Jesse-njx/dsh-cowork
Adds first-class office-document and notebook handling to coding agents inside DeepSeek Harness (and through its MCP server and CLI anywhere else). doc_read returns bounded, cell-addressed windows for xlsx and shape ids for pptx; doc_write consumes those stable addresses for xlsx and ipynb creation and editing, so binary formats are addressable in a way line numbers can never be. Five formats are readable — xlsx, ipynb, pdf (text windows by page), docx (paragraphs + word count) and pptx (slides + shape ids) — with explicit truncation notices instead of silent cuts. The safety model caps zip entries and decompressed size before any codec expands bytes (zip-bomb guard), rejects macro formats (.xlsm/.docm/.pptm, anything with vbaProject.bin) outright, refuses edits unless the file was read in the same session (expected_version, optional expected_sha256 hash check), clears stale cached formula results so Excel/LibreOffice recalculate, and writes atomically via temp file + rename.
Install
dsh plugin --profile <your-profile> add ./packages/dshREADME install (GitHub delivery — the README states the DSH bundle is not published to npm): git clone https://github.com/Jesse-njx/dsh-cowork, cd dsh-cowork, pnpm install (the prepare script builds every package), then dsh plugin --profile <your-profile> add ./packages/dsh. Restart and doc_read / doc_write are available to the model. Configuration is optional via the profile's cordis.patch.yml (cowork-docs row: maxInputBytes, maxOutputBytes, maxDecompressedBytes, maxZipEntries, maxPages, maxSheetRows, maxSheets, maxSlides, maxCells). MCP clients (Codex, Claude Code) can instead point at packages/mcp/lib/index.js, and doc-read / doc-write CLI binaries plus a SKILL.md ship in packages/cli.
Compatibility
Node 20+ and pnpm; installed into a DSH profile. Reading routes through ctx.fs with sandbox-aware resolution; in read-only sandbox mode doc_write is hard-blocked while doc_read stays available.
Details
- Repo: Jesse-njx/dsh-cowork
- Category: Other
- Stars: 6
- Version: GitHub install (README states the DSH bundle is not published to npm); the npm name dsh-cowork resolves to 0.0.1 on registry.npmjs.org with no repository field
- Last push: 2026-08-13
- First seen: 2026-08-13
Recent updates
The README documents v1 scope and the v2 roadmap: v1 reads all five formats and writes xlsx + ipynb; v2 plans ipynb write polish, docx/pptx generation, PDF form-fill with pdf-lib, PDF page-render-to-image for vision models and docx raw-OOXML editing. It also notes tests (pnpm -r test: core 35 + plugin 15 + cli 6 + mcp 7) and that the DSH bundle re-observes the real post-write version so the built-in policy machinery stays coherent, because the fs service itself is text-only.
FAQ
- How do I install dsh-cowork into DeepSeek Harness?
- Clone the repository, run pnpm install (it builds all packages), then dsh plugin --profile <your-profile> add ./packages/dsh. The README states GitHub delivery is the path because the project is not published to npm.
- Can it read spreadsheets, PDFs and slide decks?
- Yes — xlsx (bounded cell-addressed windows), ipynb (cells + inline outputs), pdf (text windows by page), docx (paragraphs + word count) and pptx (slides + shape ids). Writes in v1 cover xlsx and ipynb only.
- Does it execute macros or formulas from documents?
- No. Macro formats are rejected outright, and formulas, hidden sheets and speaker notes are treated as data — surfaced with the extraction, never executed. Zip bombs are blocked by entry-count and decompressed-size caps checked before any codec expands bytes.