Preface¶
The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In real-world use, developers or users usually only need to chat, search the web, or view history; they do not want to introduce risks of file writes or command execution. Existing sessions may already have complex tools configured, and switching modes can easily trigger them by accident. The dsh-no-workspace plugin was created to solve this problem. It provides DSH with a dedicated “read-only session” entry point.
Plugin Overview¶
dsh-no-workspace is a community plugin maintained by Syhz-666 and released under the MIT License. It does not modify the official DeepSeek source code; instead, it extends the official Web build through in-memory injection. Its core value is to provide a “no workspace” session mode and structurally lock that mode as read-only.
Core Capabilities¶
The plugin mainly includes the following capabilities:
- No Workspace (Read-only session): Adds an entry to the official workspace selector. Selecting it directly creates a session without a workspace; the working directory is an isolated empty directory located at
$DSH_HOME/.dsh-no-workspace/<sessionId>/. - Structural read-only locking: At session startup, it writes zero-length
turn/startandturn/endfiles so that they are permanently non-blank. This triggers the official preset-switch guard and permanently rejects any upgrade or change to the tool surface. - Zero coupling with the official build: The plugin does not modify official source code or build artifacts. Menu items are injected into the official bundle in memory at service startup through precise routing. No replay is required after the official project is rebuilt or upgraded.
- Immutable tool surface: The
no-workspacepreset mounts only read-only tools; the official Shell and write tools (tool-fs) are never mounted. - Controlled file access: Reading absolute paths requires approval each time. Relative paths inside the isolation root are approved by default. Reads from non-session directories are denied directly.
- No writes or commands: The session contains no Shell, no write tools, and no sub-agents.
Installation and Activation¶
Before using the plugin, ensure that you have a built official DSH project locally.
- Obtain the plugin source code and build it:
git clone <仓库地址> dsh-no-workspace
cd dsh-no-workspace
pnpm install && pnpm run build
- Install the plugin inside the official DSH project directory:
cd <dsh 项目目录>
pnpm dsh plugin --profile web add <插件目录的绝对路径>
- Restart DSH Web and refresh the browser:
pnpm dsh web
(The browser requires a hard refresh with Ctrl+F5 to load the new menu.)
How to Use¶
There are three ways to enter the read-only session provided by the plugin:
- Open the workspace selector and select “No Workspace (Read-only session)”;
- Type the
/readonly-sessioncommand in any session; - Select “Read-only session” from the mode selector.
Sessions created through the “No Workspace” menu or command default to deepseek-v4-flash + reasoningEffort: 'low', and can be manually changed at any time within the session. Sessions entered by switching from the mode selector retain their original model configuration.
Security Model¶
The plugin guarantees read-only behavior through mechanisms:
- Locking mechanism: Once a session is marked as read-only, the system writes
turn/startandturn/end, ensuring they are no longer blank. The official preset-switch guard (agent-preset-locked) permanently rejects any preset change, ensuring that the tool surface cannot be upgraded. - Tool restrictions: The
no-workspacepreset contains only read-only tools and disables all write and Shell capabilities. - File permissions: Although sandbox mode can be switched, the permission control has no practical effect under the current mode because no write tools consume broader permissions. File access follows isolation-root rules: absolute paths require approval, and relative paths inside the isolation root are approved by default.
Notes¶
- This plugin is a community plugin and is not an official DeepSeek product.
- The plugin runs with the permissions of the current DSH process. It is recommended to review the source code and license before installation.
- Because the tool surface is structurally locked, tools cannot be upgraded in a read-only session through the plugin mechanism.
Conclusion¶
dsh-no-workspace adds a safe “chat” and “search” layer to DeepSeek Harness. Through a zero-coupling architecture and structural locking mechanisms, it achieves session isolation and read-only protection without modifying the official code. For more details, visit the plugin directory page or the GitHub repository.