SSH/SFTP 远程站点与远程工作区:像本地工作区一样管理远程连接与目录。
安装
# Release 预构建包
dsh plugin --profile web add "https://github.com/Hefulalala/dsh-remote-workspace/releases/download/v0.1.0/dsh-external-dsh-remote-workspace-0.1.0.tgz"
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:Hefulalala/dsh-remote-workspace
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
A plugin for DSH that brings SSH/SFTP remote workspaces into the workspace sidebar — alongside your local directories.
- Remote site = one SSH/SFTP connection profile (host / user / auth / home directory), managed from the 🌐 Remote Sites button.
- Remote workspace = a remote site + a directory on that server. It appears in the left workspace tree exactly like a local workspace, owns its own sessions, and lets the agent read/write remote files directly.
- Unified "Add Workspace" flow — the same add-workspace entry point now asks you to choose a connection first: Local (this computer) or one of your remote sites.
中文速览
- 远程站点:SSH/SFTP 连接配置(主机 / 用户 / 认证 / 家目录),左下角“🌐 远程站点”管理。
- 远程工作区:远程站点 + 远程目录;和本地目录一样出现在左侧栏、按工作区分组 session。
- 统一添加入口:左侧栏“添加工作区”先选连接(本地 / 远程站点 / 新建站点),再选目录。
- 默认家目录:站点配置中目录留空时,自动通过 SFTP 解析服务器真实 home。
- Agent 工具:
remote_site_*管理连接,remote_workspace_*在会话中直接读写远程文件。
Features
Site management (bottom-left panel)
- Add / edit / test / delete SSH/SFTP connection profiles
- Auth modes: password, private key file (host path), or SSH Agent
- Empty home path is resolved via SFTP
realpath('.')to the server's real home
Unified add-workspace flow (left sidebar)
- Step 1 — choose connection: local computer, an existing remote site, or create a new site
- Step 2 — choose directory:
- Local → native-style directory browser (breadcrumbs, enter folders, create folder)
- Remote → SFTP directory browser starting at the site home; supports navigation and folder creation
- One site can host multiple remote workspaces
Native workspace/session grouping
- Each remote workspace gets a local anchor directory (
$DSH_HOME/remote-workspaces/<id>/) - The anchor is registered into DSH's
workspaceRegistry, so remote workspaces appear and behave like local ones: click to start a session, session history stays grouped AGENTS.mdis generated in the anchor: the agent learns the real remote endpoint/root and routes file operations throughremote_workspace_*tools
- Each remote workspace gets a local anchor directory (
Agent tools
remote_site_list / add / test / rename / update / remove / browseremote_workspace_list / add / browse / read / write / test / remove- Path traversal protection (everything is confined to the workspace root), read/write size limits
Security
- SSH host-key TOFU: first connection records
sha256:<fingerprint>, later connections reject mismatches - Config is persisted in
$DSH_HOME/storages/remote-workspaces.jsonwith0600permissions - Deleting sites/workspaces never deletes remote files; session logs are preserved
- SSH host-key TOFU: first connection records
Install
The package declares a dsh.bundle manifest, so it is installable through
DSH's plugin command and by plugin storefronts such as
dsh-market.
Option A — GitHub Release tarball (recommended)
Download
dsh-external-dsh-remote-workspace-0.1.0.tgzfrom the Releases page.Extract and prepare it:
mkdir -p ~/dsh-plugins tar -xzf dsh-external-dsh-remote-workspace-0.1.0.tgz -C ~/dsh-plugins bash ~/dsh-plugins/package/install.sh # installs ssh2 and validates artifactsInject it from your DSH session:
# DSH injector environment: # dev_inject_plugin ~/dsh-plugins/packageRefresh the DSH web page.
Option B — DSH plugin manager
The repo ships dsh.bundle.patch + cordis.patch.yml, so a DSH install that
supports bundle installation can add it directly:
dsh plugin --profile web add Hefulalala/dsh-remote-workspace
Option C — build from source
git clone https://github.com/Hefulalala/dsh-remote-workspace.git dsh-remote-workspace
cd dsh-remote-workspace
# Install the runtime dependency (and, if you want local builds, the toolchain):
npm install --omit=dev ssh2
npm install --save-dev typescript tsdown @types/node @types/react @types/react-dom @types/ssh2
bash scripts/build.sh # host: src/index.ts → lib/
npm run build:client # client: src/client/index.tsx → lib/client.js
# In the DSH injector environment:
# dev_inject_plugin /absolute/path/to/dsh-remote-workspace
scripts/build.sh auto-detects a DSH source checkout (DSH_CHECKOUT) for peer-type linking;
otherwise it falls back to the locally installed toolchain.
Usage
Open 🌐 Remote Sites in the bottom-left sidebar and add a site:
Field Notes Host / Port / Username SSH target Home directory optional; empty = auto-detect the remote home Auth password / private-key file / SSH agent Click Add Workspace in the left workspace tree:
- Choose Local → pick a local folder (same as before)
- Choose a remote site → pick a remote folder (starts at the site home)
- Choose New remote site → configure the connection, then continue to folder selection
A remote workspace now appears in the left tree. Click it to open a new session, then just talk to the agent, e.g.:
"Read /srv/app/config.yml and change the port to 8081"
The agent resolves paths against the remote root and uses remote_workspace_read/write automatically (guided by the generated AGENTS.md).
Security notes
- MVP storage: passwords and private-key passphrases are currently stored in plain text inside a
0600JSON file. For production, wire the plugin to DSH's credentials service or an OS keyring. - Private keys are never copied into the plugin store — only the host path is saved.
- Remote file APIs are same-origin and enforce workspace-root confinement (8 MB write cap, 2 MB default read cap).
- Host fingerprint changes cause the connection to be rejected (manual fix: edit the site / re-add).
Agent tools
| Tool | Purpose |
|---|---|
remote_site_list |
List configured SSH/SFTP connection profiles |
remote_site_add |
Add a site (tests the connection; home defaults to the remote home) |
remote_site_test |
Test a site connection |
remote_site_rename |
Rename a site (auto-derived workspace names follow) |
remote_site_update |
Update connection/auth/home of a site |
remote_site_remove |
Remove a site and its workspace registrations |
remote_site_browse |
Browse site directories (workspace folder picking) |
remote_workspace_list |
List remote workspaces |
remote_workspace_add |
Create a workspace for siteId + rootPath |
remote_workspace_browse |
Browse a workspace directory |
remote_workspace_read |
Read a remote file (binary → base64) |
remote_workspace_write |
Overwrite a remote file (utf8/base64) |
remote_workspace_append |
Append to a remote file (no whole-file rewrite) |
remote_workspace_write_at |
Patch part of a remote file at a byte offset |
remote_workspace_test |
Test a workspace root |
remote_workspace_remove |
Remove the sidebar grouping only |
Host HTTP API
Prefix: /remote-workspaces/api — every response is {ok:true,value} or {ok:false,error:{code,message}}.
| Method | Route | Purpose |
|---|---|---|
| GET | /ping |
Health check |
| GET | /sites/list |
List sites |
| POST | /sites/add |
Add site |
| POST | /sites/test |
Test site |
| POST | /sites/rename |
Rename site |
| POST | /sites/update |
Update site |
| POST | /sites/remove |
Remove site |
| POST | /sites/browse |
Browse a site directory |
| POST | /sites/mkdir |
Create a remote folder |
| GET | /workspaces/list |
List remote workspaces |
| POST | /workspaces/add |
Create remote workspace (siteId, optional rootPath, optional name) |
| POST | /workspaces/ensure |
Ensure sidebar anchor exists |
| POST | /workspaces/rename |
Rename workspace |
| POST | /workspaces/remove |
Remove workspace |
| POST | /workspaces/test |
Test workspace root |
| POST | /workspaces/browse |
Browse workspace directory |
| POST | /workspaces/read |
Read file (cached by mtime+size) |
| POST | /workspaces/write |
Write file |
| POST | /workspaces/append |
Append to a file |
| POST | /workspaces/writeat |
Patch part of a file at a byte offset |
| GET | /pool-stats |
Connection-pool and file-cache stats |
Data model
$DSH_HOME/storages/remote-workspaces.json (v2):
sites[]— connection profiles: host, port, user, auth, resolvedhomePath, host fingerprintworkspaces[]—siteId+rootPath+ sidebar anchor (localWorkspaceId)
Version 1 stores are migrated automatically on first load.
Development
src/index.ts Host: data model, SSH2/SFTP, workspaceRegistry anchors, HTTP API, tools
src/client/index.tsx Client: Remote Sites panel + unified add-workspace flow
cordis.patch.yml dsh.bundle patch used by `dsh plugin add`
scripts/build.sh Host build
scripts/smoke.mjs Artifact smoke test
lib/ Build output
More design details: docs/architecture.md · CHANGELOG.md.
- Host services required:
webServer,tools,workspaceRegistry - Client services required:
slots,workspaces - The client shadows DSH's built-in directory-flow slots at priority
-1and wraps local-picking behavior, so removing the plugin cleanly restores the built-in flow.
Known limitations
- Remote file editing happens through the agent tools; the site panel itself only manages connections
- Connections are pooled per site (idle TTL + auto-reconnect); hot-path file ops also get an
mtime+sizecontent cache - No remote rename/delete, directory sync, or conflict handling yet
- Passwords are stored in plain text (see Security notes)
License
BSD-3-Clause © 2026 dsh-remote-workspace contributors. See LICENSE.
链接
同类插件
Tencent/WeKnora#dsh-weknora★ 31680
把 WeKnora 知识库接入 dsh 的四个只读工具:列出知识库、混合检索原文片段、按顺序还原单篇文档,以及直接取用 WeKnora 自己带引用的 RAG 或 ReAct agent 回答(含可续聊的 session id)。
superdesigndev/treg★ 3995
给 Agent 的工具目录:按「要做的事」检索约 2,600 个外部接口(SEO 与 SERP、外链、社交、人物与公司信息补全、广告库、抓取),查看参数与单次调用价格后直接调用,凭据由服务端注入。附带技能,MCP 行在未设置 TREG_TOKEN 前保持禁用。
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1130
把腾讯云 CloudBase 后端接入 DeepSeek Harness——在对话里搭好并部署全栈应用,查询结果渲染为表格卡片(分页、排序、导出 CSV),部署后可预览真实域名,并提供 CloudBase MCP 工具集(`mcp__cloudbase__*`),登录走 device-code 流程。
gitroomhq/postiz-agent#dsh-postiz★ 499
通过 MCP 将 DeepSeek Harness 连接到 Postiz:列出已连接的社交媒体渠道、获取各平台发帖规则,并向 X、LinkedIn、Instagram、Facebook、Threads、TikTok、YouTube、Reddit、Bluesky、Mastodon、Discord、Slack、Telegram 等平台排期、存草稿或发布帖子;附带 postiz 工作流技能。
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 477
面向 DeepSeek Harness 的本地 IMAP 发票下载、OCR 识别、归档与 Excel 报销汇总。
anysearch-team/anysearch-dsh★ 443
基于 AnySearch 的实时网页与垂直搜索插件,为 DeepSeek Harness 提供搜索工具。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。