Skip to main content

dsh-browser/packages/browser/bridge-browser

347Stars17Forks3Issues1Watchers

Mount a token-authenticated WebSocket bridge in dsh web configuration, enabling the Chrome extension to read and manipulate pages within the user's real browser while preserving login state.

Evidence4/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki

ⓘ This plugin is a sub-package of the Lum1104/dsh-browser monorepo — stars and activity count the whole repository.

Language
TypeScript
License
MIT
Branch
main
browser-automationchrome-extensioncoding-agentcordisdeepseekdeepseek-harnessdshdsh-plugin

Install

cmdweb profile
$ dsh plugin --profile web add github:Lum1104/dsh-browser#path:packages/browser/bridge-browser

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin Lum1104/dsh-browser/packages/browser/bridge-browser for me: review the repository at https://github.com/Lum1104/dsh-browser first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Positioning

This plugin is the browser operation bridge for dsh web profile: mounts a token-authenticated WebSocket channel on the host webserver, allowing the Chrome extension to connect in and read and operate the page you are browsing, with login state and session preserved throughout.

Core Capabilities

  • Read structured text snapshots of the current tab (title, URL, body, numbered interaction list, and sanitized form fields)
  • Click elements by number, append or replace text in input boxes, send keyboard keys (Enter/Tab/Escape/Arrow keys, etc.)
  • Scroll viewport up/down, jump to top or bottom, scroll by pixels
  • Navigate to any HTTP(S) address within the current tab, as well as forward, backward, refresh
  • Read plain text from any page area or selector
  • Wait for page load and DOM changes to stabilize, with optional additional delay

Technical Implementation

  • Language: TypeScript
  • Key Dependencies: @deepseek-ai/schemastery (config schema), ws (WebSocket server), @deepseek-ai/dsh-tools (tool registration), @deepseek-ai/dsh-host-webserver (mount upgrade route)
  • Architecture Pattern: Cordis plugin, injected into dsh's web profile via dsh.bundle.patch; the plugin registers /ext/bridge WebSocket upgrade route and /ext/bridge-config HTTP endpoint on webServer, and pumps session events per connection via ctx.apiProxy.events.mux; browser_* tools are registered on ctx.tools, each execution dispatches tool.call frames to the extension via WebSocket
  • Entry File: packages/browser/bridge-browser/src/index.ts

Use Cases

Suitable for directly operating already-logged-in webpages within dsh (e.g., admin dashboards, SaaS consoles, multi-step flows requiring cookie preservation). DSH models lack visual capabilities, so this plugin provides a pure-text "read page + click/fill by number" toolchain, letting the model complete tasks in the user's own Chrome rather than launching a headless browser. Privacy-sensitive everyday users can also use it for form filling, content extraction, and cross-page navigation.

Prerequisites & Compatibility

DependencyMinimum VersionDescription
DSH^0.1.0-rc.6Locks dsh-* series packages via peerDependencies; root workspace actually pinned to 0.1.0-rc.8
Node.js^22.19 or >=24Repository root README mandate
Package Managerpnpm 11.xRepository uses pnpm workspace, lockfile at root
BrowserGoogle ChromeRequires Chrome MV3 extension installed together, loaded from ~/.dsh/browser-extension
PlatformCross-platformNot OS-specific, but requires local Chrome and the Node version above

This plugin declares no additional native module dependencies.

Installation

dsh plugin --profile web add github:Lum1104/dsh-browser/packages/browser/bridge-browser

For complete installation (Chrome extension build and load), use the repository's install script: curl -fsSL https://raw.githubusercontent.com/Lum1104/dsh-browser/refs/heads/main/scripts/install.sh | bash. This command alone only registers the bridge plugin; the extension needs to be built separately and loaded into Chrome.

Configuration Options

ConfigTypeDescriptionDefault
tokenstringFixed bearer token for WebSocket handshake; when missing, auto-generated on first start and written to ~/.dsh/ext-bridge-token (permissions 0600), startup log prints it simultaneouslyAuto-generated
toolTimeoutMsnumberMaximum wait time for a single tool call (ms), reserves 60 seconds for extension approval window90000
snapshotMaxCharsnumberMaximum characters allowed per page snapshot, also negotiated and sent to extension via hello32000 (min 500)
maxInteractiveItemsnumberMaximum number of numbered interactive elements per snapshot60
sessionWorkspacePathstringWorkspace directory for sessions created by extension; GUI groups them separately~/.dsh/browser-sessions (empty string = no grouping)
deferSessionCreatebooleanWhether to skip actual session creation when opening sidebar but not sending messagestrue

Environment variable DSH_EXT_TOKEN can inject token, and DSH_BROWSER_SESSION_WORKSPACE can override the session workspace path (same name as field above, equivalent).

FAQ

Q: After installation, the sidebar keeps showing "Not Connected"?

A: The dsh plugin command only registers the bridge bundle to the local web profile; if dsh was already running before installation, it won't auto-load the new plugin. Stop the current dsh process and re-run pnpm start or npx @deepseek-ai/dsh web, the extension will automatically detect the bridge address via /ext/bridge-config and reconnect, no reconfiguration needed.

Q: Do I need to manually copy-paste the Token?

A: Local (127.0.0.1) loopback connections don't require a Token; the extension directly gets the WebSocket address via /ext/bridge-config and connects. Only when using --host 0.0.0.0 to make dsh listen on non-loopback addresses do you need to fill in the Token in the sidebar settings.

Q: Which webpages cannot be read or operated?

A: Protected browser built-in pages (such as chrome://, chrome-extension://, Chrome Web Store) cannot have content scripts injected, so this plugin doesn't support them; only regular http:// or https:// pages work. Already-opened pages don't need refreshing; the extension will automatically inject the script on first operation.

Q: Will passwords or bank card numbers be sent to the model?

A: No. Sensitive fields (type=password and payment card numbers) are rendered as •••• in the page snapshot, with values never leaving the page; form fill results only return sanitized plain text.

Q: Will the model follow when I switch tabs?

A: No. When the assistant starts working, it binds the context to the currently active tab; after the user manually switches away, subsequent browser operations pause, with the sidebar asking whether to "Continue on original page" or "Follow new page". Choosing the original page allows background operations but will never change the tab you're viewing.

Q: What's the relationship with dsh's official browser capabilities?

A: This is the browser capability implementation for dsh web profile: the plugin registers browser_* toolset + WebSocket channel, the model addresses by number to execute actions in the user's own Chrome, with all login state and session preserved throughout.

Q: How to uninstall?

A: Execute dsh plugin --profile web remove @yuxianglin/dsh-bridge-browser on the dsh side to remove the bridge plugin; on the Chrome side, go to chrome://extensions, find "dsh Browser Assistant", and click "Remove". Local copies at ~/.dsh/dsh-browser (managed installation) and ~/.dsh/browser-extension (extension directory) can be cleaned up as needed.

Getting Started Difficulty

Beginner — Users basically don't need manual configuration: after installing the bridge + Chrome extension, opening the sidebar works immediately; only when debugging or customizing Token, timeout, or snapshot limits should they revisit the configuration options.

Known Issues & Limitations

  • Only one extension connection allowed at a time; newly opened windows replace the old one, and pending tool calls in the old window fail with bridge-closed
  • Protected or destroyed cross-origin iframes are marked as "unavailable" in snapshots, but don't cause the entire page snapshot to fail
  • Token has no automatic expiration mechanism; you need to manually change ~/.dsh/ext-bridge-token or change token in config to rotate
  • /ext/bridge-config only returns ws://127.0.0.1 address; non-loopback deployment requires manually entering address and Token in sidebar settings
  • The repository's Playwright e2e automatically skips when there's no available Chromium or the extension isn't built, which doesn't affect the bridge itself
  • Approval logic is forced to execute in the extension service worker, not relying on model self-discipline; the DSH tool pipeline hasn't opened the same strategy to other clients yet

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/Lum1104/dsh-browser/packages/browser/bridge-browser)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory