Fast Rust launcher for DeepSeek Harness, with clear Claude Code/Codex migration, model setup and lightweight local tools
# Add to your Claude Code skills
git clone https://github.com/jimoto-no-llm/rustdshSee how rustdsh compares with popular alternatives.
rustdsh is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by jimoto-no-llm. Fast Rust launcher for DeepSeek Harness, with clear Claude Code/Codex migration, model setup and lightweight local tools. It has 67 GitHub stars.
rustdsh's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/jimoto-no-llm/rustdsh" and add it to your Claude Code skills directory (see the Installation section above).
rustdsh is primarily written in JavaScript. It is open-source under jimoto-no-llm on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh rustdsh against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
dshAn independent community project; not an official DeepSeek or DeepSeek Harness project.
rdsh is a drop-in fast path for dsh
(the DeepSeek Harness CLI). Instead of rewriting everything, it ports only
the hot paths to Rust and delegates conversations and model runs to the
original dsh binary. Arguments you already use keep working as-is.
--version replies in about 0.90 ms with about 2.9 MB peak RSS on Linux x86_64 (original dsh: about 88 ms and 66 MB). Short-CLI numbers only; they do not describe the resident Desktop app or model calls.rdsh --version && rdsh doctor # verify install and original dsh
rdsh setup --web # open the printed #key=... URL, connect a model
rdsh tui # start a conversation, confirm a model reply
See the usage and recovery flow, settings, and architecture. Delegated conversations need the original DSH runtime.
| Item | Detail |
|---|---|
| OS | Linux, macOS, WSL, Windows (native). Agent isolation needs Linux x86_64 + bubblewrap + prlimit. |
| DSH runtime | Original dsh for conversations. Audited versions: 0.2.0-rc.2, 0.2.1-alpha.1. |
| Rust | 1.85+ (source builds only). Prebuilt binaries need no Rust. |
| Optional | Node.js 22+ for the Node.js dashboard; SearXNG for search-web; zstd CLI for exact compressed token sizes. |
Fastest (prebuilt binary, no Rust needed):
# Linux / macOS / WSL
curl -fsSL https://github.com/jimoto-no-llm/rustdsh/releases/latest/download/install.sh | bash -s -- --from-release
# Windows (PowerShell)
$f = Join-Path $env:TEMP 'rdsh-install.ps1'
Invoke-WebRequest -Uri https://github.com/jimoto-no-llm/rustdsh/releases/latest/download/install.ps1 -OutFile $f -UseBasicParsing
& $f -FromRelease
From source:
git clone https://github.com/jimoto-no-llm/rustdsh.git
cd rustdsh
./install.sh # build + install to ~/.local/bin/rdsh
./install.sh --as-dsh # also shadow `dsh` (original kept as dsh-orig)
./install.sh --restore # undo the shadowing
./install.sh --prefix=DIR # custom install dir (default ~/.local/bin)
install.sh covers Linux, macOS, and WSL (auto-detects WSL, installs Rust
via rustup unless --no-rustup). Native Windows uses install.ps1:
git clone https://github.com/jimoto-no-llm/rustdsh.git
cd rustdsh
.\install.ps1 # build + install to %LOCALAPPDATA%\rdsh\bin (+ user PATH)
.\install.ps1 -AsDsh # also shadow `dsh` (original kept as dsh-orig)
.\install.ps1 -Restore # undo the shadowing
.\install.ps1 -Wsl # also install inside WSL via install.sh
| OS | Script | Notes |
|---|---|---|
| Linux / macOS | ./install.sh |
Needs cargo or curl (rustup auto-install). |
| WSL | ./install.sh inside the distro |
Detected automatically; alongside native via install.ps1 -Wsl. |
| Windows (native) | .\install.ps1 |
Needs Rust (winget install Rustlang.Rustup); MSVC build tools required to compile. |
First boot with no model connected prints a setup pointer instead of leaving
you at the DeepSeek prompt: run rdsh setup (or rdsh setup --login to
start the Codex/opencode OAuth flow right away). Direct builds use
cargo build --release (produces target/release/rdsh).
rdsh tui # same as: dsh --profile tui (with slim env)
rdsh --profile web --patch x.yml # boot with an extra overlay
rdsh --passthrough tui # no slim env; tool isolation remains
rdsh --dry-run tui -- --resume abc # print what would be executed
Slim mode only adds environment variables; unknown keys are ignored
upstream. --passthrough toggles environment tuning and never disables
tool isolation. Details: docs/ARCHITECTURE.md.
rdsh tokens ./AGENTS.md # estimate input tokens (~4 chars = 1, CJK = 1 each)
echo ... | rdsh prune --max-tokens 4000 # keep head+tail within a token budget
rdsh search TODO --dir . --max 100 # recursive grep (parallel, same order as sequential)
rdsh compact ./s.jsonl --max-tokens 8000 # compact a session transcript (source untouched)
rdsh sessions --limit 20 --tokens # list sessions with token estimates
rdsh logs --tail 50 --grep ERROR # inspect startup logs
rdsh profiles / rdsh skills # list profiles and skills
rdsh doctor # check original dsh, DSH_HOME, slim setup
rdsh bench --n 5 # compare rdsh vs dsh startup
rdsh auth --import --provider openai-codex mirrors a login you already
did elsewhere into $DSH_HOME/.credentials.yaml, the store dsh itself reads:
~/.codex/auth.json, ChatGPT OAuth)$XDG_DATA_HOME/opencode/auth.json)rdsh auth # status: what was found, what dsh already recognizes
rdsh auth --import --provider openai-codex # write missing/older grants only (0600, others untouched)
rdsh auth --json # machine-readable status
rdsh setup # first-run wizard: import, key paste, --login/--open
rdsh setup --web # localhost setup UI (browser auto-opens, per-launch #key=... URL)
Boot, diagnostics, and setup never copy other apps credentials on their own.
Pick OAuth with --source codex or a key with --ref OPENAI_API_KEY.
Bulk import and RDSH_AUTH_AUTOSYNC are disabled.
Server-type features stay off until enabled, so a plain install remains a fast dsh:
rdsh settings set extras.enable serve,search-web
rdsh settings get extras.enable
| Extra | Command | Notes |
|---|---|---|
serve |
rdsh serve (default :38080) |
Local status page, localhost only, per-launch key. |
search-web |
rdsh search-web "query" --limit 5 |
Needs SearXNG. |
rdsh serve never collides with the dsh web GUI (:3080); --port 0
picks a free port. API and dashboard details: Web dashboard.
On Linux x86_64 with bubblewrap, prlimit, and an audited DSH, model tools are
limited to rdsh_inspect. Only copies of files you explicitly share are
mounted read-only; network and writes to host/project are denied at the kernel
level, with no host credentials or environment passed through.
rdsh --share-file README.md --share-file src/main.rs --profile tui
Shared contents can reach the model, so never share secrets. Hidden files, symlinks, and multiply linked files are refused. Unsupported platforms or DSH versions fail closed instead of running unprotected. Plugins and profiles you configured remain trusted code.
rdsh guard)guard scans stdin (hook JSON or raw text) for --deny patterns:
exit 2 blocks with a reason, exit 0 passes. --json prints
{"decision":"block"} or {}. A miss is not an approval; the host
must still enforce permissions. * matches any string. At about 1 ms
startup, per-tool-call cost is effectively zero.
echo "$input" | rdsh guard --deny "rm -rf /*" --deny "*token*"
{
"hooks": {
"PreToolUse": [
{ "matcher": "Bash", "hooks": [{ "type": "command", "command": "rdsh guard --deny \"rm -rf /*\"" }] }
]
}
}
Context generation never pulls session history automatically; use the explicit
rdsh context search. On Unix, context and recursive search open files
relative to a directory handle and refuse symlink swaps, hard links, and
special files. On Windows, native search is refused until a safe implementation
lands. This follows the dsh hook protocol: exit 2 blocks with a message the
model sees, other failures only log.
dsh)When invoked as dsh, anything that is not an rdsh-native subcommand
(tokens, guard, serve, sessions, and so on) is delegated
verbatim to the original binary, so dsh --version, dsh --profile tui,
and dsh --help stay byte-identical.
RDSH_PASSTHROUGH=1 dsh ... (no slim env), RDSH_DRY_RUN=1 dsh ... (print only).RDSH_DEFAULT_PROFILE, then local tui, else a guided error.tokens still boots via dsh --profile tokens.node "$(... dsh ...)" break while shadowed; run dsh/rdsh directly. rdsh doctor lists affected wrappers.[