dsh-file-preview
Manifest validRead-only in-conversation file preview for DeepSeek Harness: a session-authorized host Remote and a sanitizing browser modal, installed as one profile bundle.
@softspark/dsh-file-preview
Read-only file preview inside a DeepSeek Harness conversation. Click a file the agent produced or mentioned and it opens in the browser, instead of launching a desktop application.
Works on the published harness. No patch, no fork, no modified checkout.
What's New in v2.0.0
- DSH
0.1.2-rc.1support through its Session Remote opener and immutable host event snapshots. - Enforced 70% coverage, filesystem authorization integration tests, and browser registration tests.
- Complete post-release SOP and published browser TypeScript declarations.
Version 2 requires DSH 0.1.2-rc.1. Keep plugin 1.0.0 when using DSH 0.1.1-rc.2.
Contents
Why
Without it, opening a file from a conversation hands the path to the host operating system. That is the wrong gesture when the harness runs on a remote machine, in a container, or when the file is a diff you want to glance at without leaving the page.
Requirements
- Node.js 22.19.0 or newer
- DeepSeek Harness
0.1.2-rc.1 pnpmfor the profile plugin manager
Install
dsh plugin --profile web add @softspark/dsh-file-preview --save-exact
Restart DSH. The package registers both of its rows itself.
What it previews
| Kind | Formats | Bound |
|---|---|---|
| Text and code | .txt .md .json .yaml .toml .csv .ts .js .py .go .rs .sql and more | 1 MiB |
| Markup | .html .svg, sanitised to an allowlist | 1 MiB |
| Images | .png .jpg .gif .webp | 8 MiB |
| Documents | .pdf | 8 MiB |
Anything else reaches the harness's own opener untouched, exactly as before the plugin was installed.
How it claims a click
Every conversation file-open in DSH 0.1.2 reaches remote.session.openWorkspacePath({ path }). The browser half wraps its getter while preserving the native request, cancellation signal, and caller context. Removing the package restores the original descriptor.
If a future harness stops exposing that method, the plugin refuses to mount rather than silently swallowing clicks.
Security
A preview must not become an arbitrary host-file read. Authorization is computed on the host from session facts alone: a file is readable when it sits inside the addressed session's workspace, or when that same session produced it through a successful write or edit. Failures never carry file bytes, and both refusal grounds return the same code so a rejection cannot be used to probe for a file's existence.
Full model in kb/reference/security.md and SECURITY.md.
Documentation
| Document | Purpose |
|---|---|
| Architecture | The two halves and the interception seam |
| Security model | Authorization, bounds, sanitization |
| Setup | Install and confirm |
| Common issues | Why a preview refuses or does not open |
| Release SOP | How a version ships |
| Post-release SOP | Registry provenance, browser behavior, and authorization checks |
Contributing
See CONTRIBUTING. pnpm run verify is the gate.
License
Apache-2.0. See LICENSE and NOTICE.
Changelog
See CHANGELOG.md for the full release history.
Comments
Loading…
Similar plugins
by ice5kysl
dsh (DeepSeek Harness) file explorer: browse the active session's workspace and preview files (Markdown/image/PDF/text/binary) right inside the chat GUI — a standard Cordis bundle plugin (read-only /d
★ 0
↓ 1.2k/wk
MIT
JavaScript
Sep 11, 2026
dsh plugin --profile web add dsh-file-explorer-kitby Unintendedz
Archive, cross-session read, and copy-ID tools for DeepSeek Harness conversations.
★ 0
MIT
JavaScript
Sep 10, 2026
dsh plugin --profile web add dsh-session-toolsby GroupWork888
Browse and read archived DeepSeek Harness sessions from a sidebar panel. A read-only viewer: it does not restore sessions to the sidebar.
★ 0
MIT
TypeScript
Sep 29, 2026
dsh plugin --profile web add dsh-plugin-archived-sessionsby taxueseek
DeepSeek Harness 插件:原生上传管线上的文件夹按钮 + read_document 文档解析(PDF/DOCX/XLSX)。The folder button on the native upload pipeline, plus the read_document parser.
★ 39
MIT
TypeScript
Oct 1, 2026
dsh plugin --profile web add dsh-filesby ld-1101
DSH (DeepSeek Harness) plugin: workspace file preview column with Markdown/PDF/image/CSV preview, session-produced files, drag files/folders into the conversation as plain paths.
★ 0
MIT
JavaScript
Aug 17, 2026
dsh plugin --profile web add dsh-file-previewby ghbhiee
File browser, preview, and web terminal panel for DeepSeek Harness — session-docked workbench plugin
★ 0
MIT
JavaScript
Aug 18, 2026
dsh plugin --profile web add dsh-plugin-workbench