全部插件

DSH / BUNDLE / CLIENT-UI

dsh-shell-select

v0.1.0athif23 / dsh-shell-select74faa36e5d

可安装组合包UI 与客户端插件社区 · Topic 自动分析Web UI

概览

dsh-shell-select

DeepSeek Harness plugin: one model-facing shell tool whose shell is a user setting. Resolves and validates through the harness's own seams, and refuses to run when the selected shell cannot be confined.

README / ZH

插件文档

目录摘要

DeepSeek Harness plugin: one model-facing shell tool whose shell is a user setting. Resolves and validates through the harness's own seams, and refuses to run when the selected shell cannot be confined.

dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。

在 GitHub 阅读完整 README

LIMITATIONS

已知限制

**No `<shell>` executable found.** The plugin looked for the shell by name and found nothing. Install it, or set `executable` to its full path. The error lists every location that was probed. **Refused under the current permission mode.** The selected shell cannot be confined by the sandbox the session resolved. On Windows this is expected for Git Bash and WSL Bash under `workspace-write` and `read-only`. The refusal names the shell and the mode; pick a shell the mode can confine. **Automatic shows *unknown*.** You have staged an `executable` path that the host has not resolved yet. Automatic is resolved from the saved selection, so save the path and the card will name the shell it picks. **Test shell reports a refusal or the wrong shell.** Test runs the *saved* selection. If you have staged edits, save them first, or discard them. **`cmd` quirks.** The command reaches `cmd.exe` in one pass, so a `%NAME%` in your command stays literal; write `call echo %CD%` when you need expansion. Non-ASCII output depends on the console code page, so it can arrive as replacement characters. Unicode paths and filenames are unaffected. **Routes the selector does not control.** Agent commands go through the selected shell, but `run_code` program bodies, PTY-based terminal tools, and out-of-process subagents spawn their own processes. The full list, with reasons, is in [architecture.md](docs/architecture.md#execution-routes-covered-and-not-covered). Shell selection is not destructive-command protection. The sandbox restricts write-class access according to the session's permission mode; this plugin adds no destructive-command detection and is not a safety layer. The other known limitations are listed in [testing.md](docs/testing.md#known-limitations).