WJZ-P/dsh-attachments
DeepSeek Harness 插件。支持直接将图片、文件等拖入 dsh 中。更方便的拖拽;图片与文件拖放。
Project Overview项目介绍
dsh-attachments is a native plugin built exclusively for DeepSeek Harness. It is designed to add an intuitive, persistent, and low-profile file and folder attachment experience to DSH's web UI. It can be installed directly via the DSH CLI by running dsh plugin --profile web add dsh-attachment, and can be removed later with the corresponding remove command. It follows the standard DSH bundle convention, with a valid manifest that integrates smoothly with DSH's native input attachment slot, session system, and host routing.
When using the plugin, you simply drag and drop files or folders into the DSH input area, and the plugin will automatically generate a preview card for each attachment. After you submit your message, the plugin persists the attachment metadata and copies the file to the .deepseek-harness/attachments/ folder in your current working directory, so the LLM can access the file content directly. It leaves DSH's native image processing workflow untouched, so existing PNG, JPEG, WebP, and GIF images continue to use DSH's built-in preview and gallery tools. This plugin is designed for any DSH user that needs to attach multiple files or entire folders to their LLM conversations.
The plugin itself does not set any limits on the number of attachments or the maximum size of a single file; any actual limits come from your browser, your runtime environment, and the LLM you are using with DSH. To develop or build the plugin from source, you need Node.js version 22.19.0 or higher, plus the pnpm package manager to install dependencies and run the build script. The code is released under the permissive MIT open-source license, and includes input validation to block malicious paths like directory traversal and absolute Windows paths to prevent security issues. It has been tested on both Linux and Windows via GitHub CI to ensure cross-platform compatibility.
这是一个专为 DeepSeek Harness 开发的原生插件,为 DSH 带来直观、低侵入的文件与文件夹附件管理体验。它支持拖放上传,能够完整保留拖入文件夹的内部目录树结构,提供附件卡片预览与持久化存储,同时不改变 DSH 原生图片的原有处理流程。用户可以通过 DSH 官方 CLI 直接安装,执行 dsh plugin --profile web add dsh-attachment 命令即可完成安装,移除也只需一条对应命令。
用户使用时,只需将文件或文件夹拖入输入区,插件会自动生成对应的预览附件卡片,提交用户消息后会将附件元数据持久化,最终把文件复制到当前工作区的 .deepseek-harness/attachments/ 目录下,方便大模型读取文件内容。整个过程中,普通文件和文件夹由插件接管,原生图片仍然走 DSH 原有处理链路,不会打乱用户原有的使用习惯,适合所有需要在 DSH 会话中管理多文件附件的用户。
插件本身不限制附件数量或单文件大小,实际可用的容量限制由用户使用的浏览器、运行环境和目标模型共同决定。开发该插件需要 Node.js 22.19.0 以上版本和 pnpm 包管理器,代码遵循 MIT 开源许可,对所有输入做了安全校验,会拒绝非法路径写入避免安全问题,适配 DSH 的 Web profile 运行。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-attachments(WJZ-P/dsh-attachments)
仓库:https://github.com/WJZ-P/dsh-attachments
本站详情页:https://www.yhbd.top/plugins/wjz-p-dsh-attachments/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-08-19 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-attachment
把 WJZ-P/dsh-attachments 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-attachment
为 DeepSeek Harness 带来直观、持久、低侵入的文件与文件夹附件体验。
拖放即用 · 保留目录树 · 输入区与历史消息一致展示 ฅ( ̳• ·̫ • ̳ฅ)
English · 简体中文
✨ 功能亮点
| 能力 | 表现 |
|---|---|
| 📁 文件夹拖放 | 一个文件夹对应一张附件卡片,同时完整保留内部目录树 |
| 📄 普通文件 | 支持拖入、预览卡片、持久化历史与流式下载 |
| 🖼️ 原生图片共存 | PNG、JPEG、WebP、GIF 继续使用 Harness 原生图片预览、画廊和多模态检查 |
| 🧠 模型可读取 | 提交后写入当前工作区的 .deepseek-harness/attachments/,为模型提供明确路径 |
| 🧩 低侵入扩展 | 通过公开的输入附件栏 slot、会话定义与 Host 路由完成集成 |
| 🪶 原布局保持 | 输入区没有插件附件时,页面布局和原版 Harness 保持一致 |
插件自身不设置附件数量或单文件字节上限;实际可用范围由浏览器、运行环境与目标模型共同决定。
🖼️ 效果预览
拖放界面
拖入文件或文件夹时,只在原界面上方增加清晰的虚线边界,Harness 原生图片接收界面仍然保留。
图片消息历史
原生图片消息继续显示在持久化会话历史中,并可交给支持多模态输入的模型。
多图片预览
多张原生图片与插件提供的文件、文件夹卡片共用同一条输入附件区域。
🚀 安装
当前版本可直接从 npm 安装到原生 DSH 的 web profile:
dsh plugin --profile web add dsh-attachment
检查组合后的配置并启动 DSH:
dsh --profile web --dump-config
dsh --profile web
移除插件:
dsh plugin --profile web remove dsh-attachment
🧭 工作流程
flowchart LR
A["拖入文件或文件夹"] --> B["输入区附件卡片"]
B --> C["提交用户消息"]
C --> D["持久化附件元数据"]
D --> E["复制到工作区附件目录"]
E --> F["模型读取文件或目录树"]
- 浏览器端负责拖放识别、上传、输入卡片和历史渲染;
- Host 端负责字节传输、持久化元数据、下载路由与工作区落盘;
- 图片继续走 Harness 原生链路,插件只接管普通文件与文件夹;
- 拖入目录时,内部成员按完整目录树传输,不会拆成大量输入卡片。
📦 DSH 插件约定
本仓库是可直接安装的标准 DSH bundle:
package.json声明dsh.bundle.patch;cordis.patch.yml插入 Host 插件行;dsh.client.platform设置为web;exports["./client"]暴露预构建浏览器 bundle;- 官方
@deepseek-ai/*包全部使用peerDependencies; - 插件与 Tauri API 解耦,可用于原生 DSH Web profile。
🧪 开发与验证
环境要求:Node.js ^22.19.0 || >=24.0.0、pnpm。
pnpm install
pnpm run build
pnpm test
npm pack --dry-run
当前版本面向 DeepSeek Harness 0.1.0-rc.5 的标准 bundle、Web Client 发现、输入附件栏、会话事件与 Host 路由接口。
🔐 安全与跨平台
- 文件名、MIME 类型、附件 ID 与目录成员路径均按不可信输入校验;
- Windows 盘符、UNC 路径、绝对路径及目录穿越片段会在写入前被拒绝;
- GitHub CI 同时覆盖 Linux 与 Windows,避免路径语义差异造成回归;
- 安全问题报告方式及支持范围见
SECURITY.md。
🛍️ 插件市场
Marketplace 数据模板、截图 URL 和提交前检查项记录在 MARKETPLACE.md,README 图片资源位于 assets/markdown/。
📄 License
让附件安安静静待在该在的位置,也让模型更轻松地找到它们。 (。•̀ᴗ-)✧
nexu-io/open-design
EthanYoQ/AI-Novel-Writer
fufankeji/deepseek-harness-studio
EthanYoQ/Invoice-Downloader
Clarklevis1995/dsh-mobile
ZSeven-W/dsh-ios
THU-MAIC/dsh-openmaic
988hj7tczd-oss/dsh-computer-use