
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-opencode-provider
Advanced tools
Use OpenCode models inside DeepSeek Harness without a separate provider API key.
Use models available through a local OpenCode server inside DeepSeek Harness without a DeepSeek API key.
DeepSeek Harness (DSH)
└─ LLM Runtime
└─ opencode-local provider route
└─ OpenCodeAdapter (dsh-opencode-provider)
├─ POST /api/session → create session
├─ POST /api/session/{id}/prompt → serialized conversation
├─ GET /api/session/{id}/event → SSE stream
└─ POST /api/session/{id}/interrupt → best-effort cancel
↕ HTTP + SSE
OpenCode Server (127.0.0.1:4096)
↕
Model (mimo-v2.5-free)
The adapter serializes the full DSH conversation (system prompt + messages) into a single prompt string, sends it to the OpenCode server, and translates the SSE event stream into DSH StreamChunk values. OpenCode runs its own internal agent/tool loop, so the adapter exposes text output only — structured DSH tool calling is not available.
session.text.delta, session.execution.succeeded) and current (session.next.text.delta, session.next.step.ended) event envelopesdata.wrapper envelopes are unwrapped defensivelyhttp://127.0.0.1:4096)dsh plugin --profile web add dsh-opencode-provider
git clone https://github.com/goku54477/dsh-opencode-provider.git
cd dsh-opencode-provider
pnpm dsh
opencode serve --hostname 127.0.0.1 --port 4096
The adapter auto-configures with the default base URL (http://127.0.0.1:4096). No additional setup is needed.
In DeepSeek Harness, select the model:
opencode-local/mimo-v2.5-free
All fields are optional. Defaults work out of the box with a local OpenCode server.
# Inside your DSH cordis.yml or plugin config
llm-opencode:
# Endpoint of the OpenCode server
baseURL: "http://127.0.0.1:4096"
# Context window reported to the harness (default: 128000)
defaultContextWindow: 128000
# Max output tokens per request (default: 16384)
maxTokens: 16384
# Advisory model list for discovery consumers
models:
- id: mimo-v2.5-free
name: mimo-v2.5-free
description: "OpenCode local agent (text output only)"
contextWindow: 128000
# Retry policy
retryPolicy:
mode: always
backoff:
initialDelayMs: 100
maxDelayMs: 5000
jitterRatio: 0.2
POST /api/session with { model: { id, providerID: "opencode" } }GET /api/session/{id}/event) and prompt delivery (POST /api/session/{id}/prompt) concurrently. This avoids a deadlock where the OpenCode server withholds SSE headers until the session has activity.[System]\n...\n\n[User]\n...\n\n[Assistant]\n... and embedded in the prompt.session.text.delta, session.next.step.ended, session.execution.succeeded, etc.) are mapped to DSH StreamChunk types (block-start, text-delta, block-end, finish).# Build
npm run build
# Type-check
npm run typecheck
# Run tests
npm run test
# Build + test
npm run check
# Clean output
npm run clean
This plugin communicates with a local HTTP server (no TLS by default). Do not expose the OpenCode server to untrusted networks. The default binding (127.0.0.1) restricts access to the local machine.
v0.1.0 has been tested on the following exact environment:
| Component | Version |
|---|---|
| OS | Windows 11 |
| Node.js | 22.23.2 |
| DeepSeek Harness | 0.1.0-rc.8 |
| OpenCode | 1.18.19 |
| Model | opencode/mimo-v2.5-free |
Other platforms, Node versions, harness releases, OpenCode versions, and models have not been verified. The adapter may work elsewhere, but no guarantees are made.
inputModalities: ["text"] only. Image/audio/video inputs are not forwarded.mimo-v2.5-free. Adding models requires manual config; the adapter does not dynamically discover available models from the server.stream() call creates a fresh OpenCode session. Conversation state is not preserved across requests.127.0.0.1. Remote servers require manual baseURL configuration and appropriate network access.FAQs
Use OpenCode models inside DeepSeek Harness without a separate provider API key.
The npm package dsh-opencode-provider receives a total of 127 weekly downloads. As such, dsh-opencode-provider popularity was classified as not popular.
We found that dsh-opencode-provider demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.