
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
Batteries-included capability suite for DeepSeek Harness: MCP manager with lazy proxy + OAuth, parallel steerable subagents, side conversations, image generation — one install, every piece verified end to end.
One install that turns a stock DeepSeek Harness into a batteries-included agent workstation.
dsh plugin --profile <your-profile> add dsh-work-x
Restart dsh (plugins mount at startup). That is the entire setup: the suite
carries the pi2dsh engine and four
capability packages, versions pinned to combinations that have been verified
end to end on a real DSH loop — never "should work", always "was watched
working".
一条命令,把官方 DSH 变成开箱即用的全能 agent 工作台。装完重启 dsh 即可; 所有组件版本锁死在真机端到端验收过的组合上。
| Capability | Stock DSH | dsh-x |
|---|---|---|
| MCP | Config-file servers, statically mounted; every tool costs context window | Lazy proxy (one tool + on-demand search/describe — dozens of servers without eating context), in-session manager, OAuth flows, MCP Apps (ui://), prompts→slash-commands, elicitation, sampling, fast cancellation — full verified matrix |
| Subagents | Low-level agent registry, no product surface | Spawn / parallel / background delegation, mid-run steering, resume (in-session and across restarts), stop-with-parent, per-child model & thinking level, live inheritance of your /model switches — acceptance report |
| Side conversations | — | /btw <question>: ask something off-topic without polluting the main context; answer lands in a side panel |
| Image generation | — | Codex-backed image generation as a normal tool call, generated pixels shown inline (bring your own Codex credential) |
The suite: pi-mcp-adapter ·
@tintinweb/pi-subagents ·
pi-btw ·
@crazygit/pi-codex-image-gen,
running unmodified through the pi2dsh compatibility engine. Vision companion
routes are off in this suite; subscription logins stay whatever your DSH
profile already has.
dsh-work-x targets dsh web (and the desktop shells that wrap it) as its primary
surface. The automated regression drives a real browser against a clean
install and asserts each bundled package's own command is offered by the
composer — not that a file exists somewhere.
dsh plugin --profile web add dsh-work-x dsh-better-sidebar
dsh web --port 5179
dsh-better-sidebar is the
community sidebar the suite's product UI seats into: its Tasks page shows your
subagents natively (click through to steer or stop them), and dsh-work-x adds an
MCP tab there — this session's servers grouped by layer (project /
global), with per-project enable/disable. A machine-wide view of the same
servers lives in Settings → MCP and works with or without the sidebar.
Without dsh-better-sidebar everything still runs; you just lose those two
panels. (DSH has no way yet for one plugin to declare a companion bundle —
we've proposed one —
so the install command names both.)
Override engine config in your profile's user patch layer
($DSH_HOME/profiles/<p>/cordis.patch.yml), targeting the row by id — never
insert a second row:
- id: pi2dsh
config:
exclude: ["pi-btw"] # drop a suite member you don't want
Plugin-specific settings follow each plugin's own environment variables and slash commands, as documented by the plugin.
dsh-work-x is a normal DSH bundle. Its patch mounts the pi2dsh engine (re-exported
through this package, so it resolves under pnpm's isolated layout), and the
engine reads this package's pi2dsh.suite manifest — an explicit list, one
dependency-hop from your profile — and mounts each member exactly as if you
had dsh plugin add-ed it yourself. No directory scanning, no forks, no
patched DSH internals; remove it with dsh plugin remove dsh-work-x and the whole
suite is gone.
dsh-work-x is the curated product; pi2dsh is the engine and remains independently installable for anyone who wants to pick their own Pi packages. Anything verified for pi2dsh is inherited here at the same version pins.
FAQs
Batteries-included capability suite for DeepSeek Harness: MCP manager with lazy proxy + OAuth, parallel steerable subagents, side conversations, image generation — one install, every piece verified end to end.
The npm package dsh-work-x receives a total of 24 weekly downloads. As such, dsh-work-x popularity was classified as not popular.
We found that dsh-work-x demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.