whitefirer/dsh-browser-fs
dsh (DeepSeek Harness) plugin: allows the agent to read and write local files on the machine where the browser resides — File System Access authorization + WS relay, including non-secure context compatibility mode
Project Overview项目介绍
dsh-browser-fs is a native DSH plugin built specifically for DeepSeek Harness, designed to let DSH agents read and write files on the same local machine that is running the user's browser. When DSH is deployed remotely on a server, the built-in file system tool can only access the remote host machine, so agents cannot reach files stored on the user's own local device. To install the plugin, users can run dsh plugin --profile web add dsh-browser-fs to pull it from npm, or install directly from GitHub with the command dsh plugin --profile web add github:whitefirer/dsh-browser-fs. After running the install command, users need to restart DSH to fully activate the plugin and make it available for use.
Once installed and activated, a floating draggable card will appear at the bottom right of the DSH web interface that users can open or collapse. Users can click the "Authorize Directory" button on the card to select a local directory on their machine, and the authorization handle is stored persistently in the browser's IndexedDB. After authorization, the DSH agent can use three dedicated tools: browser_fs_list to list directory contents, browser_fs_read to read text files, and browser_fs_write to write new text content to the authorized local directory. The plugin also supports in-card directory browsing, file preview with syntax highlighting for common code formats, and basic text editing. It is targeted at developers who use remotely deployed DSH and need consistent access to their local files.
This plugin is released under the open source MIT license, and it has a peer dependency on @deepseek-ai/dsh-tools which is already included with all standard DSH installations, so no extra installation steps are needed for most users. There are several key limits to note: full read-write functionality only works in a secure browser context (HTTPS or localhost), and non-secure contexts like plain HTTP LAN access automatically downgrade to a read-only compatible mode. Additionally, the plugin requires that the DSH browser tab remains open to function, and it only supports reading and writing UTF-8 encoded text files. Multiple connected devices can each authorize their own local directories, and tool calls are automatically routed to the correct authorized device.
本项目是专为 DeepSeek Harness (DSH) 开发的原生插件,用于解决远程部署 DSH 时,Agent 无法读写浏览器所在本地机器文件的问题。DSH 自带的文件系统工具仅能访问宿主机,当 DSH 部署在远程服务器、用户通过浏览器访问时,就会碰到本地文件无法访问的障碍。本插件通过浏览器 File System Access API 让用户授权本地目录,Agent 即可通过三个工具对该目录下文件进行读写操作,填补了这一功能缺口。
用户安装后打开 DSH 网页版,右下角会出现可拖拽位置、可调整高度的插件卡片,点击授权按钮即可选择本地需要读写的目录。授权完成后,Agent 就能通过 browser_fs_list、browser_fs_read、browser_fs_write 三个工具操作浏览器机器本地的文件,卡片还支持目录浏览、文件预览、语法着色、文本编辑保存等功能。本插件面向需要在远程部署的 DSH 网页端访问本地文件的开发者,解决了跨设备文件访问的痛点。
本插件采用 MIT 许可证开源,可通过 npm 或 GitHub 直接安装到 DSH 的 web 配置文件,依赖 DSH 自带的 @deepseek-ai/dsh-tools 包。它存在一些使用限制:仅支持 UTF-8 文本读写,非安全上下文(非 HTTPS/localhost)会自动降级为兼容只读模式,且必须保持浏览器标签页打开才能使用。多设备场景下支持每台设备各自授权本机目录,工具调用会自动路由到对应设备执行。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-browser-fs(whitefirer/dsh-browser-fs)
仓库:https://github.com/whitefirer/dsh-browser-fs
本站详情页:https://www.yhbd.top/plugins/whitefirer-dsh-browser-fs/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-08-23 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-browser-fs
把 whitefirer/dsh-browser-fs 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-browser-fs
中文 | English
让 dsh 的 agent 读写浏览器所在机器的本地文件。dsh 自带的 fs 工具只能摸宿主机; 远程部署时浏览器在别的机器上,agent 够不到你本地的文件。本插件补上这个缺口:
用户在 dsh web 页面里通过 File System Access API(showDirectoryPicker)授权一个本地
目录,句柄存 IndexedDB;agent 通过三个模型工具 list/read/write 该目录下的文件,工具
调用经插件自建的 WebSocket 通道转发到浏览器执行。

原理
双面插件(cordis 插件体系):
- host 半(
src/index.ts,跑在 dsh 宿主 Node 进程)ctx.webServer.registerUpgrade注册精确路径/browser-fs/ws的 WS 通道;ctx.tools.register注册browser_fs_list/browser_fs_read/browser_fs_write;- execute 把
{type:'call', rpcId, op, args}帧发给「持有授权句柄」的标签页,按 rpcId 配对 result 帧;exec.signal接到 pending 的 abort(同时给浏览器发 cancel 帧)。
- client 半(
src/client/,浏览器里跑)- 启动时从 IndexedDB 读回句柄并
queryPermission;连回 host 的 WS(断线指数退避重连); - 收到 call 帧后在授权目录上执行 File System Access 操作,回发 result 帧;
- 在
shell.overlay层注册一张浮动卡片:显示连接/授权状态,提供 授权目录 / 重新授权 / 更换目录 / 解除授权 按钮。 - 授权状态变化时广播
{type:'state', hasHandle, dirName};host 只把调用派给hasHandle=true的标签页(多个标签在线时的执行者选择)。
- 启动时从 IndexedDB 读回句柄并
安装
# 从 npm 装(推荐,零脚本、无需构建授权)
dsh plugin --profile web add dsh-browser-fs
# 或直接从 GitHub 装(构建产物已入库,安装零脚本)
dsh plugin --profile web add github:whitefirer/dsh-browser-fs
# 本地开发:改代码后重装(改动需先 npm run build,产物 lib/ 已纳入版本库)
npm install
npm run build
dsh plugin --profile web add file:/abs/path/to/dsh-browser-fs
# 重启 dsh 后生效
dsh plugin add 会把本包装进 profile 的 dependencies,并因 manifest 里的
dsh.bundle.patch 声明自动把 dsh-browser-fs 追加进 dsh.profile.bundles 层栈
(patch 内容即本仓库的 cordis.patch.yml:insert 一行挂 host 半,config 含
wsPath 与 requestTimeoutMs)。
使用
- 打开 dsh web 页面,右下角出现「browser-fs 浏览器文件」卡片(未授权时默认展开; 授权后默认折叠成 📁 圆钮,点一下展开、按住可拖动,「—」收起;折叠状态存 localStorage,刷新保持,圆钮上的状态点颜色与卡片一致);
- 点「授权目录」,在系统选择器里选一个本地目录(需要 readwrite 权限);
- 卡片上的「目录内容」区可直接浏览授权目录:懒加载树(点目录行展开/收起, 每级上限 200 条,超出显示「…还有 N 项」),顶部搜索框支持递归搜索文件名/路径; 文件行显示大小并带「复制路径」按钮(复制相对路径,方便贴给 AI);
- 之后 agent 即可使用三个工具:
browser_fs_list { path?, recursive? }— 列目录(相对路径/类型/大小,递归可选)browser_fs_read { path, maxBytes? }— 读文本文件(默认上限 256 KiB,截断会标注)browser_fs_write { path, content }— 写文本文件(自动创建父目录,返回字节数)
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
MichengAI/dsh-codex-ui
HakureiMonika/dsh-sandbox-escalation-fix
PerryLink/dsh-claude-move
MutaLucem/dsh-plugin-integration
sheep-programmer/dsh-web-search-free