Degurechaff57/dsh-openapi

Safe OpenAPI 3.x discovery and API calling tools for DeepSeek Harness

Gives DeepSeek Harness a safe, structured doorway into any OpenAPI 3.x API: openapi_list discovers APIs and searches operations, openapi_describe returns parameters, request bodies, servers, and responses for one operation, and openapi_call validates and invokes an operation with bounded output. Provides operation discovery without reading a huge spec into model context, declared-parameter validation, environment-backed credentials, read-only defaults, SSRF checks, and response limits — without patching the Harness agent loop.

Other ★ 4 updated 2026-08-13 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add github:Degurechaff57/dsh-openapi

Plain ESM JavaScript, so installing from GitHub does not run a build or prepare script: dsh plugin --profile web add github:Degurechaff57/dsh-openapi. The bundle installs with an empty API catalog — add API entries to the profile's cordis.patch.yml (id: openapi, config.apis with source, baseUrl, allowedMethods). Map request headers to environment variables via credentials (prefix Bearer etc.) to keep secrets out of YAML. For a source checkout, dsh plugin --profile web add /absolute/path/to/dsh-openapi.

Compatibility

DeepSeek Harness Web profile. Indexes configured OpenAPI 3.x documents; environment-backed credentials; SSRF checks; response limits.

Details

Recent updates

Three model-facing tools (openapi_list / openapi_describe / openapi_call); credential headers applied after model-supplied parameters so a tool call cannot override them; missing env vars fail the call before network I/O.

FAQ

How do I add an API?
Add an entry to the plugin's config in the profile's cordis.patch.yml: id: openapi, then config.apis with a source (URL or local file), baseUrl, and allowedMethods. Start Harness and ask the agent to use openapi_list to discover operations.
How do I keep API keys out of YAML?
Map a request header to an environment variable: credentials: - header: Authorization, env: INTERNAL_API_TOKEN, prefix: 'Bearer '. The credential header is applied after model-supplied parameters, so a tool call cannot override it.
Does installing from GitHub run a build?
No — the plugin is plain ESM JavaScript, so installing from GitHub does not run a build or prepare script.

Alternatives

PerryLink/dsh-lsp-actions · omdsh-dev/dsh-custom-tool · liustack/modsearch

More plugins in Other

Browse more in Other

Guides for Other plugins