dsh-file-upload avatar

dsh-file-upload

DeepSeek Harness (dsh) file-message plugin: Claude-style drag-and-drop / paperclip upload, content sniffing, document-to-Markdown via Microsoft MarkItDown (with built-in JS fallback), text inlining, read_document tool for agents.

PluginKnowledgeAI ModelsFileStorage
Verification
L2 · Structured
Security
High
Health
Active
Trust
Silver

What it does

DeepSeek Harness (dsh) file-message plugin: Claude-style drag-and-drop / paperclip upload, content sniffing, document-to-Markdown via Microsoft MarkItDown (with built-in JS fallback), text inlining, read_document tool for agents.

Installation

dsh plugin --profile web add dsh-file-upload-2

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOHIGH-RISKSCAN9 FILES
dd93aa
Automated review · daily
HIGH-RISK

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

2 critical·0 warning·4 info·9 files scanned
code-exec ×2
scanned commitdd93aa74d0492026-08-17
latest commitdd93aa74d049

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: High2 critical · 0 warning · 4 info

• Static heuristic scan: done (9 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

Scan findings · 6

  • infoMakes network requests (fetch / axios)src/asr.ts:53
    const res = await fetch(options.endpoint, {
  • infoMakes network requests (fetch / axios)src/client/index.tsx:159
    const res = await fetch('/api/upload', {
  • infoMakes network requests (fetch / axios)src/client/index.tsx:477
    void fetch('/api/upload', {
  • criticalChild process module usage (Node.js)src/convert.ts:18
    import { execFile } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/index.ts:17
    import { execFile } from 'node:child_process'
  • infoReads process.envsrc/index.ts:194
    return process.env[config.asrApiKeyEnv]

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-16 · activity: Active

• Repo created: 2026-08-17

• Stars: ★ 4 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/HongMing-Huang/dsh-file-upload

Was this page helpful?