DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

File Uploads — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins
F

dsh-file-uploads

File Uploads

Upload arbitrary local files from the DeepSeek Harness Web composer, attach them to prompts, and manage stored uploads in Settings.

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:l541402398/dsh-file-uploads#3ea46e1583eac426cc34e191ea811e71b0c8347e
READMECompatibilityVersions

Compatibility and provenance

File Uploads is published as dsh-file-uploads and currently resolves to version 1.0.0. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
web
Release source
github
Registry updated
8/21/2026

Versions

1.0.0stable
8/21/2026

Related plugins

Loading related plugins…

Latest
1.0.0
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
web
License
MIT
Source
github
GitHub
★ 0
Weekly downloads
0
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in productivity-workflow.

Acp App@deepseek-ai/dsh-acp-appThe dsh ACP profile bundle: automation-only JSON-RPC stdio and process lifecycle over dsh-baseClient Ui Task Board@linxin666/dsh-client-ui-task-boardHost-authoritative task board for the DSH Web GUI with real session execution, Host cron scheduling, and optional cross-platform idle-sleep protection; mounted without DSH source changes.Web All@linxin666/dsh-web-allDSH Web UI 全家桶聚合插件:一键安装全部功能插件(task-board / git-graph / pet / remote-web-ui / web-ui-settings / skin-center / community-plugins / compat shim)。compat 桥接层已并入本包(src/client),无需独立 compat npm 包。Agent Teams@nanmicoder/dsh-agent-teamsAgentTeams for DeepSeek Harness: multi-agent team collaboration (captain, members, tasks with dependencies, messaging) driven by natural language, with a tree monitor in the web GUI

README

dsh-file-uploads

English | 简体中文

Upload arbitrary local files from the DeepSeek Harness Web composer, attach their container paths to prompts, and manage stored uploads from Settings.

Features

  • Adds a Files button beside the existing composer controls.
  • Accepts multiple arbitrary local files, not only images.
  • Shows pending files as image-like cards above the composer.
  • Keeps the text editor clean: no visible path or generated description is inserted into the draft.
  • Serializes each hidden file reference into a model-readable absolute path only when the message is submitted.
  • Clears pending cards after submission and restores them when submission fails.
  • Stores every upload in one fixed directory, $DSH_HOME/uploads by default.
  • Lists uploaded files in Settings → Uploaded files, with download and delete actions.
  • Prevents overwrites by publishing duplicates as name (1).ext, name (2).ext, and so on.
  • Enforces per-file and total-directory quotas.

Compatibility

  • DeepSeek Harness 0.1.0-rc.6
  • Web profile
  • Node.js 22 or newer

Harness currently transports native attachments as raster images only. This plugin intentionally uses the arbitrary-file path supported by the agent environment: it stores the file inside the Harness host/container and adds that path to the submitted text through the built-in input-reference serializer.

Install

Install the tagged GitHub release into the Web profile:

dsh plugin --profile web add "github:l541402398/dsh-file-uploads#v1.0.0"

Restart the running Web profile after installation, then refresh the browser page.

To install the latest development branch instead:

dsh plugin --profile web add "github:l541402398/dsh-file-uploads#main"

To remove it:

dsh plugin --profile web remove dsh-file-uploads

Use

  1. Open a conversation in the Harness Web GUI.

  2. Select Files in the composer toolbar.

  3. Choose one or more local files.

  4. Review or remove the pending cards above the composer.

  5. Add any normal prompt text you want, or leave the editor empty.

  6. Submit the message. The model receives a line such as:

    上传文件:`/path/to/.dsh/uploads/report.pdf`
    

The generated line is never shown in the editor before submission. The stored path refers to the filesystem visible to the Harness host; in a Docker deployment, this is the path inside the container.

Settings

The plugin adds an Uploaded files section to Settings. It displays:

  • the fixed storage directory;
  • per-file and total-directory limits;
  • current storage usage;
  • file name, size, modification time, and absolute path;
  • download and delete actions.

Files persist until they are deleted manually.

Configuration

The plugin works without configuration. These environment variables override its defaults:

VariableDefaultPurpose
DSH_UPLOAD_DIR$DSH_HOME/uploadsAbsolute upload directory.
DSH_UPLOAD_MAX_BYTES104857600Maximum bytes per file (100 MiB).
DSH_UPLOAD_TOTAL_MAX_BYTES1073741824Maximum total bytes in the directory (1 GiB).

Example Docker Compose fragment:

services:
  dsh:
    environment:
      DSH_UPLOAD_DIR: /data/dsh/uploads
      DSH_UPLOAD_MAX_BYTES: 104857600
      DSH_UPLOAD_TOTAL_MAX_BYTES: 1073741824
    volumes:
      - ./dsh-data:/data/dsh

Security model

  • List, upload, download, and delete routes use the same loopback/trusted-host and Origin checks as the built-in Harness Web API.
  • Cross-site browser requests are rejected.
  • File names are normalized and stripped of path components and control characters.
  • Downloads and deletions accept only regular files in the configured directory and do not follow symbolic links.
  • Uploads are written to private temporary files, synced, and atomically published without overwriting existing files.
  • Interrupted .upload-* temporary files are removed when the plugin starts.
  • Unexpected server errors are logged without returning internal paths to the browser.

This trust fence is not a user-account authentication system. If the Harness Web GUI is exposed to other users or the public Internet, protect the whole deployment with an authenticated reverse proxy and configure Harness trusted hosts correctly.

Development

Run the checks:

npm test
npm run check

The package is a persistent dual-face Cordis bundle:

  • index.js — Host HTTP routes, storage, quotas, and trust checks.
  • client.js — composer button, pending-file rail, hidden reference codec, and Settings UI.
  • cordis.patch.yml — installable dsh.bundle composition row.
  • test/upload-manager.test.js — Host storage and security regression tests.

See CONTRIBUTING.md for local-link development instructions.

License

MIT