DeepSeek Harness 插件

dsh-workspace-scope-selection

A fourth permission option for DeepSeek Harness sessions: selected-workspace-write, where the user opens the workspace directory tree and toggles which directories the agent may write to.(英文原文)

跳到安装方式

来源信息

GitHub 仓库
jiangr100/dsh-workspace-scope-selection
最近更新
2026年8月17日
分类
自动化与任务
GitHub stars
0
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/jiangr100/dsh-workspace-scope-selection
插件名:dsh-workspace-scope-selection
作者:jiangr100

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-workspace-scope-selection

A fourth permission option for DeepSeek Harness sessions: Selected Workspace Write. Instead of "only the workspace" or "everything", you pick exactly which directories the agent may write to — the workspace itself included.

What you get

  • The composer permission chip (and /permission) gains a **Selected

Workspace Write** option.

  • Picking it opens a directory-tree editor right away. **The checked state IS

the writable scope**: check directories to make them writable; the session workspace sits at the top, checked by default — uncheck it to make the workspace read-only. Everything unchecked is denied (or needs your approval).

  • A small Edit scope button next to the access chip reopens the editor.
  • The selection is per-session and survives restarts.

Install

dsh plugin --profile web add file:/path/to/dsh-workspace-scope-selection

Use the file: protocol (not a bare path — that records a link: symlink and the plugin fails to load). Then restart dsh web.

Usage

1. Click the permission chip (or /permission) → Selected Workspace Write. 2. In the editor, check the directories the agent may write to. Unchecking a parent removes its whole subtree; a directory included via a checked parent shows a "via parent" mark. 3. Click Done. The selection applies immediately.

How it works

  • The plugin adds a selected-workspace-write sandbox mode and enforces it

in both the filesystem tools and the shell/terminal sandboxes: only the selected directories (plus platform temp areas) are writable.

  • The selection is stored in the session log and replayed on resume.
  • Outside the selection, writes are denied and can be escalated with your

approval, like any other sandboxed operation.

Notes

  • The General-settings Permission row still lists the three built-in options;

this one is a per-session switch via the chip or /permission.

  • Windows grants the workspace + temp areas only (selected extra roots are

denied there).

  • Writes outside the selection always require an approved escalation.

Uninstall

dsh plugin --profile web remove dsh-workspace-scope-selection

then restart dsh web.

Development

node --test test/core.test.mjs

lib/client.js is a hand-written module-loader bundle (no build step).