DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Wsl Workspace — DeepSeek Harness 插件(DSH Plugin)
← Plugins

dsh-wsl-workspace

Wsl Workspace

DeepSeek Harness 的 WSL 工作区支持:从 Web GUI 添加 WSL 工作区,并在 WSL 发行版内运行整个代理会话(bash + 文件工具),类似 VS Code Remote-WSL。无需在 WSL 内安装工具链。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:6Mikao9/dsh-wsl-workspace#79e8592f7c35daf979ba3e5ec48c80868d5a2910
README兼容性版本

兼容性与来源证明

Wsl Workspace 以 dsh-wsl-workspace 发布,当前版本为 0.4.3。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
github
Registry 更新时间
2026/9/20

版本

0.4.4stable
2026/9/19
0.4.3stable
2026/9/11
0.4.2
stable
2026/9/2
查看其余 13 个版本收起版本
0.4.1stable
2026/9/2
0.4.0stable
2026/8/29
0.3.2stable
2026/8/29
0.3.1stable
2026/8/24
0.3.0stable
2026/8/24
0.2.4stable
2026/8/21
0.2.3stable
2026/8/16
0.2.2stable
2026/8/14
0.2.1stable
2026/8/14
0.2.0stable
2026/8/14
0.1.2stable
2026/8/14
0.1.1stable
2026/8/14
0.1.0stable
2026/8/14

相关插件

正在加载相关插件…

最新版
0.4.3
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
web
许可证
MIT
发布源
github
GitHub
★ 50
周下载
453
最近提交
2026/9/19
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

dsh-wsl-workspace

English · 中文 · 日本語 · 한국어 · Français · Deutsch · Español · Português · Русский alt text Add a WSL workspace from the DeepSeek Harness web GUI and run the whole agent session — bash commands and file reads/writes — inside a local WSL distribution with Linux paths. Nothing needs to be installed inside WSL. The session can reach both WSL and Windows at the same time: bash commands run inside the WSL distribution, while Windows files stay accessible via /mnt/<drive> (for example /mnt/c/Users/...).

Install

Pick one of the three ways below, then restart dsh web:

# 1) npm package
dsh plugin --profile web add dsh-wsl-workspace

# 2) GitHub repository (ships the prebuilt lib/, no local build required)
dsh plugin --profile web add https://github.com/6Mikao9/dsh-wsl-workspace

# 3) Local directory (development / self-hosted)
dsh plugin --profile web add D:\path\to\dsh-wsl-workspace

After restarting dsh web, a W button appears beside Settings at the sidebar foot.

Usage

Click the W button beside Settings at the sidebar foot to open the "Add WSL workspace" dialog. Pick a distribution from the list, then browse the directory tree or type an absolute Linux path (for example /home/me/proj) — use the Check button to verify the path exists before creating the workspace. The dialog follows the DeepSeek Harness UI language. The username field is optional: leave it empty to run commands as the distribution's default user, or name a Linux user of that distribution to run the session as that user instead (equivalent to wsl.exe -u <username>). The username only changes the bash tool's run identity — the file tools go through the Windows-side WSL share and are unaffected. Each workspace's username is kept in <dshHome>/wsl-workspaces.json; delete the entry (or recreate the workspace from the dialog) to return to the default user.

Click "Create & open" to start a new session in the workspace. In the new session the bash tool executes commands inside the chosen distribution and read/write/edit operate on WSL files, so every path the model sees is a Linux path. The mode picker keeps working as usual: Standard, PTC, Minimal and Creative each land on their WSL variant automatically (the WSL variant entries in the picker are bilingual, e.g. WSL · Standard mode(标准模式)), and Windows files stay reachable from inside the session under /mnt/<drive> (for example /mnt/c/Users/...). The dialog's "?" button opens a panel with the DSH releases this build declares, how the plugin is used, and the limitations it cannot fix. alt text

Behavior notes

  • bash tool: runs inside the WSL distribution as the configured username (empty = the distro default user, often root), so it can read and write anywhere in the distro. The Windows ACL sandbox cannot wrap wsl.exe — its children run on the Linux kernel side — so WSL itself is the isolation boundary and the DSH file policy does not apply to bash.
  • File tools (read/write/edit): go through the Windows-side WSL 9P share and run under the DSH file policy. Under workspace-write, reads work anywhere but writes are restricted to the session workspace; switch the file policy to danger-full-access to also allow writes outside it. The username field does not affect the file tools.
  • Skill catalog: the session's skill catalog is discovered starting at the session cwd's nearest .git ancestor (falling back to the cwd itself), then scanning downward for .dsh/skills / .agents/skills — including nested projects — bounded to 4 directory levels, 64 skill directories and 4096 visited directories. Register the workspace at the project root you work in; if the registered workspace itself sits inside a larger git repository, the scan starts at that repository's root (matching the host's own rule) and sibling projects may surface. Results are cached for 10 seconds per scan root, so freshly added skills appear within that window; skill bodies always load live. One substrate limit to know: the Windows-side \\wsl.localhost share cannot resolve Linux symlinks (they read back as unresolvable entries), so a project linked into the workspace via ln -s is not discoverable — the scan walks past it without failing; register the workspace at a level that contains the real project directories instead. One more substrate limit affects every UNC workspace and cannot be worked around here: the model does not receive the skill catalog. The host skill provider watches the share with fs.watch, which fails with EISDIR on \\wsl.localhost\..., so that observation is reported incomplete and dsh-tool-skill withholds the whole catalog message while a snapshot is incomplete. The skills themselves stay reachable — the model can still load one by name with the skill tool — and a session in a Windows workspace on the same harness does receive the catalog.
  • The garbled localhost port-forwarding banner wsl.exe prints to stderr when the distro was not running yet is harmless.

Changelog

0.4.3 — 2026-09-11

  • The persona text moved in 0.1.3-alpha.2 (#22): DSH renamed the persona's model-facing scalar from text to an inline suffix plus a folded prefix, and the variant generator only recognised text: >-. On that line the WSL environment sentence was never appended - the session still ran inside the distribution, but the model was never told that its working directory is a Linux path reachable from Windows as /mnt/<drive>. The generator now amends suffix, text or prefix (folding an inline scalar into a block scalar when needed, so the sentence joins the working-directory line exactly where the legacy text block put it), and a persona carrying complete: true is still left alone. Verified on seven releases: the five older ones produce byte-identical presets, and the two newer ones now carry the sentence into the model's system message.
  • Help panel: the dialog gained a "?" button that opens an in-place panel - the DSH releases this build declares (read from package.json through the host route, so the list can never drift from the manifest), how the plugin is used, its features, and the limitations it cannot fix.
  • verify-lib hardening: its comment/string stripper could pair a lone apostrophe inside a comment with a later one and swallow the rest of the bundle, which made every node:* import look tree-shaken. The quote rules now stop at a newline, exactly as a JavaScript string does.

0.4.2 — 2026-09-10

  • Create & open in a 0.1.2-rc.1 workspace: the session starter is now resolved when the dialog writes, not when the plugin applies. This plugin applies before the UI domain that publishes uiWorkspace registers its service, so the lookup cached at apply time stayed undefined for the whole page life: Create & open created the workspace and then silently opened no session, leaving sessionIds empty while the dialog reported success. A release exposing neither uiWorkspace.startSession nor workspaces.startSession now fails before anything is written, instead of leaving an orphaned workspace behind.
  • Skill body integrity: skill bodies no longer lose their first character. findFrontmatterEnd already returns the index of the body's first character (the closing delimiter's newline plus one), so the slice must start there; the previous offset dropped that character and made the one after the delimiter look like the body. The existing fixtures always put a blank line after the delimiter, which is exactly what hid it.
  • UTF-8 BOM skills are no longer dropped: a SKILL.md saved with a leading BOM (Notepad, VS Code's "UTF-8 with BOM", PowerShell redirection) did not match the opening --- and disappeared from the catalog entirely. The parser strips the BOM before the fence check.
  • Binding converges on late inputs: the agent-preset roster and the registered /mnt/<drive> workspace set are both inputs to binding, and both land asynchronously after the plugin's first pass. Each now re-runs the pass when it arrives instead of waiting for a session-store event that may never come.
  • Compatibility manifest corrected: 0.1.3-alpha.1 is not published (npm view @deepseek-ai/dsh@0.1.3-alpha.1 is a 404), so the declaration could never be verified; it is replaced by the published 0.1.3-alpha.2.
  • Reproducible publishes: a new .gitattributes (* text=auto eol=lf, lib/** -text) pins line endings. core.autocrlf=true used to rewrite text files to CRLF on checkout, and since lib/ is committed and published verbatim the same commit produced different npm tarballs depending on the machine; the repository already stored LF, so no renormalisation was needed.
  • Closed-loop tests: tests/client-lifecycle.test.mjs drives the browser half through the shipped lib/client.js for both service shapes — legacy ( + ) and current ( + ) — and asserts for the normal, late-registration and no-starter cases. The skill tests now cover a body that starts on the delimiter's next line, for LF and CRLF files.

0.4.1 — 2026-09-03

  • DSH v0.1.2-rc.1 compatibility: Added backward compatibility support for DSH v0.1.2-rc.1 and later versions through feature detection and compatibility wrappers. The plugin now automatically detects the DSH version at runtime and uses the appropriate API:
    • uiWorkspace.startSession() for v0.1.2-rc.1+
    • workspaces.startSession() for v0.1.1-rc.2 and earlier
    • summary.projectionValues?.agentPreset for v0.1.2-rc.1+
    • summary.agentPreset for v0.1.1-rc.2 and earlier
    • Projection-based auto-sync for v0.1.2-rc.1+
    • sessions.noteAgentPreset() for v0.1.1-rc.2 and earlier
  • Updated compatibility manifest: Added v0.1.2-rc.1 to the dsh.compatibility.dshReleases declaration.
  • Fixed without inject crash on v0.1.2-rc.1+: the agent-preset roster is read through the remote.agentPresets namespace service via ctx.get('remote.agentPresets') (topology-free store lookup) instead of the remote aggregate's agentPresets property, which Cordis' associate proxy rejects when the dotted property is not declared in inject. inject stays limited to the services both DSH generations share (slots, locale, sessions, workspaces).
  • Compatibility manifest: declared v0.1.3-alpha.1 compatible (its plugin-facing API surface matches v0.1.2-rc.1). Final adaptation notes consolidated in docs/COMPATIBILITY_SUMMARY.md (supersedes the root-level draft plans).

0.4.0 — 2026-08-29

Follow-ups from the #12 limitation list and the #13 compatibility work:

  • Lookup cache: completed skill-catalog lookups are cached per scan root for 10 seconds, so repeated catalog builds no longer rescan the workspace over the slow 9P share; get() keeps reading skill bodies live, and freshly added skills appear within the TTL window.
  • Symlinked projects — investigated, substrate-limited: the discovery walk now recognizes directory symlinks explicitly and prunes them safely (no crashes, no loops). Following them is not possible over the \\wsl.localhost 9P share — the Windows side cannot resolve Linux symlink targets (probed: readlink → EISDIR, stat/readdir → ENOENT) — so a project linked into the workspace via ln -s stays undiscoverable; a name+body fingerprint dedupe also guarantees aliased skill files can never publish twice on substrates that do resolve links.
  • Block-scalar frontmatter: description: / whenToUse: written as YAML block scalars (| literal, > folded) now parse — such skills were silently dropped before.
  • Compatibility manifest: dsh.compatibility.dshReleases declares per-release compatibility with the official DSH versions, backed by reproducible disposable-Profile install/start/uninstall evidence (scripts/verify-dsh-compat.sh), and engines declares the Node.js floor.
  • Guard scripts: scripts/check-rank-parity.mjs fails the release when the copied project-rank constants drift from the host's dsh-skill-filesystem.

0.3.2 — 2026-08-29

  • WSL workspace sessions now inject nested-project skill catalogs (#10): .dsh/skills and .agents/skills directories of projects nested below the registered workspace root are discovered and published with the host's project ranks and sources, so the model sees the same skill catalog it would see when the session cwd is the project folder itself. Discovery is depth- and budget-bounded, prunes node_modules/dot-directories, and leaves non-WSL sessions untouched.
  • Host-parity scan root: lookups from inside a project subtree resolve the nearest .git ancestor first, so the enclosing project's skills stay visible from deeper cwds; skills above that ancestor do not leak.
  • Hardening: the skill-root budget is enforced per push, and the skills.registerProvider call is guarded so a host whose skills service has a different shape can no longer break plugin load.
  • Housekeeping: removed stale prebuilt lib/ chunks that shipped dead vendor code (including an inlined schemastery copy that triggered dsh.so's new Function static rule); added scripts/repro-setup.sh plus a nested skill-catalog regression suite, and a matching TESTING.md section.

License & attribution

MIT — see LICENSE and NOTICE. The NOTICE precisely lists:

  • Adapted/inherited source code: DeepSeek Harness (MIT) — dsh-bash-local (executor mechanics), dsh-fs-local (WslFileSystem subclasses it), and the shipped agent presets (read and transformed by the variant generator);
  • Design references (no source copied): dsh-bash-terminal (MIT, wsl argv / WSLENV approach), dsh-side-panel (BSD-3-Clause, host-route pattern), vpshub (MIT, roadmap reference).

Keep LICENSE and NOTICE when redistributing.

Acknowledgments

Special thanks to dsh-deep-whale (DSH Web 鲸鱼娘 skin series · 深海女仆工坊 maid-atelier, CC BY-NC-SA 4.0): the whale girl skin plugin brings a full set of adorable skins to the DeepSeek Harness Web UI and makes daily use of DSH a warmer experience.

connection.api.agentPresets
workspaces.startSession
remote.agentPresets
uiWorkspace
Create & open