Introduction

The DeepSeek Harness (DSH) ecosystem supports extending functionality through plugins. @MarvekG/dsh-plugins is a DSH plugin collection maintained by MarvekG, including compatibility fixes and feature enhancements. It solves two specific common issues in agent development: redundant sandbox permission request errors, and failure when clicking file paths in the Web interface.

Core Features

This plugin includes the following verified capabilities:
1. Handling redundant sandbox permission requests: When session permissions have been switched to danger-full-access, but retry requests still carry sandbox_permissions and justification narrower than the current permissions, the plugin automatically cleans up these redundant fields to prevent DSH from erroring with sandbox escalation is not strictly wider.
2. Changing path clicks to open a Web viewer: Intercepts native file-open requests (which may involve spawn powershell.exe) and opens them in a browser instead, resolving path invocation failures in WSL environments.
3. Multi-entry structure: Contains sandbox-same-mode and path-viewer as two independent entries, each with its own Cordis lifecycle.
4. Syntax highlighting: Relies on highlight.js for code syntax highlighting.

Installation and Enabling

Make sure the dsh command-line tool is installed and working properly.

Install from GitHub

Run the following command to install the plugin to the web profile (replace the profile name according to your actual setup):

dsh plugin --profile web add github:MarvekG/dsh-plugins

After installation or updating, you must restart DSH Web for the changes to take effect.

Upgrade from an Old Version

This package has been renamed from @MarvekG/dsh-bug-fix to @MarvekG/dsh-plugins. When upgrading, you must first uninstall the old package and then install the new one; the update flow cannot be used.

dsh plugin --profile web remove @MarvekG/dsh-bug-fix
dsh plugin --profile web add github:MarvekG/dsh-plugins
dsh web

Note: Do not restart DSH Web between uninstallation and reinstallation, to avoid assembly warnings caused by the missing old name.

Local Debugging and Testing

Local Debugging

After cloning the repository, run the following commands in the root directory:

dsh plugin --profile web add .
dsh web

Running Tests

Run the following command in the plugin directory:

npm test

Typical Usage

Sandbox Permission Handling

The plugin wraps execution functions during tool registration, covering global tools and DSH Web’s preset-scoped tools. When the following conditions are met, it removes redundant escalation fields and executes according to the current permissions:
1. sandbox_permissions is an explicitly exposed enum value in the tool schema;
2. justification is a non-empty string;
3. The requested permissions are not wider than the effective sandbox permissions of the current call and current session.

Actual permission escalations and invalid inputs are still processed according to the original flow.

Path Viewer

The plugin separately mounts the dsh-plugins-path-viewer entry via cordis.patch.yml.
* View a path: Access GET /view?path=<absolute path>[&line=N]. Files are rendered as a line-number table, and directories are rendered as a clickable list page.
* Configuration options:
* maxBytes: Byte limit per rendering.
* intercept: List of RPC methods to be redirected.
* Implementation mechanism: Uses webserver/index-inject to inject a script into GUI pages, intercepts host.openPath and host.openTextFile RPCs, and displays them in a new tab using window.open('/view?path=…'). If the request is intercepted, the original request is automatically allowed to pass.

Notes

  1. Always restart DSH Web after installation or updating.
  2. The plugin does not expand the workspace or modify workspaceRoot; it only performs path display and permission cleanup.
  3. The plugin is open-sourced under the MIT license.