Agents can quickly generate reports, charts, images, or PDFs in DeepSeek Harness (DSH) sessions. However, locating these artifacts in the conversation history and tracing their origin usually requires leaving the current session or relying on external tools. Artifact Harbor is designed specifically for DSH Web, providing a native “Artifacts” entry in the session header. It anchors agent-generated files to the corresponding Workspace, enabling secure preview and traceability.

Core Capabilities

As a local-first artifacts browser, Artifact Harbor provides the following capabilities:

  • Multi-format support: Supports preview for Markdown, HTML, PNG/JPEG/WebP, SVG, and PDF.
  • Complete metadata: Displays file paths, MIME types, sizes, timestamps, SHA-256 checksums, and Git status.
  • Explainable provenance: Clearly annotates artifact ownership (Session, Turn, Tool Call) and confidence (exact, temporal, or unknown).
  • Secure boundaries: Restricts path access scope based on realpath, limits read size, sanitizes content, applies strict CSP (prohibiting network requests, navigation, and script execution), and renders using an empty iframe sandbox.
  • Native session experience: The UI is integrated inside DSH Web and does not rely on a standalone desktop viewer.
  • Real-time indexing: A debounced file watcher updates the file list in real time, supporting creation, editing, renaming, and deletion operations.
  • Workspace isolation: Discovery is limited to the workspace scope and does not scan the user home directory.

Installation and Enablement

Artifact Harbor is currently not published to a public npm registry and must be built and installed from source. Before you begin, ensure your environment meets the compatibility requirements: DeepSeek Harness version @deepseek-ai/dsh@0.1.1-rc.2, Node.js version ^22.19.0 or >=24.0.0, and pnpm version 10.20.0.

  1. Clone the repository and enter the directory:
    git clone https://github.com/bleakbelladonnals/dsh-artifact-harbor.git
    cd dsh-artifact-harbor
  1. Enable Corepack, then install dependencies, build the project, and pack it as a tarball:
    corepack enable
    pnpm install --frozen-lockfile
    pnpm build
    npm pack --ignore-scripts
  1. Add the packaged plugin to the DSH Web configuration and start the Web interface:
    dsh plugin --profile web add "$PWD/dsh-artifacts-0.1.0.tgz"
    dsh web

Typical Usage

After successful installation, open a Session whose cwd points to a registered Workspace. An Artifacts button will appear in the session header. Click the button to view all supported files generated in the current session. The file list refreshes automatically as files in the Workspace change.

Use Cases and Notes

  • Intended users: Developers or architects who need to manage and review agent-generated content within the session context.
  • Community project: Artifact Harbor is a community project, not an official DeepSeek product.
  • Version constraints: v0.1 is currently a developer preview and has compatibility fixed to DSH 0.1.1-rc.2.
  • Content trust: All artifact content is treated as untrusted, even if created by the agent itself. When handling untrusted Workspaces, always read the SECURITY.md documentation.
  • Security mechanisms: HTML and SVG files are sanitized on the host and include a strict CSP (disallowing network access, scripts, form submissions, and so on). Rendering does not execute scripts or allow cross-origin access.
  • Path security: Absolute paths, traversal variants, and symbolic links attempting to escape the Workspace are denied (fail closed).

Uninstall

To remove the plugin, run the following command:

dsh plugin --profile web remove dsh-artifacts

Uninstallation releases routes, SSE streams, listeners, and in-memory indexes. Related relative metadata may remain in $DSH_HOME/state/dsh-artifacts, but artifact content and Session logs are not cached.

Artifact Harbor is open source under the MIT license and aims to provide secure, traceable file management for local-first agent workflows. For the project address and detailed documentation, see its GitHub repository.