All plugins

DSH / BUNDLE / CLIENT-UI

@aibo204/dsh-plugin-computer-use

v0.2.1aibo204 / dsh-plugin-computer-use0215f7d20e

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

@aibo204/dsh-plugin-computer-use

Opt-in DeepSeek Harness desktop Computer Use tools over Open Computer Use MCP

README / EN

Package documentation

Registry summary

Opt-in DeepSeek Harness desktop Computer Use tools over Open Computer Use MCP

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- **The desktop is real and cannot roll back actions** — the plugin provides no VM, browser sandbox, domain allowlist, transaction awareness, or rollback. High-risk classification matches phrases in the latest accessibility snapshot; icon-only, misleading, uncovered-language, or dynamically changed controls can remain ambiguous and therefore use the unknown-activation policy. - **OS security surfaces remain inaccessible** — secure password fields, macOS authorization dialogs, Windows UAC secure desktop, locked sessions, remote desktops, and custom-rendered controls may not be observable or controllable. - **Element indexes are runtime-local and ephemeral** — a new Session, reconnect, app/window change, or fresh state capture can invalidate earlier indexes. The provider reports stale or unsupported operations; callers must recapture rather than guess. - **One preset instance serves one active desktop owner** — a second joined Session cannot use Computer Use until the owner Session is disposed. Deploy separate authored preset instances when multiple Sessions require concurrent desktop control. - **Cross-platform behavior follows the pinned upstream runtime** — DSH owns integration, approval, cleanup, and lifecycle, while platform capture and input defects must be fixed or upgraded in `open-computer-use`. - **Evidence can contain sensitive screen pixels** — the default archive captures recognized high-risk actions and stores its private copies locally. Set `archiveMode: off` to disable that archive; `automaticScreenshots` separately controls model-visible evidence for other actions. Attachment or image admission failure can still leave only a safe capture diagnostic.