Introduction

DSH Web plugin: Exposes a strictly constrained read-only image route on a Web server, allowing agents to directly embed images from the workspace in the conversation.

When using DSH Web UI, the Markdown renderer treats http(s) links as images, but the server usually does not provide static routes for workspace files (unmatched paths fall back to the SPA), and the renderer’s URL sanitizer rejects data:-formatted content. As a result, charts generated by agents (such as matplotlib PNGs) could previously only be presented as “clickable files” and could not be viewed directly within the conversation flow.

Installation and Enablement

Run the following command to install the plugin into the web profile:

dsh plugin --profile web add dsh-plugin-inline-image

After installation, the dsh web process must be restarted to load the plugin. After editing ~/.dsh/profiles/web/package.json to add the plugin to the bundles manifest, restart again for the change to take effect.

Configuration

Append the plugin configuration to ~/.dsh/profiles/web/cordis.patch.yml. If roots is not configured, the plugin automatically falls back to all workspaces already registered by the harness.

- insert:
    - id: inline-image
      name: 'dsh-plugin-inline-image'
      config:
        # alias -> 允许对外提供图片的绝对目录
        roots:
          sixsigma: /Users/guoguo/6sigma
        # 默认 false:.svg 不开放(可携带脚本,XSS 风险);确需时改为 true
        allowSvg: false

Usage

After configuring roots, agents can reference images in conversations using Markdown syntax. It is recommended to instruct agents to use this format in prompts.

  • Basic usage: ![distribution chart](/dsh-image/sixsigma/distributions.png)
  • Subdirectory usage: ![](/dsh-image/sixsigma/reports/chart.webp)

Security Mechanism

The plugin ensures security through a defense-in-depth strategy:

  1. HTTP method restriction: Only GET and HEAD methods are allowed; other methods return 405.
  2. Path validation: Path segments are URL-decoded and checked for empty values, ./.., or / to prevent path traversal.
  3. Lexical and physical checks: After path resolution and normalization, the path must remain within the root directory; use realpath() to resolve symbolic links and validate again to prevent escape.
  4. Extension whitelist: Only common raster image formats are supported (png/jpg/jpeg/webp/gif/avif/bmp/ico). SVG is disabled by default to prevent XSS attacks; enable manually if needed.

Summary

This plugin resolves the problem in the DSH ecosystem where agents find it difficult to directly display local workspace images. A controlled read-only route enables inline display. Restart the service after installation, and pay attention to path security restrictions during configuration.

  • Plugin directory: https://www.skillhub.cn/plugins/usavv1547-cyber/dsh-plugin-inline-image
  • Source code: https://github.com/usavv1547-cyber/dsh-plugin-inline-image