Introduction

In 2026, DeepSeek Harness (DSH) remains a common local tool for agent development. When starting the Web GUI with dsh --profile web for management, developers can usually only view workspace state in a browser and lack the ability to interact directly with the local environment. As a client-side plugin, dsh-workspace-native-open solves this pain point by injecting menu items, allowing the Web UI to directly trigger file operations on the host.

Core Features

The plugin only works when the Web GUI is accessed through a loopback address. In any DSH workspace row, clicking the ⋯ menu adds three native actions:

  1. Open in File Explorer: Invokes the system file manager (explorer.exe / open / xdg-open). Supports automatic WSL path translation.
  2. Open in Terminal: Starts a new terminal window in the workspace directory. On Windows, it probes for pwsh first and then powershell; WSL paths are translated with wslpath and opened in a Windows console; other platforms use $TERMINAL.
  3. Open in Code: Directly attempts to open the directory. The plugin does not detect whether VS Code is installed; failures are silently ignored after the click. Under WSL, the Linux-side code script is preferred.

Additionally, the plugin has the following features:

  • Security: The menu is only displayed for localhost, 127.0.0.1, ::1, and the built-in dsh.localhost allowlist. Remote access or requests with a Host header outside the allowlist are rejected.
  • Silent operation: Failures do not interrupt the user, but all requests, probe results, and error logs are written to the harness log with the workspace-native-open prefix.

Installation

Requires the Web profile (dsh --profile web). Install it with the official command:

dsh plugin --profile web add github:JoeyLearnsToCode/dsh-workspace-native-open

How It Works

The plugin consists of a host side and a client side.

The host side registers a POST /api/plugin/workspace-native-open endpoint on the webServer service. This endpoint validates whether the Host header is in the allowlist, enforces request body length and timeout limits (413/408), and performs the native open action. For security, it enforces a JSON content type and protects against CSRF.

The client side subscribes to the webserver/index-inject event to inject scripts and styles into index.html. The script activates only under loopback hostnames. It dynamically adds menu items by observing the workspace menu button in the DOM (identified via aria-label) and the subsequent portal menu (paired by click causality). Menu labels are generated from <html lang> and the plugin’s inline translation files.

Platform Details and Notes

  • Windows terminal: Uses where.exe to probe for pwsh and powershell. Note that Windows 10 and later always include PowerShell, so no cmd fallback is retained. The Windows console program uses Start-Process and must not use DETACHED_PROCESS; otherwise, the command exits silently.
  • VS Code security: Node ≥ 20.12 refuses to spawn .cmd shims directly (CVE-2024-27980). Therefore, code.cmd is invoked through a PowerShell launcher, and the plugin does not probe its installation status.
  • WSL behavior: On WSL, clicking Open in Terminal opens a Windows console in the translated \\wsl$ path, matching File Explorer behavior.
  • Custom allowlist: dsh.localhost is already allowed by default. To allow other local domain names, modify LOOPBACK_HOSTNAMES in src/index.ts and rebuild.
  • Logging: All operations are logged with the workspace-native-open prefix, including failure reasons and exit codes.

Summary

dsh-workspace-native-open is a lightweight DSH plugin that uses DOM injection and host-endpoint bridging to enable secure interaction between the Web UI and the local file system. It is suitable for users who need to manage a local development environment from a browser.

GitHub repository: JoeyLearnsToCode/dsh-workspace-native-open