Mooling0602/dsh-web-file-uploader
DeepSeek Harness 网页界面的文件上传插件。
Project Overview项目介绍
This is a native plugin built exclusively for the DeepSeek Harness web user interface. It adds a custom paperclip-styled attachment button directly to the right of DSH’s official attachment button in the composer toolbar, with optional settings to hide the original button and use this plugin’s button instead. It supports multi-file selection, renders uploaded files as preview cards with image thumbnails in the dock above the composer, and stores all uploaded files on the DSH host machine rather than only in the user’s browser. It also handles file name sanitization for invalid characters and automatically appends collision suffixes for new files with duplicate names.
The plugin uses a card-driven injection design, so any file with an open card will have its absolute host path injected into every outgoing user message. Closing a card stops injection but leaves the file intact on the host for later access by the model, while deleting a card permanently removes the file from the host (if no other active references to the deduplicated copy exist). The plugin automatically adapts injection behavior based on the model’s capabilities: for multimodal models, images are injected as native ImageBlocks, while for text-only models and all non-image files, only the file path is injected into the prompt.
The plugin is released under the permissive MIT open source license, and uses content-addressed deduplication to avoid wasting storage space on repeated uploads. All UI text is automatically localized to match DSH’s existing language setting, with support for both English and Simplified Chinese. The project follows a core-logic-plus-thin-adapter architecture, and the dynamic plugin mode is already fully implemented and verified in live DSH sessions. The static bundle build works but still requires additional verification of its compatibility with DSH’s web module loader. Storage location varies by build mode, going to either the session workspace or DSH’s home data directory.
这是专为DeepSeek Harness(DSH)网页端打造的原生文件上传插件,它在输入框工具栏的官方附件按钮右侧新增了一个回形针样式的自定义上传按钮,支持多选文件,并且会在输入框上方的停靠栏以带缩略图的预览卡片展示已上传文件。上传的文件会存储在DSH宿主机上而非仅保存在浏览器端,同时支持文件名消毒、自动处理重名冲突,还提供复制路径、删除文件等功能。
插件采用卡片驱动的注入逻辑,只要卡片处于打开状态,对应文件的绝对路径就会随每条用户消息注入对话。关闭卡片仅停止注入,文件仍保留在宿主机方便模型后续读取,删除卡片则会彻底从宿主机移除对应文件。针对不同模态的模型会自动适配:多模态模型的图片会以原生ImageBlock注入,纯文本模型和非图片文件则仅注入路径,它面向所有需要在DSH网页端灵活管理上传文件的用户。
本项目采用MIT许可协议免费开源,使用内容寻址去重技术避免重复上传占用过多存储空间,UI文本会跟随DSH网页端的语言设置自动切换中英双语。项目采用核心逻辑+适配层的架构,动态插件模式已经过实际会话验证可用,静态打包模式的客户端模块仍需验证工具链兼容性。存储位置根据打包模式不同,分为会话工作区和DSH数据目录两种。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-web-file-uploader(Mooling0602/dsh-web-file-uploader)
仓库:https://github.com/Mooling0602/dsh-web-file-uploader
本站详情页:https://www.yhbd.top/plugins/mooling0602-dsh-web-file-uploader/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 10 · 最近提交 2026-09-26 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 10 stars - an early-stage project星标 10,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-web-file-uploader
把 Mooling0602/dsh-web-file-uploader 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-web-file-uploader
A file-upload plugin for the DeepSeek Harness web UI. It adds a DeepSeek-web-style paperclip attach button to the composer input row and uploads the selected files to the DSH host machine — with model-aware adaptation so the files are actually usable by the running model, and content-addressed deduplication so storage never gets flooded by re-uploads.
Features
- 📎 Paperclip attach button in the composer tool row, wearing the official
attach button's chrome (28px circle,
--dsw-specific-selectorfill, 14px filled glyph,--dsw-alias-interactive-bg-hover-solidhover) with the paperclip rotated 45° to keep this plugin's long-standing diagonal, so the two buttons stay tellable apart at a glance. It sits directly to the right of the official attach button, ahead of the permission chips — and Settings can optionally hide the official button and let this one take its place - Multi-file selection with preview-style attachment cards (image thumbnails) in the dock above the composer: reading → uploading → saved, with copy-path and remove buttons
- Files are stored on the DSH host, never only in the browser
- Name sanitization (path separators,
.., control characters rejected) and automatic-1/-2collision suffixes for distinct files with the same name - Content-addressed deduplication — see Deduplication
- UI strings localized through the app's
localeservice (zh / en; follows the dsh web language setting or the system default)
Model-aware adaptation & the attachment-card design
Uploaded files are shown as attachment cards in the dock above the composer. The cards are the source of truth for injection:
| State | Behavior |
|---|---|
| Card present | The file's absolute path is injected into every user message sent while the card is visible |
Card closed (×) |
The plugin calls the host remove RPC — the file is dropped from the pending registry, no longer injected, and the file is kept on disk so the model can still re-read it from the uploads folder |
| Card deleted (🗑) | The plugin calls the host delete RPC — the file is permanently removed from the DSH host and the dedup index is scrubbed |
| Ctrl+V paste | Pasted images ride the native draft-image pipeline — no card is created and the plugin never touches them |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
titanwings/dsh-automation
linhut/gongwen-skill
Jungod1121/dsh-anchored-standard
omdsh-dev/dsh-advisor
wlj521/dsh-ui-tweaks
Moeblack/deepseek-manners