nailing10086-zx/dsh-custom-ui
Custom UI for DeepSeek Harness Web: right-side file-tree sidebar, workspace file open, balance meter.
This is a DeepSeek Harness (DSH) plugin. Review its GitHub README, installation information, maintenance status, and public security signals here.
No Chinese README provided upstream — showing the repository’s original content.
dsh-custom-ui
Custom UI plugin for DeepSeek Harness Web.
Adds a right-side file-tree sidebar, workspace file open, and a DeepSeek account balance meter in the composer stats line.
Features
- Balance meter — shows the DeepSeek account balance in the composer stats line. The API key is resolved server-side only through the credentials seam (
credentialReffrom@deepseek-ai/dsh-credentials) — it never crosses the wire to the browser. - File tree sidebar — a right-side workspace file tree for quick navigation, with collapse/expand and a floating toggle button.
- Workspace file open — open files/folders with the system default application (workspace-rooted; path traversal guarded).
Install
dsh plugin --profile web add dsh-custom-ui
Then restart dsh web. If installed from a local checkout instead, link it via pnpm link (or "dsh-custom-ui": "link:<path>" in the profile's package.json) and rebuild.
Requirements
- DeepSeek Harness Web (
dsh web) DEEPSEEK_API_KEYconfigured in the harness credentials (for the balance meter; the file tree works without it)
Host routes
| Route | Purpose |
|---|---|
GET /api/custom-ui/balance | DeepSeek account balance (via DEEPSEEK_API_KEY through the credentials seam) |
GET /api/custom-ui/fs/list | Directory listing (workspace-rooted) |
GET /api/custom-ui/fs/open | Open a file/folder with the system default |
Development
# host half (server routes)
node lib/index.js # or run through dsh plugin dev flow
# client half (browser UI) — HMR while `pnpm run dev:web` runs in the DSH checkout
# client-plugin changes reload without a refresh only while the dev:web watcher is running
Build the client bundle with your DSH toolchain, then restart dsh web.
Security
- The API key is resolved server-side only; the browser client never receives it.
- File routes are workspace-rooted:
resolve()+ prefix check against the workspace root blocks path traversal. - Review
lib/index.jsandlib/client.jsbefore installing if you did not clone from the official repo.
License
MIT — see LICENSE.
Security & install evidence
This score is based solely on public repository metadata and the install evidence registered here — it is not a code security audit.
From a public plugin catalog, linked to a public GitHub repository.
The repository declares the MIT license.
Code updates within the last 180 days.
No verifiable install metadata registered yet — please review the repository instructions manually.
The inspected package metadata declares no install lifecycle scripts.