Introduction¶
In 2026, DeepSeek Harness (DSH) remains a common local tool for agent development. When starting the Web GUI with dsh --profile web for management, developers can usually only view workspace state in a browser and lack the ability to interact directly with the local environment. As a client-side plugin, dsh-workspace-native-open solves this pain point by injecting menu items, allowing the Web UI to directly trigger file operations on the host.
Core Features¶
The plugin only works when the Web GUI is accessed through a loopback address. In any DSH workspace row, clicking the ⋯ menu adds three native actions:
- Open in File Explorer: Invokes the system file manager (
explorer.exe/open/xdg-open). Supports automatic WSL path translation. - Open in Terminal: Starts a new terminal window in the workspace directory. On Windows, it probes for
pwshfirst and thenpowershell; WSL paths are translated withwslpathand opened in a Windows console; other platforms use$TERMINAL. - Open in Code: Directly attempts to open the directory. The plugin does not detect whether VS Code is installed; failures are silently ignored after the click. Under WSL, the Linux-side
codescript is preferred.
Additionally, the plugin has the following features:
- Security: The menu is only displayed for
localhost,127.0.0.1,::1, and the built-indsh.localhostallowlist. Remote access or requests with aHostheader outside the allowlist are rejected. - Silent operation: Failures do not interrupt the user, but all requests, probe results, and error logs are written to the harness log with the
workspace-native-openprefix.
Installation¶
Requires the Web profile (dsh --profile web). Install it with the official command:
dsh plugin --profile web add github:JoeyLearnsToCode/dsh-workspace-native-open
How It Works¶
The plugin consists of a host side and a client side.
The host side registers a POST /api/plugin/workspace-native-open endpoint on the webServer service. This endpoint validates whether the Host header is in the allowlist, enforces request body length and timeout limits (413/408), and performs the native open action. For security, it enforces a JSON content type and protects against CSRF.
The client side subscribes to the webserver/index-inject event to inject scripts and styles into index.html. The script activates only under loopback hostnames. It dynamically adds menu items by observing the workspace menu button in the DOM (identified via aria-label) and the subsequent portal menu (paired by click causality). Menu labels are generated from <html lang> and the plugin’s inline translation files.
Platform Details and Notes¶
- Windows terminal: Uses
where.exeto probe forpwshandpowershell. Note that Windows 10 and later always include PowerShell, so nocmdfallback is retained. The Windows console program usesStart-Processand must not useDETACHED_PROCESS; otherwise, the command exits silently. - VS Code security: Node ≥ 20.12 refuses to spawn
.cmdshims directly (CVE-2024-27980). Therefore,code.cmdis invoked through a PowerShell launcher, and the plugin does not probe its installation status. - WSL behavior: On WSL, clicking Open in Terminal opens a Windows console in the translated
\\wsl$path, matching File Explorer behavior. - Custom allowlist:
dsh.localhostis already allowed by default. To allow other local domain names, modifyLOOPBACK_HOSTNAMESinsrc/index.tsand rebuild. - Logging: All operations are logged with the
workspace-native-openprefix, including failure reasons and exit codes.
Summary¶
dsh-workspace-native-open is a lightweight DSH plugin that uses DOM injection and host-endpoint bridging to enable secure interaction between the Web UI and the local file system. It is suitable for users who need to manage a local development environment from a browser.
GitHub repository: JoeyLearnsToCode/dsh-workspace-native-open