somnusovis/dsh-multi-workspace
Multi-workspace sandbox: grants file-write access to every registered workspace automatically — add a workspace, write to it immediately, no config or escalation needed.
A multi-workspace sandbox for DeepSeek Harness that automatically grants file-write access to all registered workspaces — add a workspace in the UI, write to it immediately, no config needed. By default the DSH file sandbox only allows writes to one workspace directory (the session cwd) and writing elsewhere requires sandbox escalation. The plugin reads the live workspace registry on every sandbox policy check and injects every registered workspace path as an additional writable root, in two layers: it wraps sandboxPolicy.resolve() to attach workspace paths, and wraps fs.writeText/editText with a retry fallback on each workspace root. The README also documents a subtlety it guards with a smoke test: the wrapped resolve() must return a plain object, because executors spread the policy and a prototype-based copy silently drops the keys, making the Windows-ACL runner fail with SANDBOX_UNAVAILABLE.
Install
dsh plugin --profile web add github:somnusovis/dsh-multi-workspaceREADME Installation block quoted verbatim; it also lists the npm form dsh plugin --profile web add dsh-multi-workspace under "Or from npm (once published)". Registry-verified live 2026-09-15: dsh-multi-workspace returned HTTP 404 on registry.npmjs.org, so the GitHub form is used and no npm ownership or version claim is made. After install the README says to restart the DSH web service and refresh the browser.
Compatibility
Widens the fs sandbox only: the README states shell commands stay confined to the session workspace because the command sandbox seam reads only the single policy.workspaceRoot, so pwsh / bash writes outside the session workspace are still denied. Under workspace-write the fs fallback retries without going through the approval flow, so the README advises making sure the registered workspaces are trusted.
Details
- Repo: somnusovis/dsh-multi-workspace
- Category: Tools & Capabilities
- Stars: 0
- Version: README does not pin a version (npm name did not resolve on 2026-09-15)
- Last push: 2026-08-29
- First seen: 2026-08-15
Recent updates
The README documents the mechanism, limitations and a regression guard rather than a release-by-release changelog; the npm name did not resolve when checked on 2026-09-15.
FAQ
- How do I install it?
- The README's install command is dsh plugin --profile web add github:somnusovis/dsh-multi-workspace, then restart the DSH web service and refresh the browser.
- Does it widen shell access too?
- No — the README says the widening applies to the fs tools only; shell commands remain confined to the session workspace because the command sandbox seam reads only the single workspace root.
- Is there a safety caveat?
- Yes — the README notes the fs fallback silently retries under workspace-write without the approval flow, so registered workspaces should be trusted.
Alternatives
1624318455/dsh-plugin-tavily · 6Mikao9/dsh-wsl-workspace · 863683348/dsh-plugin-finance-data