All plugins

DSH / BUNDLE / CLIENT-UI

dsh-plugin-workbench

v0.3.0ghbhiee / dsh-plugin-workbench114287891b

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

dsh-plugin-workbench

Web terminal, file browser and file preview for DeepSeek Harness

README / EN

Package documentation

Registry summary

Web terminal, file browser and file preview for DeepSeek Harness

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- **Long files are windowed.** The preview lays out the first 2 000 lines and says so; markdown over that length falls back to the source view, because the markdown renderer has no windowing of its own. - **The editor is a textarea.** No syntax highlighting while editing, no autosave, no conflict detection: a save overwrites whatever is on disk. - **mkdir/rename/delete bypass the fs seam.** `ctx.fs` has no equivalent (it exposes read, write, and edit only), so those three go through `node:fs` and this plugin's own guard is the only gate — unlike `write`, which additionally passes the harness's per-call write policy. - **A session keeps the sandbox mode it was spawned under.** Lowering the mode later does not retroactively confine a running shell — close it and open a new one. - **No remote runtimes.** Spawning goes straight to node-pty instead of `ctx.subprocess.spawnTerminal`, because that seam's handle exposes no `resize()` (rows/cols are fixed at spawn). Terminals therefore only work where the host process runs. - **Reconnecting does not restore the old shells.** They are gone with the socket; you get a fresh one, and scrollback from before the drop is lost. - **Refreshing is polling, not watching.** The listing and any open preview re-check every five seconds while visible, and immediately when the tab regains focus; there is no filesystem watch, so a change can take up to five seconds to show. Searching pauses the listing poll. - **HTML previews are sandboxed and, by default, inert.** Scripts are blocked unless you opt in per file, and even then run walled off in an opaque origin. Because the frame has no base URL and no same-origin access, a page's relative or external resources — its own linked CSS/JS/images — may not load: it is a structure-and-inline-styles preview, not a live site. Use **View source** for the markup. - **Link interception is a content heuristic.** File-link buttons are recognized by their title/text being path-shaped (there is no stable hook on them), so a dsh change to how links render could make some links fall back to the host opener until the heuristic is updated. - **No Range requests.** `bytes` sends whole files, so large media cannot be seeked; it is meant for images and small downloads. - **Only UTF-8 text is displayable.** Other encodings are detected and refused rather than transcoded; there is no encoding picker.