The default file sandbox in DeepSeek Harness (DSH) restricts write permissions to the session working directory (cwd). If you need to write files under another registered workspace directory, you typically need to escalate permissions through the sandbox. This increases the configuration overhead when developing agents or working with workspaces.

dsh-multi-workspace is a plugin designed for DeepSeek Harness, developed by maintainer somnusovis. Its core purpose is to automatically grant file write access to all registered workspaces.

Core Features

This plugin implements multi-workspace writes through a two-layer mechanism:

  1. Extended sandbox policy: On each sandbox policy check, it reads the real-time workspace registry and injects the path of each registered workspace into sandboxPolicy.resolve().
  2. Filesystem retry: It wraps fs.writeText and fs.editText, and when encountering a write denial, attempts a silent retry using the root path of the target workspace.

Installation and Enabling

Use the official plugin installation command to add the plugin:

dsh plugin --profile web add github:somnusovis/dsh-multi-workspace

After installation, restart the DSH Web service and refresh the browser.

Typical Usage

After adding a workspace in the DSH UI, you can directly use file-writing tools (such as fs.writeText or editText) to operate on that workspace without any additional configuration steps.

Notes and Limitations

  1. Shell command scope is limited
    This plugin only extends the write scope of filesystem tools. The underlying command sandbox (@deepseek-ai/dsh-sandbox-local) still reads only a single policy.workspaceRoot. Therefore, commands such as pwsh or bash are still denied when attempting to write outside the session directory.

  2. Silent retry and trust mechanism
    When a file write fails, the plugin silently retries under the workspace-write permission, bypassing the approval workflow. This means the plugin runs with the permissions of the current DSH process. Before using it, make sure that any registered workspace is trusted.

  3. API return value requirement
    The wrapped resolve() function must return a Plain Object containing its own properties such as mode, workspaceRoot, and sessionId. If the returned value relies on prototype chain inheritance, the executor may lose these critical keys when expanding the object, causing runtime errors (such as SANDBOX_UNAVAILABLE).

Summary

dsh-multi-workspace addresses the limitation that DSH’s default sandbox supports writes only to a single workspace. For development scenarios that require frequent switching among multiple workspaces and directly writing files, this plugin streamlines the process by automatically injecting paths and using a silent retry mechanism.