tipoLi5890/dsh-file-mention 预览 preview

tipoLi5890/dsh-file-mention

DSH Web Composer插件:'@' 文件提及 + 拖放文件路径

Project Overview项目介绍

This is a native plugin built exclusively for the DeepSeek Harness (DSH) Web composer, adding secure session-scoped @ file and folder mentions plus managed drag-and-drop file intake. It only inserts lightweight path references instead of attaching full file content to conversation context. Before each agent step, the DSH host validates each referenced path and adds a path-only workspace reference marker, letting the agent decide how to inspect the target with its own tools. To install, run dsh plugin --profile web add github:tipoLi5890/dsh-file-mention then restart your DSH Web client to activate it. For local development, you can link a local directory to test changes.

When a user types @ in the DSH composer, the plugin opens a ranked list of workspace files and folders that updates as the user types to filter matches by name or path. Users can navigate options with arrow keys and confirm selection with Enter or Tab, and paths with spaces are automatically wrapped in quotes for correct parsing. It also handles drag-and-drop and paste events for non-image files, routing them through a managed upload pipeline that stores temporary files and inserts the validated path at the current caret position. This plugin is ideal for developers who want to keep context clean while referencing workspace files in DSH conversations.

This plugin is released under the open-source MIT license, with no associated costs for personal or commercial use. It requires a compatible DSH Web profile with input-trigger, runtime, and locale services, and uses DSH's bundled React so no extra build steps or third-party dependencies are needed. It includes configurable hard limits for performance and storage: 20,000 max index entries, 50MiB per individual file, 250MiB per-session upload quota, 2GiB global upload quota, and a default 7-day retention for uploaded files. Browsing outside the current session root is intentionally disabled to maintain workspace security.

这是一款专为 DeepSeek Harness (DSH) Web 编辑器开发的原生插件,提供会话级安全的@文件/文件夹提及功能与拖拽文件摄入能力。该插件仅插入轻量路径引用,不会附加或注入文件内容,在代理执行步骤前,主程序会验证每个路径的有效性,添加仅路径的引用标记,再由代理自行决定如何检查目标。安装可通过DSH命令行完成,添加后重启DSH Web即可生效。

用户输入@后会自动弹出工作区文件和文件夹列表,可继续输入字符按文件名或路径筛选匹配结果,支持键盘方向键、回车或Tab完成选择。除了手动提及,还支持拖放非图像文件、粘贴非图像文件进入统一管理上传管线,插入路径后会保留光标原有位置。它适合需要在DSH对话中精准引用工作区文件,又不想占用额外上下文空间的日常开发用户使用。

该插件遵循MIT许可开源免费使用,内置多项可配置限额,例如单索引最多20000条条目,单个上传文件最大50MiB,会话上传配额250MiB,全局上传配额2GiB,默认上传保留7天。不需要额外构建,也不需要安装第三方依赖,直接使用DSH提供的运行时React即可,本地开发可通过链接方式调试。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:tipoLi5890/dsh-file-mention

把 tipoLi5890/dsh-file-mention 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-file-mention

Awesome DSH Plugin

Traditional Chinese: README.zh.md

Secure, session-scoped @ file/folder mentions and drag-and-drop file intake for the DeepSeek Harness (DSH) Web composer.

The plugin inserts lightweight path references. It does not attach or inject file content: immediately before an agent step, the Host validates each path and adds a path-only <workspace-reference> marker. The agent then decides whether and how to inspect the target with its own tools.

Features

  • Files and folders — bare @ opens a workspace list; continue typing to filter by basename or path.
  • Git-aware index — tracked files plus untracked non-ignored files; deleted tracked paths are removed. Non-Git workspaces use a bounded filesystem walk.
  • Controllable index — nested .aiinclude rules can add required ignored files with last-match-wins semantics; dirty/mtime metadata, monotonic indexVersion, and workspace invalidation keep changed files current.
  • Fast typing — one per-session index request, warm() prefetch, single-flight loading, 30-second stale-while-revalidate, local ranking, and optional recent-path prioritization.
  • Unambiguous references — picks retain the full relative path. Paths with spaces use @"quoted path" syntax.
  • Validated markers — agent/pre-step checks workspace confinement, symlink-resolved location, existence, and file/directory kind without reading content.
  • Keyboard completion — arrows + Enter or Tab through the input-trigger controller.
  • Managed drag-and-drop — streaming temp files, atomic no-clobber finalize, per-file/session/global quotas, retention cleanup, progress, and cancellation.
  • Paste-to-upload — pasting non-image files routes them through the same managed pipeline instead of failing in the built-in image intake; pure rail-image pastes still reach the image rail.
  • Caret-preserving insertion — uploaded @ paths insert at the caret recorded before the upload through the frozen slash/input-insert-text contract (draftRev CAS with caret remap), falling back to append.
  • Reference tray — compact file/folder cards below the composer support copy, reveal, single removal, and batch clear without altering surrounding text.
  • Control Center — Overview, Index, Uploads, and Output tabs expose live index diagnostics, storage meters, ignore presets, index rebuild, and expired-upload cleanup instead of a flat settings form.
  • Candidate context — optional changed-file status labels and browser-local recent-path history improve repeated navigation without sending history to the Host.
  • Official UI slots — the tray, Control Center, and optional Host-validated assistant output path companion use supported DSH integration points.
  • Zero build — hand-written Host ESM and lazy-CJS browser bundle; React is supplied by the DSH Client runtime.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-plugin-automations 下一个 Next dsh-user-addons →