DeepSeek Harness plugin

dsh-open-file

Workspace-bound arbitrary file upload, reading, OCR, and rendering for DeepSeek Harness.

Jump to install

Source facts

Repository
hyper-dsh-plugins/dsh-open-file
Latest update
Aug 18, 2026
Category
Tools & Capabilities
GitHub stars
2
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/hyper-dsh-plugins/dsh-open-file
Plugin: dsh-open-file
Author: hyper-dsh-plugins

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer4 files
README.mdSource · read only
README language

dsh-open-file

English · 简体中文

Workspace-scoped file attachments, document reading, local OCR, and page rendering for DeepSeek Harness Web.

dsh-open-file brings files of any format into DeepSeek Harness conversations. Its included agent tools inspect each upload and read, OCR, or render the content available for the task through one traceable workflow.

<p align="center"> <img src="https://raw.githubusercontent.com/hyper-dsh-plugins/dsh-open-file/main/assets/dsh-open-file-drop.png" width="960" alt="Drop files anywhere in DeepSeek Harness Web"> </p>

<p align="center"> <strong>Drag files into the conversation</strong><br> Drop one or more files anywhere in DeepSeek Harness Web to add them to the active session. </p>

Features

  • Adds an Add → Attachment action to the existing + menu.
  • Accepts multiple files through the system picker, page-wide drag and drop, and clipboard paste.
  • Presents compact draft cards with format icons, upload progress, cancellation, retry, and removal controls.
  • Places sent attachment cards directly below their user message and keeps the conversation aligned.
  • Streams same-origin binary uploads into the active session workspace.
  • Provides four agent tools: file_inspect, file_read, file_ocr, and file_render.
  • Reads text, PDF, DOCX, PPTX, XLSX, bounded ZIP archives, common image formats, and metadata for regular files.
  • Runs English and Simplified Chinese OCR with packaged language data.
  • Returns source hashes, locators, cursors, parsers, and stable references for traceable reasoning.

Compatibility

ComponentVersion or requirement
DeepSeek Harness0.1.0-rc.6
Node.js>=22.13.0
Operating systemsWindows, Linux, macOS
Browser APIsfetch, XMLHttpRequest, File, drag and drop, clipboard file paste

The Web integration uses the rc.6 input-trigger registration, conversation renderer, native image workflow, and client runtime APIs. Compatibility checks report FILE_WEB_COMPATIBILITY when the host contract requires attention.

Install

Install the latest npm release:

dsh plugin --profile web add dsh-open-file

Install version 0.1.2:

dsh plugin --profile web add dsh-open-file@0.1.2

Install a locally reviewed package:

npm ci
npm pack
dsh plugin --profile web add ./dsh-open-file-0.1.2.tgz

The package activates the Host service, Web client, and Open File Skill through cordis.patch.yml. npm presents this README.md as the package documentation.

Quick start

1. Open a DeepSeek Harness session with an active workspace. 2. Select +AddAttachment, drop files onto the Web app, or paste files from the clipboard. 3. Review the draft cards and wait for the ready state. 4. Send the message to create session-bound dsh-open-file://attachment/v1/... references. 5. Let the Assistant inspect, read, OCR, or render the selected content.

<p align="center"> <img src="https://raw.githubusercontent.com/hyper-dsh-plugins/dsh-open-file/main/assets/dsh-open-file-formats.png" width="960" alt="Files in multiple formats ready in the DeepSeek Harness composer"> </p>

<p align="center"> <strong>Upload any file format whenever your task calls for it</strong><br> Documents, data, source code, archives, images, and every other format share one attachment flow. </p>

ToolRole
file_inspectReturns metadata, parser details, and selectable part_ref values
file_readReads a selected part with text cursors or worksheet ranges
file_ocrRuns local English and Simplified Chinese OCR on a selected image part
file_renderRenders a selected document part to a workspace PNG

Image files integrate with the DSH image workflow. Documents and regular files use the workspace attachment workflow.

Configuration

Version 0.1.2 uses packaged release defaults. cordis.patch.yml registers the Host service, Web client, and Skill. Resource limits are listed below and represented in the public contract.

Permissions, storage, and protocol

Source files and derived artifacts live under the active session workspace:

<workspace>/.dsh/open-file/v1/sessions/<sha256(session-id)>/

The plugin reads and writes this session directory and registers same-origin upload routes on the DSH Web Host. OCR uses the packaged eng and chi_sim language data.

POST   /dsh-open-file/v1/uploads/prepare
PUT    /dsh-open-file/v1/uploads/<upload-id>     application/octet-stream
POST   /dsh-open-file/v1/uploads/<upload-id>/commit
DELETE /dsh-open-file/v1/uploads/<upload-id>

Tool responses include the source hash, parser, locator, cursor, and canonical references. Extracted file content is tagged as untrusted evidence for downstream reasoning.

Default limits

LimitDefault
File size256 MiB
Draft files per session20
Draft bytes per session512 MiB
ZIP entries10,000
Expanded ZIP entry64 MiB
Total expanded ZIP bytes512 MiB
ZIP compression ratio100:1
Upload timeout300 seconds
Parse and render timeout30 seconds
OCR timeout120 seconds
Rendered pixels40,000,000

These values define the 0.1.2 resource envelope.

Security

  • Session references, active Agent sessions, authoritative workspaces, and disk metadata participate in one validation chain.
  • Canonical containment and symlink-aware checks protect managed workspace paths.
  • ZIP validation covers normalized paths, links, encryption, duplicates, CRC integrity, archive depth, expansion size, and compression ratio.
  • Office XML validation covers declarations, entities, and relationship targets.
  • Type detection uses magic bytes and container structure.
  • Published sources are immutable; derived artifacts use exclusive creation and atomic metadata replacement.

See [SECURITY.md](./SECURITY.md) for the security policy and reporting process.

Troubleshooting

  • Attachment entry: confirm that the Web client plugin is active and the Host matches DeepSeek Harness 0.1.0-rc.6.
  • Upload: confirm the live session, workspace permissions, same-origin route, and resource limits.
  • OCR: select an image part or a PNG generated by file_render, then choose eng, chi_sim, or both languages.
  • Document parsing: use file_inspect to review the detected type, parser, and available parts.

Stable error codes are exported from the package contract and included in tool failures for programmatic handling.

Uninstall

dsh plugin --profile web remove dsh-open-file

Install a selected release to complete a version change:

dsh plugin --profile web add dsh-open-file@0.1.2

Development

npm ci
npm run typecheck
npm run lint
npm test
npm run build
npm run verify:release
npm pack

The release workflow runs type checks, linting, the complete automated test suite, production builds, and npm artifact inspection across Windows, Linux, and macOS.

Release gate

GitHub and npm publication begins after maintainer approval of both README files and the generated tarball. Final acceptance covers package installation, Web startup, file selection, drag and drop, uploads, message rendering, all four tools, draft controls, and plugin removal.

License

[MIT](./LICENSE)