
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
dsh-plugin-workbench
Advanced tools
VS Code-style workspace file explorer for the DeepSeek Harness web GUI — editable preview with syntax highlighting, tabs and line numbers, full right-click file operations (create / rename / delete / copy / cut / paste / reveal in file manager), inline im
能直接改文件的 VS Code 风格工作台——不是只读预览:文件树 + 可编辑代码预览 (语法高亮、标签页、行号栏)+ 右键文件操作(新建 / 重命名 / 删除 / 复制 / 剪切 / 粘贴 / 在系统中打开 / 在资源管理器打开)+ 图片内联预览,每个工作区独立保存状态。 装上之后,DSH 网页就是一个轻量代码编辑器。
✅ 开箱即用:0.0.9 起布局补丁全自动——装完重启即生效;DSH 升级覆盖 bundle 后插件会自动补回,无需任何手动操作(仅锚点失效时才需手动,见「配置」节)。 0.0.15 起自动识别 npm 与 DSH Desktop 两种构建产物,DSH Desktop 开箱即用。
装完你会看到:
@相对路径 变成可点击链接,点开直接在工作台预览;
真实 Web GUI 截图。
Ctrl+S/Cmd+S 保存;
md 默认渲染预览(源码/渲染一键切换),.txt 等散文格式与超大代码文件
自动降级为纯文本编辑,加载快、不卡界面explorer / macOS open,WSL 自动转译)@相对工作区路径 插入聊天输入框;
发送后消息中的 @相对路径 渲染为超链接(点击在工作台预览打开),
语法为 @ + 相对工作区路径,其它 @文本 一律按原样显示、无特殊含义.dsh-trash,不复制字节)reveal 端点执行/dsh-plugin-files/raw/<path> 内联显示fs.watch(监听父目录,可存活原子重命名),
变更经 SSE /dsh-plugin-files/events 推送,干净标签自动同步无需环境变量或配置文件;布局补丁全自动(插件启动时自动检测并重跑
scripts/patch-layout.mjs,幂等、非阻塞;0.0.15 起自动识别同一版本的两种构建产物
——npm 构建与 DSH Desktop 内置构建;锚点与编译产物字节级耦合,DSH 升级后如失配
需更新锚点):
/dsh-plugin-files,写操作显式以 danger-full-access 执行,无外部配置项。布局补丁锚点与 DSH 编译产物字节级耦合,DSH 升级后如失配需更新锚点;0.0.15 起 自动识别 npm / DSH Desktop 两种构建产物,插件启动时自动检测并重打补丁 (详见「配置」节)。
# npm(推荐)
dsh plugin --profile web add dsh-plugin-workbench
# 或 GitHub
dsh plugin --profile web add github:Pasumao/dsh-plugin-workbench
源码安装(本地开发 / 调试):
git clone https://github.com/Pasumao/dsh-plugin-workbench.git
cd dsh-plugin-workbench
pnpm install
pnpm run build # 产出 lib/index.js 与 lib/client.js
# 以 link: 方式挂载进 profile
安装后打布局补丁并重启:
node node_modules/dsh-plugin-workbench/scripts/patch-layout.mjs
# 重启 dsh web
0.0.9 起插件启动时会自动检测并重打布局补丁,DSH 升级后无需再手动跑; 仅当自动重打失败(锚点失效)时才需手动执行上面的命令。
pnpm install
pnpm run build # 产出 lib/index.js(host)与 lib/client.js(browser)
pnpm run typecheck
dsh plugin --profile web remove dsh-plugin-workbench
# 可选:把布局 bundle 还原为官方原始版本(推荐,卸载后干净如初)
node node_modules/dsh-plugin-workbench/scripts/patch-layout.mjs --restore
# 重启 dsh web
不跑
--restore也没关系:0.0.18 起布局补丁会自适应——explorer 列在没有插件 往explorer/explorer.preview插槽注册内容时自动收起(宽度归 0), 卸载后不会残留空列。--restore只是把它还原成完全未打补丁的原始 bundle。 脚本带两道防呆:目标看起来已是未打补丁的新版 bundle(dsh 刚升级过)、或备份 属于更旧的 dsh 版本时,会拒绝回滚并提示(--force可强行恢复)。
/dsh-plugin-files RPC 通道仅限 loopback;写操作显式以 danger-full-access 执行;
右键菜单的新建/重命名/删除同样经该通道(loopback 信任,与编辑器保存一致)/dsh-plugin-files/raw/<path>:仅响应图片扩展名,
先经 ctx.fs.resolve → stat(沙箱一致的路径解析)再读取字节,20MB 上限scripts/patch-layout.mjs(0.0.15 起锚点表分
npm / desktop-ci 两个构建变体自动探测,desktop-ci 变体存于
scripts/layout-anchors.desktop-ci.json)见 CONTRIBUTING 与 CODE_OF_CONDUCT; 变更记录见 CHANGELOG。
0.1.2-rc.1(0.0.16 起布局补丁锚点适配该版:detailsCol 边框样式
1px/--dsw-alias-border-l2 → .5px/--dsw-alias-border-l3、DetailsColumn 的
children 新增 SessionProvider 包裹);0.1.1-rc.2 及更早版本用 0.0.15 的锚点表。ui-layout patch exited 1,此时升级本插件即可。本插件属于 Pasumao 的 dsh 插件生态,同系列已发布插件可搭配使用:
| 插件(npm) | GitHub | 说明 |
|---|---|---|
| dsh-notify | GitHub 仓库 | Windows 原生通知 + 系统托盘 |
| dsh-plugin-choice-refresh | GitHub 仓库 | 选择增强:重新生成选项 / 更多选项 |
| dsh-plugin-dev-kb | GitHub 仓库 | 插件开发知识库(官方文档完整镜像 + 技能) |
| dsh-plugin-image-tools | GitHub 仓库 | 图片选择卡 + 回复内嵌图片 + 盲模型收图 |
| dsh-plugin-table-zoom | GitHub 仓库 | 聊天长表格浮窗查看 + 一键复制 Markdown |
| dsh-plugin-windows-guard | GitHub 仓库 | Windows 环境防坑:守则技能 + 乱码检测 / 危险写拦截 / 编码诊断修复 |
| dsh-plugin-context-trim | GitHub 仓库 | 会话注入门控:skill / tool / 提示词段落按会话裁剪 |
本系列其余插件见 Pasumao · dsh 插件;觉得好用欢迎到 GitHub 点 ⭐。
部分源码与文档由 AI 辅助生成(DeepSeek Harness),均经人工审查与实机验证; 权限相关逻辑已按最小权限原则复核。
FAQs
[DISCONTINUED 2026-09-11: DSH >=0.1.5 ships a built-in workspace file tree + document preview (dsh-client-ui-sidebar-files / sidebar-documentpreview); please uninstall and use the built-in features] VS Code-style workspace file explorer for the DeepSeek H
The npm package dsh-plugin-workbench receives a total of 286 weekly downloads. As such, dsh-plugin-workbench popularity was classified as not popular.
We found that dsh-plugin-workbench demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.