Nothree-code/folder-tree-sh
DSH Web UI 的工作区文件树面板:浏览、预览(DOCX / Markdown / PDF / 代码 / CSV),并通过真实上下文菜单管理文件。
Project Overview项目介绍
folder-tree-sh (also called dsh-ftree) is a native plugin built exclusively for the DeepSeek Harness (DSH) Web GUI. It adds a full-featured file tree panel to the DSH workspace that supports file browsing, multi-format previews, inline editing, Git change tracking, and complete file management operations. It includes features like automatic directory refresh, file name filtering, customizable sorting, and persistent panel size and state that work right out of the box after installation. It requires no modifications to the DSH core code, supports hot swapping via profile bundle installation, and follows all DSH plugin ecosystem specifications.
This plugin is designed for DSH users who want to handle all file operations directly within their DSH workspace without switching to external tools. It allows users to open multiple files in separate tabs that can be switched instantly, and supports common file operations like creating new files/folders, renaming, deleting, copying, pasting, and copying file paths via the right-click menu. It also includes a dedicated Git change panel that shows the current branch, lists all changes by status, and lets users perform common Git actions like staging, unstaging, discarding changes, and viewing diffs directly inside DSH.
folder-tree-sh is released under the open-source MIT license, and includes multiple security protections to keep your workspace safe. These protections include Origin whitelisting, anti-CSRF tokens, workspace path whitelisting, Shell injection prevention, and safe delete that moves files to the recycle bin instead of permanent deletion. DOCX previews require the mammoth library, and if mammoth is not available, it automatically falls back to extracting plain text via PowerShell. Text files are loaded in 1MB chunks with a maximum file size of 100MB, and all edits are automatically backed up before saving.
这是一款专门为 DeepSeek Harness (DSH) Web GUI 开发的原生工作区文件树插件,提供文件目录浏览、多格式文件预览、内联编辑、Git 变更面板和完整的文件操作功能。插件无需修改 DSH 核心代码,支持热插拔,通过 profile bundle 方式安装即可使用,完全适配 DSH 的插件生态规范。
开发者可以通过该插件在 DSH 工作区内直接完成所有文件相关操作,无需切换外部工具。插件支持按名称、大小、修改时间排序文件,可过滤隐藏文件,拖拽调整面板宽度,面板开关状态会持久保存在 localStorage 中。它还支持多标签同时打开多个文件,切换响应即时,能显著提升在 DSH 内处理文档和代码的工作效率。
该插件采用 MIT 许可开源,内置多重安全防护机制,包括 Origin 白名单、CSRF 令牌校验、工作区路径白名单、Shell 注入防护等,保障操作安全。DOCX 预览依赖 mammoth 库,若缺失则自动降级提取纯文本;文本文件采用分块加载,单文件上限为 100MB。保存文件前会自动生成最多三个滚动备份,删除文件会移入回收站而非直接删除。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:folder-tree-sh(Nothree-code/folder-tree-sh)
仓库:https://github.com/Nothree-code/folder-tree-sh
本站详情页:https://www.yhbd.top/plugins/nothree-code-folder-tree-sh/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 4 · 最近提交 2026-09-13 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:Nothree-code/folder-tree-sh
把 Nothree-code/folder-tree-sh 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
folder-tree-sh
DSH Web GUI 的工作区文件树插件(dsh-ftree):文件浏览、多格式预览、内联编辑、Git 变更面板与完整文件操作,零核心修改、热插拔(profile bundle)。
功能
文件树
- 目录展开/折叠,5 秒自动刷新 + 手动刷新
- 过滤框:按文件名实时过滤
- 排序:名称 / 大小 / 修改时间(目录始终置顶)
- 隐藏文件开关:默认隐藏
.git/node_modules/.DS_Store - 宽度拖拽调整 + 面板开关状态持久化(localStorage)
预览(多标签)
- Markdown:渲染 + 编辑双模式(工具栏、实时预览、自动保存、Ctrl+S),支持工作区相对路径图片(
经 host raw 路由渲染) - 代码:30+ 语言轻量高亮
- CSV:自动分隔符检测(
,;Tab)+ 表格渲染 - 图片:缩放(Ctrl+滚轮)/ 双击复位
- PDF:浏览器原生渲染(
no-cache字节流) - DOCX:mammoth → HTML 真渲染(含图片),无 mammoth 时自动降级为 PowerShell 提取纯文本
- 文本:分块加载(1MB/块,100MB 上限),GBK 编码自动检测回退
- 多标签同时打开多个文件,切换即时
编辑
- Markdown 内联编辑:自动保存(800ms 防抖)+ 手动 Ctrl+S,保存前滚动备份
.dshbak.1~3
Git 变更面板
- 分支显示 + 变更列表(未跟踪 / 已暂存 / 已修改)
- 操作:暂存(add)、取消暂存(restore --staged)、丢弃更改(checkout --,未跟踪文件走回收站删除)、查看差异(diff / diff --cached)
文件操作(右键菜单)
- 刷新、新建文件、新建文件夹、重命名、删除(回收站)、复制/剪切/粘贴、原地复制、打开源文件夹(资源管理器定位)、复制路径、添加到聊天(图片)
安全模型
- Origin 白名单:从
webStartup动态派生(127.0.0.1 / localhost / [::1] / 配置的 host / trustedHosts),跨站请求一律 403;监听0.0.0.0(LAN)时退化为仅靠 CSRF token - 每进程 anti-CSRF token:所有变更路由(op / write / git-op)必须携带
/dsh-ftree-token颁发的 token - 工作区白名单:所有路径必须位于已注册 workspace 根(deny by default)
- 删除进回收站,不永久删除;写入前滚动备份
.dshbak.1~3 - Shell 注入防护:所有 PowerShell 命令经单引号转义(
'→'') - realpath 路径守卫(
lib/pathguard.js):所有路径经realpath规范化(跟随符号链接与 NTFS junction)后再做工作区前缀校验,..穿越、junction 与 symlink 逃逸均无法绕过白名单;不存在的写入目标自动回溯最近存在祖先(realpathLenient) - 预览缓存:按文件 size 校验自动失效,写入后主动清除
开发
# 同步修改到 node_modules 实体拷贝(改完 lib/ 后执行)
powershell -ExecutionPolicy Bypass -File sync.ps1
# 若 package.json 有改动(名称/版本/dsh.client)
cd ..\.. && pnpm add "file:./packages/dsh-ftree"
# 重启 dsh web 生效
版本号以 package.json 为准(host 启动时读取,/dsh-ftree-meta 暴露给客户端做 stale-cache 检测)。
路由一览(host)
| 路由 | 方法 | 说明 |
|---|---|---|
/dsh-ftree-meta |
GET | 版本信息 |
/dsh-ftree-token |
GET | CSRF token |
/dsh-ftree-list |
GET | 列目录(withMtime=1 时附修改时间) |
/dsh-ftree-read |
GET | 分块读文件(text/image/pdf/docx) |
/dsh-ftree-op |
POST | rename / delete / paste / open / mkdir / newfile |
/dsh-ftree-write |
POST | 保存文本(带 .dshbak 备份) |
/dsh-ftree-pdf |
GET | PDF 字节流 |
/dsh-ftree-raw |
GET | 工作区原始字节(markdown 图片) |
/dsh-ftree-git |
GET | git status(branch + 变更) |
/dsh-ftree-git-op |
POST | stage / unstage / discard / diff |
许可
MIT
boogoo619/dsh-focus-overlay
lwklbb/DSH-SessionGraph
ZSeven-W/dsh-openpencil
joeseesun/qiaomu-rss-dsh
LAU-MARS/dsh-cad
penguin-oo/dsh-bookmarks