Sessions & Tokens | Per-session details, parent-child grouping, sortable |
| Profiles & Plugins | Which plugins a profile has installed, which are disabled, which will keep it from starting |
| Backup | Create, inspect, verify, restore, export, delete packages |
| Health Check | "Exactly what's broken" + which line to change; only runs when you click the button, doesn't run off on its own |
| Settings | Language, port, behavior — no need to edit YAML by hand |
| About | Version, credits, and what it deliberately does not do |
| Update Center | dsh / official desktop app / this tool / plugins — update in one place |
| Logs | Filter, search, export |
Command line (dsh-minato): 31 named commands + a numbered menu when run with no arguments. This is exactly what the GUI calls, and it can also be used on its own:
Each command emits machine-readable markers (STATUS_OK / BACKUP_OK / RESTORE_FAIL…), and scripts and the GUI act on the markers instead of guessing from text.
The installation method has also changed:
| Platform | Artifact | Notes |
|---|---|---|
| Windows | dsh-minato-<版本>-win-x64-setup.exe | Double-click to install; a portable version also works: dsh-minato-win-x64.zip, run gui\dsht-gui.exe |
| Linux | dsh-minato-linux-x64.tar.gz | After unpacking, ./install.sh, installs to the current user, no sudo needed |
| Verification | hashes.txt + hashes.txt.asc | SHA-256 of all artifacts, plus their GPG signatures |
What it can do now
| Feature | Description |
|---|---|
| Install dsh | Double-click. No terminal needed, no need to understand Node.js. Installs the CLI, configures PATH, adds a Start menu entry, and leaves an uninstaller next to it |
| One-click start/stop / monitoring | One button to open the Web UI, live status line + the URL to open |
| Backup / Restore | Packages sessions, settings, and credentials together; packages carry a completion marker + per-file content hashes — interrupted or modified packages are rejected, not silently restored |
| Backup manager | See exactly what's in each package before you act |
| Move to another computer | Export a package and import it on a new machine |
| Update Center | dsh, official desktop app, this tool, installed plugins — update in one place |
| Health Check | "Exactly what's broken" — names what's broken and prints the line to fix |
| Sessions & Tokens | Per-session token / cache hit rate / speed, parent-child grouping |
| Balance | After you enter your own key, see DeepSeek topped-up balance and granted balance; if not entered, the whole card is hidden and not a single request is sent |
| Profile diagnosis and prescription | profilecheck statically scans which file, which line, which key is missing; profilepatch is idempotent, backs up first, previews first, requires --yes to write, adds only one line, and rolls back byte-for-byte on failure |
| Boot diagnosis | bootdiag takes the innermost lesion from the error chain, and if it can't recognize it, plainly says unknown, without guessing |
| Uninstall | By default never deletes your data, and refuses to delete directories that "don't look like an installation directory" |
| Self-check / shortcuts / auto-start / config read-write | The miscellaneous but everyday things |
There is also an optional read-only bridge plugin dsh-minato-bridge: the dsh process itself is the only one that knows "which sessions are still alive," and it doesn't write that to disk. Without the plugin, the "running" column shows unknown; with it, you can see it in real time. The plugin makes no model requests (doesn't burn tokens), doesn't write dsh state, doesn't read session bodies, doesn't go online, and doesn't block.
From 2.6 to 3.0, what was filled in along the way
2.7 line: from "usable" to "repairable when broken." Tray resident, bottom status bar, hotkeys, action bubbles; desktop shortcuts can be chosen to point to the GUI; added a "verify this installation" button (pulls the latest official Release's hashes.txt and compares SHA-256, three states: match / mismatch / unable to verify). Most important is the localization chain when dsh won't start: profilecheck scans out which profile file, which line, which entry is missing which key → bootdiag takes the innermost lesion from the stack → profilepatch, with backup, preview, idempotence, and rollback, adds only that line; later a second prescription --disable was added to isolate any bad plugin first before troubleshooting (append only, doesn't modify any existing character). Along the way, an honest correction: restore --dry-run with a relative path would falsely report "0 files"; fixed (only affects preview, not actual restore).
3.0.0: Graduation. Cross-platform CLI + ten-page GUI, Linux support (one-click Node install without sudo, chooses package by CPU architecture, must pass official SHASUMS256 verification before unpacking), backup/restore engine rewritten (completion marker + per-file hashes + automatic anchor before restore that can be rolled back + truncated package rejection + doesn't write through symlinks), 47 bug fixes. Representative items: restore failure automatically rolls back; symlinks / junctions no longer bypass the restore isolation gate; .. out-of-bounds deletions are always rejected; interrupted backups are recognized as incomplete; wipe only prints manual deletion paths — doesn't delete or back up. The CLI's Program.cs was split into seven partial files (3595 → 1060 lines); identical backup code on Windows and Linux was extracted into a shared base class (previously "fixing a bug in one place meant remembering to fix it in two," and that had already been missed once). Real-machine verification also caught three problems that all automated gates missed: no hashes.txt in the tar package, 5 shell scripts lost their executable bit, and the bridge plugin required users to manually add a patch line — all three were fixed in this version.
3.0.1: Fixed both "stuck" and "dishonest readings." Switching pages no longer waits for the CLI to finish (previously a health check took 6.5 seconds and an update took 7.9 seconds, with the screen frozen); now clicking switches pages immediately, with a loading indicator and data fading in when it arrives; the health check was changed to run only on button click; "attached in dsh" is no longer described as "running," but honestly reported in three states (running / attached · last activity N ago / activity unknown); the settings page was categorized and switched to dropdowns; DeepSeek balance detection was added; the GUI was slimmed down by a third through trimming (self-contained package about 74 MB → about 50 MB). One other thing worth noting: .dsh_launcher_root (the marker the uninstaller's "anti-accidental-deletion" gate depends on) had been untracked, which would cause release packages to lose this gate — restored.
3.0.2 (latest): two pitfalls actually hit in practice. First, updates could be clicked several times in a row — each click started a new CLI process, so three clicks meant three update --yes running at once (npm installs stepping on each other, three backups in a row, rollback points overwriting each other). Now only one CLI action is allowed at a time, and clicks while one is running are honestly rejected with an explanation of what is running and how long it has been running — no queueing (queueing would pile invisible work behind long tasks); the button is disabled and shows "In progress: X…", and the gate is always released in finally when the action ends. The same loophole in the "Back up now" button was included as well. Second, the balance entry point was hard to find: when no key was bound, previously there was nowhere to even find "where to enter it"; now the settings page has a separate group and the overview page has a line entry — but the balance numbers are still not shown at all when unbound.
Security and Privacy: Only What the Code Actually Does
- Operates only on the local machine. Only these commands go online:
check,update-info,update-center,doctor,install,update,verify-install --url, andbalance(and only when you've entered a key; if not, it's completely offline). The rest — status, sessions, backup, restore, logs — open not a single connection. - No telemetry, no accounts, no uploads.
- Uninstall does not delete your data. Uninstall deletes only its own files; deleting data is a separate explicit action.
- Backup integrity is "verified," not "assumed." The completion marker is written last, with per-file content hashes; interrupted or modified packages are rejected.
- Zero third-party runtime dependencies (CLI / installer / launcher / plugin), with the sole exception that the GUI is built on Avalonia.
- The API key you enter is stored in plaintext in the local configuration, and is only sent to the DeepSeek API by the
balancecommand. If you don't enter one, nothing is stored. - Releases are verifiable: CI generates a SHA-256 manifest + maintainer GPG signature (
verify.ps1pins the maintainer fingerprint and prints the Release → Tag → Commit chain); the repository stores no binaries, and builds are reproducible.
Testing: It Tests Itself
With no third-party dependencies, it uses C#'s /define:UNIT for same-assembly unit tests + a stubbed end-to-end integration test matrix (touching only stub directories, never real data). Currently (3.0.2) it runs: 355 contract tests · 68 GUI logic tests · 25 bridge plugin self-tests, plus 318 unit tests retained on the v2 line; CI is all green on both windows-latest / ubuntu-latest, and the Windows package also includes a GUI smoke test that actually launches and creates a window. Backup / restore / delete go through real round trips (isolated root), symlinks / junctions are verified in both directions, and releases prove themselves (tampering can be detected). Only after tasting the bread yourself do you dare serve it.
First Use (Three Steps)
- Verify before running: Windows artifacts are not digitally signed, so SmartScreen may pop up "Unknown publisher" — verify with the published
.sha256(and the GPG-signedhashes.txt) before clicking. - Install: On Windows, double-click the installer (or unpack the portable package and run
gui\dsht-gui.exe); on Linux, unpack and run./install.sh. Opening it gives you that ten-page window. - If something goes wrong, run a health check first: click "Run Health Check"; it will name what's broken and give the line to fix it; if a profile is broken, go
profilecheck → bootdiag → profilepatch.
Honest Boundaries
- This is a third-party, unofficially maintained project, unrelated to official DeepSeek, and no compatibility with future dsh versions is promised. It is not a dsh plugin: it is a standalone process, does not inject into dsh, and can be used even if dsh is not installed.
- Windows artifacts are not digitally signed — please verify with the published
.sha256and GPG signature rather than relying on certificates. - The GUI is based on Avalonia, so it is not zero-dependency — the rest of the project is.
- The bridge plugin requires pnpm; the
desktopprofile is managed exclusively by the official desktop app, and plugins must be added in the desktop app's own dialog. - Real-machine Linux verification remains at 3.0.0 (3.0.1 / 3.0.2 only have CI packaging and smoke tests), stated honestly.
- If you're a terminal-savvy user, using the official npm commands directly is lighter and faster; this tool is for people who "don't want to touch the terminal" — after all, there are always people who just want to eat bread and don't want to mind the stove.
Get It
GitHub: https://github.com/sakanamaru/dsh-minato (the old address DeepSeek-Harness-Toolkit automatically redirects to the new repository)
As of 3.0.0, the project was officially renamed
dsh-minato; the old name DeepSeek Harness Toolkit is no longer used. The link in this article has also been changed tohttps://shiogiri.com/posts/dsh-minato— if you came in through a bookmark, please re-bookmark it.
MIT license (code); source, build scripts, hash manifest, and tests are all in the repository; the icon is not MIT (see the repository's docs/ASSETS.md); when reposting or redistributing, please retain attribution and the "unofficial" notice.
In Kirihoshi-chō, the bakery's oven is never empty.
v1 script assistance: SOGR-Momono Dango · v2 refactor and packaging: DeepSeek DSH · GitHub: @sakanamaru