Introduction¶
The DeepSeek Harness (DSH) ecosystem supports extending functionality through plugins. @MarvekG/dsh-plugins is a DSH plugin collection maintained by MarvekG, including compatibility fixes and feature enhancements. It solves two specific common issues in agent development: redundant sandbox permission request errors, and failure when clicking file paths in the Web interface.
Core Features¶
This plugin includes the following verified capabilities:
1. Handling redundant sandbox permission requests: When session permissions have been switched to danger-full-access, but retry requests still carry sandbox_permissions and justification narrower than the current permissions, the plugin automatically cleans up these redundant fields to prevent DSH from erroring with sandbox escalation is not strictly wider.
2. Changing path clicks to open a Web viewer: Intercepts native file-open requests (which may involve spawn powershell.exe) and opens them in a browser instead, resolving path invocation failures in WSL environments.
3. Multi-entry structure: Contains sandbox-same-mode and path-viewer as two independent entries, each with its own Cordis lifecycle.
4. Syntax highlighting: Relies on highlight.js for code syntax highlighting.
Installation and Enabling¶
Make sure the dsh command-line tool is installed and working properly.
Install from GitHub¶
Run the following command to install the plugin to the web profile (replace the profile name according to your actual setup):
dsh plugin --profile web add github:MarvekG/dsh-plugins
After installation or updating, you must restart DSH Web for the changes to take effect.
Upgrade from an Old Version¶
This package has been renamed from @MarvekG/dsh-bug-fix to @MarvekG/dsh-plugins. When upgrading, you must first uninstall the old package and then install the new one; the update flow cannot be used.
dsh plugin --profile web remove @MarvekG/dsh-bug-fix
dsh plugin --profile web add github:MarvekG/dsh-plugins
dsh web
Note: Do not restart DSH Web between uninstallation and reinstallation, to avoid assembly warnings caused by the missing old name.
Local Debugging and Testing¶
Local Debugging¶
After cloning the repository, run the following commands in the root directory:
dsh plugin --profile web add .
dsh web
Running Tests¶
Run the following command in the plugin directory:
npm test
Typical Usage¶
Sandbox Permission Handling¶
The plugin wraps execution functions during tool registration, covering global tools and DSH Web’s preset-scoped tools. When the following conditions are met, it removes redundant escalation fields and executes according to the current permissions:
1. sandbox_permissions is an explicitly exposed enum value in the tool schema;
2. justification is a non-empty string;
3. The requested permissions are not wider than the effective sandbox permissions of the current call and current session.
Actual permission escalations and invalid inputs are still processed according to the original flow.
Path Viewer¶
The plugin separately mounts the dsh-plugins-path-viewer entry via cordis.patch.yml.
* View a path: Access GET /view?path=<absolute path>[&line=N]. Files are rendered as a line-number table, and directories are rendered as a clickable list page.
* Configuration options:
* maxBytes: Byte limit per rendering.
* intercept: List of RPC methods to be redirected.
* Implementation mechanism: Uses webserver/index-inject to inject a script into GUI pages, intercepts host.openPath and host.openTextFile RPCs, and displays them in a new tab using window.open('/view?path=…'). If the request is intercepted, the original request is automatically allowed to pass.
Notes¶
- Always restart DSH Web after installation or updating.
- The plugin does not expand the workspace or modify
workspaceRoot; it only performs path display and permission cleanup. - The plugin is open-sourced under the MIT license.