pandashere/dsh-codex-bridge
Codex CLI bridge plugin for DeepSeek Harness with host tools and a Web conversation tab.
A dual-face (host + browser) plugin that bridges the OpenAI Codex CLI into DSH. call_codex starts a Codex session (codex -a never exec --json) in the session's working directory with async (returns immediately, runs in parallel) and block (waits for the final answer) modes; codex_status polls and codex_abort cancels; codex_steer resumes a settled session on the SAME thread (codex exec resume <thread_id>) so direction can be corrected with full history. A Codex tab in the conversation pane observes each session live with status, prompt, an Agent Loop waterfall (messages, tool calls with command/args, collapsible output with exit code, turn separators), transcript and final answer.
Install
npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add ./dsh-codex-bridge-0.1.0.tgzREADME install flow: build, validate and pack the standalone bundle from the plugin directory (npm install, npm run check, npm pack), install the generated tarball into a DSH profile with the command above, then restart dsh web (npx @deepseek-ai/dsh@0.1.0-rc.6 web). Installing the source directory as a link is not supported because host peers are supplied by the DSH profile. Update by building a tarball with a newer package version, removing the installed bundle and adding the new tarball; uninstall with npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web remove dsh-codex-bridge. The browser half is served at /plugins/dsh-codex-bridge/client.js.
Compatibility
Requirements: Node.js 22+, @deepseek-ai/dsh@0.1.0-rc.6, and an authenticated Codex CLI available as codex (or set codexPath). The plugin does not read or store API keys — authentication stays with the Codex CLI. Codex runs with the calling user's privileges under its own sandbox policy (read-only / workspace-write are offered to the model; danger-full-access is deploy-config only), always in the session working directory (fail closed), and resource amplification is bounded by maxParallel / maxSessionsPerSession / maxLoopSteps / maxLoopBytes.
Details
- Repo: pandashere/dsh-codex-bridge
- Category: Coding & Development
- Stars: 1
- Version: GitHub main (README-documented; not published to npm — the tarball build is the install path)
- Last push: 2026-08-13
- First seen: 2026-08-13
Recent updates
README states the design stance explicitly: this is a UX channel, not a security boundary — Codex runs under its own sandbox policy with the calling user's privileges, the model-facing surface is deliberately tight, and all resource caps are configurable (maxParallel 3, maxSessionsPerSession 8, maxLoopSteps 32, maxPromptChars 16384 by default).
FAQ
- How do I install dsh-codex-bridge?
- From the plugin directory run npm install && npm run check && npm pack, then install the tarball: npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add ./dsh-codex-bridge-0.1.0.tgz, and restart dsh web. Installing the source directory as a link is not supported.
- Does the plugin store my Codex credentials?
- No — it reads no API keys; authentication remains owned by the Codex CLI (found as codex on PATH or via the codexPath config key).
- Why does Codex run in the session directory?
- By design: Codex always runs in the session working directory (never the host cwd, fail closed), and only top-level agents may call it by default (allowedAgents defaults to roots).