In DeepSeek Harness (DSH) session permission control, there are usually only two options: “Workspace Only” or “All”. When a balance is needed between the two, i.e., restricting the agent to write only to specific directories, the dsh-workspace-scope-selection plugin provides a fourth option: Selected Workspace Write.

Plugin Overview

This plugin is maintained by jiangr100 and uses the MIT License. It adds a new permission option in the composer, allowing users to precisely specify writable directories through a directory tree editor, and enforces this restriction in the file system and Shell tools.

Installation and Enablement

Install using the file: protocol, then restart dsh web.

dsh plugin --profile web add file:/path/to/dsh-workspace-scope-selection

After installation is complete, restart the dsh web process to load the plugin.

Core Features

  1. Permission Option
    Adds the Selected Workspace Write option to the composer’s permission chip (or via the /permission command).

  2. Directory Tree Editor
    After selecting this option, a directory tree editor opens. Checked directories are the writable scope. The workspace root directory is checked by default; uncheck it to make it read-only. Unchecking a parent directory removes its entire subtree; subdirectories checked via a parent directory display a “via parent” label.

  3. Sandbox Mode
    The plugin adds a selected-workspace-write mode to the file system and Shell/terminal sandboxes. Only selected directories (plus the platform temporary area) are writable.

  4. Session Persistence
    The selection result is stored in the session log and remains valid after the session is restarted.

  5. Access Control
    Any write operation beyond the selected scope is rejected and must go through the approval escalation process.

Usage Steps

  1. Click the permission chip or enter /permission, and select Selected Workspace Write.
  2. In the editor, check the directories you allow the agent to write to.
  3. Click Done to immediately apply the scope restriction.

Notes

  • General Settings Difference: In the permission row of “General Settings”, only the three built-in options are still displayed; the option provided by this plugin is a per-session toggle.
  • Windows Platform Limitation: On Windows, only the workspace and temporary area are writable; additional selected root directories will be denied writes.
  • Write Approval: Any write operation beyond the selected scope always requires escalated approval.