AI Agent Hub
Back to plugins
🧩

dsh-workspace-write-plus

admin-security Updated 2026.09.08

Run the following command in DeepSeek Harness:

dsh plugin install yzxxy010/dsh-workspace-write-plus

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install yzxxy010/dsh-workspace-write-plus in the DeepSeek Harness terminal to install this plugin, then restart DSH to see the Workspace-Write++ option in the permission selector. Source repository: https://github.com/yzxxy010/dsh-workspace-write-plus

About this plugin

Running DeepSeek Harness on Windows hits a very specific wall: the official Workspace-Write permission tier wraps every child process in a restricted token, but Git for Windows and MSYS rely on memory-mapped files and named pipes that simply will not function under that restriction. Even git --version fails, let alone clone or push. Git is not broken; the sandbox and MSYS are incompatible.

This plugin adds a fourth tier to the permission selector: Workspace-Write++. The idea is deliberately restrained. File writes remain confined to the workspace, so you do not hand the model full disk access. But any binary that matches the allow-list (bash and pwsh by default) is exempted from the process sandbox and gets a full token, so MSYS can open the memory mappings and pipes it needs. The allow-list lives in Settings, one entry per line, and supports both bare file-name matching and glob-style path patterns for precise control. Edits take effect immediately.

It is built for Windows users who run DSH day-to-day, need Git and Shell scripts to work reliably, and want to keep the model contained without granting it complete filesystem access. Workspace-Write++ is not a shortcut to Full Access; it simply splits the sandbox granularity a half-step finer: the file boundary stays, and only the specific binaries you name are let out of the process sandbox.

Use Cases

  • Git commands fail to spawn child processes on Windows due to MSYS token restrictions
  • Running Shell scripts under a confined permission tier without granting full disk access
  • Exempting specific binaries such as bash and pwsh from process sandboxing

Best For

  • DeepSeek Harness users on Windows
  • Developers who depend on reliable Git workflows
  • Admin security teams requiring fine-grained permission control