dsh-TUI is a terminal interface plugin for DeepSeek Harness that gives the coding agent a Claude Code-style display with live status, streaming thoughts, rollback, context usage, and TPS information. It is for users who prefer a richer terminal workflow, and the catalogue entries extend the DeepSeek Harness environment with related skills and instructions.
Borrowing it
Nothing to install: this file belongs to ccch1mneyyy/dsh-TUI. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/ccch1mneyyy/dsh-TUI/main/.agents/skills/audit/SKILL.mdgit clone --depth 1 https://github.com/ccch1mneyyy/dsh-TUIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/ccch1mneyyy/dsh-tui/audit)<a href="https://agentmods.dev/skills/ccch1mneyyy/dsh-tui/audit"><img src="https://agentmods.dev/badge/skills/ccch1mneyyy/dsh-tui/audit.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00042 | $0.00309 |
| Opus 5 | $0.00021 | $0.00154 |
| Sonnet 5 | $0.00008 | $0.00062 |
| Haiku 4.5 | $0.00004 | $0.00031 |
Grade A, and why
audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Establish the audit scope, then trace the relevant runtime paths. For a findings-only request, leave code unchanged; carry out fixes when the user has requested them.
- Identify entry points, state owners, external inputs, and teardown paths within the requested scope.
- Follow inputs through validation and consumers. In this TUI, inspect applicable session projections, plugin capabilities, file access, terminal escape handling, and long-session resource bounds. Prioritize paths whose failure can lose state, cross a trust boundary, or leave the terminal unusable. Check dependencies and lockfiles for known vulnerabilities against advisory data.
- Confirm suspected defects against callers, existing guards, and focused regressions. Check exports, registries, and supported compatibility paths before declaring code dead. Explain a simplification in terms of current requirements and the behavior it preserves.
- Report confirmed findings by severity with location, trigger, impact, and a concrete remedy. Keep unverified leads separate. For a cross-layer failure, a short input → boundary → effect trace may be enough to explain it.
- State the areas examined, checks actually run, and material gaps. No findings means none found in that scope, not proof that the whole project is safe. An audit can finish without findings or a forced list of healthy areas.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed · -11 lines · +5 tokens per session 99fd3bc56d7e
- 8d ago First seen · 25 lines · 37 tokens per session scan A 8cf852c43daf
audit is a skill published in the GitHub repository ccch1mneyyy/dsh-TUI (2,884 stars, last pushed today), licensed MIT. It adds 42 tokens to every session and 309 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
review-changes
Review local code changes for concrete correctness, regression, security, and test gaps before shipping.
dsh-code-review
Use when reviewing a pull request in the deepseek-harness repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality gates) and the review-specific checks that code alone can't show.
dsh-find-simplifications
Use when working in the deepseek-harness repo to find non-obvious simplification candidates, remove redundant comments or implementation-heavy documentation, write proposed Agent Notes or inline TODO/FIXME/XXX notes, audit or coalesce superseded Agent Notes, or fold worthwhile simplification ideas from another PR…
submit-dsh-plugin
A submission checklist and workflow for adding a DeepSeek Harness plugin to the community’s public catalogue. It prepares the catalogue entry and checks the plugin’s repository, metadata, tests, and required files.
karpathy-guidelines
A set of coding guidelines based on observations about common mistakes made by language models. It emphasizes simple solutions, small targeted edits, clear assumptions, and checkable results.
babysit-pr
Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…