GLFzr/dsh-file-upload
DSH拖拽文件转路径插件:Codex式拖拽,路径自动插入输入框(Drop File to Path for DeepSeek Harness)
Project Overview项目介绍
This is a natively-developed plugin built exclusively for DeepSeek Harness (DSH), that extends the default Web GUI attachment system which originally only handled image uploads to support any file type. It can be installed using DSH’s official CLI plugin command, and will automatically load every time DSH restarts after the initial one-time setup. Users can drag and drop one or multiple files of any format anywhere on the DSH Web UI page, and the plugin saves the file to a local transfer directory, generates a blue uneditable file chip inserted into the input box, so the DSH agent can access and read the file content. On Chromium-based browsers like Google Chrome and Microsoft Edge, the plugin can get the original file path via the browser’s entry API, allowing direct reference of local files without any upload or copying.
The plugin includes a built-in two-level deduplication system that checks for matching file name, size, and last modified date to avoid re-uploading files that have already been added, which saves both time and disk space. The width of each generated file chip automatically adapts to the length of the file name, so the UI stays clean and consistent regardless of how long the file name is. A trash icon for accessing the transfer directory cleaning tool is added to the DSH sidebar above the settings icon; users can view the full file list, delete redundant automatically-named copies, remove files over a specified size, or clear the entire transfer directory. All cleaning actions require explicit user confirmation before execution, to prevent accidental deletion of important files.
The plugin supports a maximum file size of 512MB, splits files into 4MB chunks for upload, and runs full integrity checks on each chunk to ensure no corrupted files are written to local disk. It is released under the open-source MIT license, and all core host-side logic has a full suite of automated unit tests that run via GitHub Actions CI on every push and pull request. The only known limitations are that concurrent uploads of multiple large files can consume a significant amount of host process memory, and direct path references on Chromium only work for actual local files, not virtual or placeholder cloud files. This is not a security flaw, just a current architectural limitation that may be improved in future releases.
这是一款专为 DeepSeek Harness 开发的原生插件,将原本 DSH Web GUI 仅支持图片的附件通道扩展为支持任意类型文件上传。用户可将任意格式文件(包括 PDF、ZIP、代码、Excel、图片等)拖入网页界面,插件会将文件物化到本地中转目录,生成蓝色文件芯片插入输入框,供 AI 代理读取文件内容。在 Chrome、Edge 等 Chromium 内核浏览器中,可通过浏览器 API 直接获取原文件路径,实现本地文件零上传零复制引用。
插件支持在页面任意位置拖入多个文件,具备两级去重机制可避免重复上传同一文件,文件芯片宽度会自动适配文件名长度。插件还提供了中转目录清理功能,在侧边栏设置图标上方设有垃圾桶图标入口,可打开浮层查看文件列表、清理冗余副本、按大小删选文件或清空整个目录。所有清理操作执行前都会要求用户确认,既避免误删,也可防止中转目录无限制膨胀占用磁盘空间。
插件可通过 DSH 官方插件命令行工具安装,一次安装后 DSH 重启即可自动生效,无需重复部署。该插件单个文件最大支持 512MB,以 4MB 分块上传,具备完整的校验和完整性检查,可避免损坏文件落盘。插件采用 MIT 开源许可证,核心逻辑拥有完整单元测试,仅存在并发大文件上传内存占用较高这类架构级限制,无重大已知缺陷。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-file-upload(GLFzr/dsh-file-upload)
仓库:https://github.com/GLFzr/dsh-file-upload
本站详情页:https://www.yhbd.top/plugins/glfzr-dsh-file-upload/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 10 · 最近提交 2026-08-28 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 10 stars - an early-stage project星标 10,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:GLFzr/dsh-file-upload
把 GLFzr/dsh-file-upload 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH 文件上传插件(File Upload)v2.1.0
把 DSH Web GUI 原版只支持图片的附件通道,扩展为任意文件上传:拖入任意文件(PDF、3MF、ZIP、Excel、代码、图片……)→ 文件上传/引用到本机中转目录 → 输入框出现一个蓝色文件 chip → agent 可以直接读取该文件。
定位说明(v2.0.0 起):本插件的本质是文件上传功能,不是"路径展示"。路径只是内部机制——agent 读取文件必须依赖磁盘路径,浏览器又拿不到(见下文"为什么必须上传"),所以插件负责把文件物化到本机、并把路径交给 agent。用户界面不再出现任何路径概念:chip 只显示文件名,用户只需知道"文件上传好了,agent 能读了"。
本仓库是持久化 profile 插件(dsh.bundle + dsh.client 双声明):按官方方式安装一次,DSH 重启后自动生效。
功能特性
- 🖱️ 页面任意位置拖入任意文件(多文件、图片均可);拖拽时全屏提示"松开以接收文件"
- 📦 任意文件类型:原版"仅图片"附件通道被完全静默接管,任何文件都可拖入
- 📍 本机文件零上传直引:Chromium(Edge/Chrome)拖拽会经 entry API 暴露源文件路径——直接引用,零上传、零复制(你电脑里那份文件就是唯一的一份);仅当浏览器拿不到路径(如 Firefox)时才走上传中转
- 🔵 文件以一个整体 chip 插入输入框:蓝色文字(只显示文件名+格式)、不可被局部删改(Backspace/Delete 一次删除整个引用)
- 📐 篮筐宽度随文件名自适应:插入时用 composer 真实字体实测文件名宽度,pill 精确贴合(误差 <1 个字符)
- 🙈 内部细节全部隐藏:
.b64后缀、_1/_2重名序号、中转目录路径——用户界面永远看不到;提交给 agent 的才是完整真实路径 - ♻️ 两级去重(先查后传,防误复用):
begin快路径命中条件 = 同名 + 同大小 + manifest 登记的源文件修改时间与本次拖入一致——重复拖同一文件仍秒回(零上传);但编辑过且字节数没变的文件绝不误复用(v2.1.0 起,新/旧文件首次拖入都先完整上传,由end的 sha256 逐字节比对裁决:内容相同复用旧路径,内容不同落_1副本) - 📇 中转目录清单(manifest):插件把每个自己写入的文件登记到
~/.dsh-dropbox/.dsh-manifest.json(原名、源修改时间、sha256、是否自动编号副本)——清理面板的"冗余副本"标记只认清单,不会把notes_2024.txt这类自然命名误判为副本(v2.1.0 起) - 🧹 失败即清理:上传任一步失败,客户端立即调用 abort 释放宿主会话,不再滞留内存到超时(v2.1.0 起)
- 🛡️ 完整性校验:每块精确长度校验、分块必须齐全、解码后字节数必须与声明一致——截断/缺块/伪造数据一律拒绝,绝不落盘损坏文件
- ⏳ 插入点待机圆环:上传真正需要等待时,在文件将要出现的位置(光标右侧一个字符处)显示 DeepSeek 蓝色转圈环(渐隐拖尾、持续转动);瞬间完成的路径(本机直引、秒回去重、极小文件)不出圈;chip 插入的同一瞬间圆环立即消失
- 🚀 ~4MB 分块上传,上限 512MB;请求体上限 16MB/次;失败右下角红色提示 4 秒
- 🗑️ 侧边栏垃圾桶图标(设置图标上方):打开上传目录清理浮层——文件清单、一键清理冗余
_N副本、按大小清理、清空全部,操作前确认,避免中转目录无限膨胀
为什么必须上传/中转?(浏览器限制)
这是 WebUI 与 Hermes/Codex 之类本地 CLI 的本质区别,不是本插件的缺陷:
- 浏览器是沙盒:网页里的 JavaScript 拿不到本地文件的磁盘路径(安全模型,防止网页偷读你的磁盘)。Hermes/Codex 直接跑在你的电脑上,可以随便读
C:\...\xxx.pdf;DSH 的 Web GUI 是一个浏览器网页,它手里的文件只是一个内存File对象。 - agent 只能读磁盘路径:agent 读取文件靠的是磁盘路径。浏览器无法把一个内存文件"变成"磁盘路径交给 agent,所以插件必须先把文件物化到本机中转目录(默认
~/.dsh-dropbox),agent 才能访问。 - 唯一的例外(零上传):Chromium 系浏览器(Edge/Chrome)拖拽本机文件时,
DataTransferItem.webkitGetAsEntry()能探测到源文件路径——此时插件直接引用原路径,零上传、零复制。Firefox、或从非本机来源(网页、压缩包内)拖拽时拿不到路径,才必须走上传兜底。 - 大文件的代价:新文件第一次拖入必须完整上传(几百 MB 也要传),这是浏览器限制决定的。为了把重复成本降到零,插件做了两级去重(见工作原理)。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
reactive-resume/reactive-resume
anywhere-labs/dsh-desktop
dataelement/dsh-desktop
ccch1mneyyy/dsh-TUI
DSH-EAC/DSH-Desktop-EAC
shaobeichen/dsh-pocket
xyTom/coding-tools-mcp