DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-flutter-sandbox

l

dsh-flutter-sandbox

Manifest valid

dsh plugin: let Flutter and Dart run inside DeepSeek Harness's workspace-write sandbox

hasBundlePatch

dsh-flutter-sandbox

A DeepSeek Harness (dsh) plugin that lets Flutter and Dart run inside dsh's workspace-write sandbox.

Out of the box, dsh only lets sandboxed commands write the session workspace and /tmp. Flutter also writes outside the project on every run, so even flutter --version fails:

update_engine_version.sh: line 71: .../flutter/bin/cache/engine.stamp.tmp: Read-only file system

This plugin replaces dsh's stock sandbox provider with one that also grants write access to these directories (only those that exist):

DirectoryWhy
Flutter SDK ($FLUTTER_ROOT, or found from flutter on PATH)The tool updates bin/cache on every run
$PUB_CACHE or ~/.pub-cachePackage downloads
~/.dart-tool, ~/.dartServerTelemetry state and analysis-server cache
~/.flutter, $XDG_CONFIG_HOME/flutter (~/.config/flutter)Flutter settings
$GRADLE_USER_HOME or ~/.gradle, ~/.androidAndroid builds

Everything else stays protected, and read-only and danger-full-access modes are unchanged. The model is told about the extra directories in its context.

Install

dsh plugin --profile tui add github:liyuqian/dsh-flutter-sandbox

Use --profile web (or any other profile name) for other profiles. Remove it with dsh plugin --profile tui remove dsh-flutter-sandbox.

Configure

The defaults need no configuration. To turn off the Flutter directories or add your own, override the plugin row in your profile's cordis.patch.yml (~/.dsh/profiles/<profile>/cordis.patch.yml):

- id: sandbox-flutter
  config:
    flutter: true               # grant the Flutter/Dart/Gradle/Android directories above
    extraWritableRoots:         # additional absolute directories
      - /home/me/.cocoapods

The stock provider's options (runnerCommand, runnerFailureSignatures, probeTimeoutMs) are accepted too.

How it works

The plugin's bundle patch disables dsh-base's sandbox row (@deepseek-ai/dsh-sandbox-local) and inserts sandbox-flutter, a subclass of that provider. For each workspace-write call it lets the stock provider build the runner command, then inserts one grant per existing directory before the -- that precedes your command:

  • bubblewrap (Linux): --bind <dir> <dir>
  • Landlock (Linux): --rw <dir>
  • Seatbelt (macOS): (allow file-write* (subpath "<dir>"))

Limitations

  • Shell commands only. dsh's own file write/edit tools check writable paths separately and still deny these directories; the model can ask for approval as usual. Flutter, pub and Gradle write through the shell, so this does not affect them.
  • Windows is not supported. The ACL runner cannot grant extra directories, so confined commands fail with a clear error instead of silently running without the grants.
  • Depends on the stock runner's argument layout. A dsh release that changes it makes the plugin fail loudly with "unexpected sandbox argv layout" rather than run unconfined. Tested with dsh 0.1.1-rc.2.
  • Pub workspaces. flutter pub get in a package of a pub workspace writes to the workspace root; start the dsh session at that root.

Develop

npm test

The tests cover root discovery and each runner's grant insertion without a dsh installation.

License

MIT

Comments

Loading…

Similar plugins

dsh-lark

by sugarforever

DeepSeek Harness Plugin for Lark Integration

Tools & CapabilitiesManifest valid

★ 26

↓ 172/wk

MIT

TypeScript

Sep 7, 2026

dsh plugin --profile web add @sugarforever/dsh-lark

by XiaoWind

DeepSeek Harness plugin: portable workspace vault for DSH conversations and logs

Manifest valid

★ 0

MIT

JavaScript

Aug 28, 2026

dsh plugin --profile web add dsh-vault

by 9livewolf

This plugin lets two deepseek bounce around the interface—it has no real purpose.

Just for FunManifest valid

★ 17

JavaScript

Aug 27, 2026

dsh plugin --profile web add dsh-think-bounce-pet

by Momojie-S

DSH plugin: per-workspace .env injection for shell subprocesses

Tools & CapabilitiesManifest valid

★ 2

MIT

JavaScript

Sep 12, 2026

dsh plugin --profile web add @momojie-s/dsh-workspace-env

by cnskycn

DSH (DeepSeek Harness) plugin dev workbench: draft/publish/rollback safety

Manifest valid

★ 0

MIT

JavaScript

Aug 17, 2026

dsh plugin --profile web add dev-workbench

by n8guru

DSH hook plugin: a session may not stop the harness it runs inside

Tools & CapabilitiesManifest valid

★ 0

MIT

JavaScript

Sep 2, 2026

dsh plugin --profile web add dsh-self-preserve