DeepSeek Harness 插件

somnusovis/dsh-multi-workspace

Star 数 ★ 1 分类 工具与能力 收录于 2026-08-16

多工作区沙箱:自动赋予所有已注册工作区的文件写入权限——添加工作区后即可直接写入,无需配置或提权。

安装

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:somnusovis/dsh-multi-workspace

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

该插件的 README 只有英文版本。

Multi-workspace sandbox for DeepSeek Harness (DSH).

Automatically grants file-write access to ALL registered workspaces — add a workspace in the UI, write to it immediately, no config needed.

Problem

By default, DSH file sandbox only allows writes to one workspace directory (the session cwd). Writing to other directories requires sandbox escalation.

Solution

This plugin reads the live workspace registry on every sandbox policy check and injects every registered workspace path as an additional writable root.

How it works

Two layers:

  1. Wraps sandboxPolicy.resolve() to attach workspace paths
  2. Wraps fs.writeText/editText with retry fallback on each workspace root

Limitations

  • Shell commands stay confined to the session workspace. The multi-workspace widening applies to the fs tools only (layer 2 re-issues each denied write with the target workspace's root). The command sandbox seam (@deepseek-ai/dsh-sandbox-local, windows-acl / bwrap / seatbelt) reads only the single policy.workspaceRoot, so pwsh / bash writes outside the session workspace are still denied.
  • The fs fallback silently retries under workspace-write without going through the approval flow. That is the plugin's intended "write immediately" behavior — make sure the registered workspaces are trusted.
  • The wrapped resolve() must return a plain object (own mode / workspaceRoot / sessionId): executors spread the policy ({ ...policy }), and a prototype-based copy silently drops those keys, making the windows-acl runner fail with --workspace undefined (SANDBOX_UNAVAILABLE). test/smoke.mjs guards this regression.

Installation

dsh plugin --profile web add github:somnusovis/dsh-multi-workspace

# Or from npm (once published)
dsh plugin --profile web add dsh-multi-workspace

Restart DSH web service and refresh browser.

License

MIT

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →

社区评论

评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。