DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Session Scope — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-session-scope

Session Scope

DeepSeek Harness 的每个会话工作区可见性范围。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-session-scope@0.5.0
README兼容性版本

兼容性与来源证明

Session Scope 以 dsh-session-scope 发布,当前版本为 0.5.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/8/28

版本

0.5.0stable
2026/8/28

相关插件

正在加载相关插件…

最新版
0.5.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
285.3 kB
文件数
53
Surface
web
许可证
MIT
发布源
npm
GitHub
★ 0
周下载
0
最近提交
2026/9/6
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-session-scope

An independent per-session workspace visibility layer for DeepSeek Harness. A session keeps its original workspace and cwd while exposing only explicitly selected workspace directories to the agent.

The central policy rule is:

Permission != Scope

Permission controls effects (read-only, workspace-write, or danger-full-access). Session scope independently controls which part of the workspace is visible (full, focused, or Linux isolated).

Development status

0.5.0 implements the specification through Phase 4. It currently contains:

  • a TypeScript port of the reusable upstream directory picker, path safety, filesystem fence, and sandbox integration;
  • a strict TypeScript session-scope domain model;
  • the durable session-scope/set snapshot and last-write-wins fold;
  • full, focused, and isolated state vocabulary;
  • canonical root validation, nested-root collapse, navigation ancestors, and stable error codes;
  • typed host operations (getScope, setScope, listScopeDirectory, and getScopeCapabilities) plus the /scope command and session-scope projection;
  • pure visibility rules for content vs. navigation paths, filtered directory listings, and scoped glob/grep/search roots;
  • runtime filesystem enforcement carried per session with AsyncLocalStorage, including text and bounded byte reads, plus a monotonic final guard for known path-aware tools;
  • broad glob/grep composition across selected content roots, including fail-closed handling for an omitted path and output path revalidation;
  • model-facing scope context that exposes accessible roots without naming hidden siblings;
  • an independent Scope composer chip and tree picker, separated from the ordinary permission selector;
  • Linux isolated process confinement through DSH's existing bubblewrap provider for one-shot bash and persistent PTY creation;
  • an empty workspace overlay with only selected roots rebound, permission-aware read-only/writable mounts, and a post-mount working directory;
  • functional backend capability detection plus fail-closed handling for unknown runner profiles, partial enforcement, unsupported platforms, and danger-full-access;
  • a process lifecycle fence that prevents scope changes while foreground or background shell jobs and persistent terminals retain an old mount view;
  • scoped pre-step filesystem context for workspace instructions and project skill discovery, while user/OS paths outside the workspace retain ordinary DSH policy;
  • fail-closed LSP calls under selected scope because the current upstream LSP provider indexes the whole session workspace;
  • fork inheritance through the durable seed plus fail-closed subagent initialization before child publication, including nested and resumed children;
  • compatibility folding for legacy workspace-scope/selection sessions;
  • Vitest coverage for the ported primitives and new scope state.

Focused scope covers DSH filesystem services and known path-aware tools, but does not confine arbitrary shell processes. Isolated scope additionally confines DSH's supported bash and PTY launch paths when the Linux provider selects a fully enforcing, recognized bubblewrap profile. It is unavailable on other backends and cannot currently be combined with danger-full-access; these combinations fail closed instead of silently degrading to Focused.

Installation

npm install dsh-session-scope

The package ships the DSH bundle patch as cordis.patch.yml and exposes its server and web-client entry points through the package exports map. Node.js 20 or newer is required.

Development

npm install
npm run check

CI runs the TypeScript build, Vitest suite, package-contract checks, and a packed-plugin composition smoke test against the DSH releases listed in compatibility.json on Linux, macOS, and Windows.

TypeScript sources live in src/; npm run build emits distributable ES modules, source maps, and declarations into lib/. Tests run with Vitest.

Prior art and attribution

The initial directory picker, path canonicalization, filesystem fencing, and sandbox integration were adapted from dsh-workspace-scope-selection by jiangr100, used under the MIT License. The original copyright notice is preserved in LICENSE.