Multi-workspace sandbox: grants file-write access to every registered workspace automatically — add a workspace, write to it immediately, no config or escalation needed.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:somnusovis/dsh-multi-workspace
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Multi-workspace sandbox for DeepSeek Harness (DSH).
Automatically grants file-write access to ALL registered workspaces — add a workspace in the UI, write to it immediately, no config needed.
Problem
By default, DSH file sandbox only allows writes to one workspace directory (the session cwd). Writing to other directories requires sandbox escalation.
Solution
This plugin reads the live workspace registry on every sandbox policy check and injects every registered workspace path as an additional writable root.
How it works
Two layers:
- Wraps sandboxPolicy.resolve() to attach workspace paths
- Wraps fs.writeText/editText with retry fallback on each workspace root
Limitations
- Shell commands stay confined to the session workspace. The multi-workspace
widening applies to the fs tools only (layer 2 re-issues each denied write
with the target workspace's root). The command sandbox seam
(
@deepseek-ai/dsh-sandbox-local, windows-acl / bwrap / seatbelt) reads only the singlepolicy.workspaceRoot, sopwsh/ bash writes outside the session workspace are still denied. - The fs fallback silently retries under
workspace-writewithout going through the approval flow. That is the plugin's intended "write immediately" behavior — make sure the registered workspaces are trusted. - The wrapped
resolve()must return a plain object (ownmode/workspaceRoot/sessionId): executors spread the policy ({ ...policy }), and a prototype-based copy silently drops those keys, making the windows-acl runner fail with--workspace undefined(SANDBOX_UNAVAILABLE).test/smoke.mjsguards this regression.
Installation
dsh plugin --profile web add github:somnusovis/dsh-multi-workspace
# Or from npm (once published)
dsh plugin --profile web add dsh-multi-workspace
Restart DSH web service and refresh browser.
License
MIT
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 31292
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 3854
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1128
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 499
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 474
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 438
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.