npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@yiln-dsh/dsh-plugin-file-message

v0.3.4

Published

DSH bundle plugin that lets the model send workspace-backed files and images into the conversation.

Readme

@yiln-dsh/dsh-plugin-file-message

A DSH dsh.bundle that lets the model send workspace-backed files and images into the conversation.

The plugin deliberately uses live file references, not copied attachment objects:

  • send_image accepts an existing PNG, JPEG, WebP, or GIF in the current session workspace.
  • send_file accepts any regular file in the current session workspace.
  • The source path and session identity are stored in the tool result presentation metadata and in the session sidecar send-attachments-metas.json next to session.jsonl.zstd.
  • The browser card reads the current file through the Host when it needs an image preview or download; historical cards recover missing session identity from the sidecar by callId.
  • Deleting or moving the source file makes the historical message unavailable; deleting a session does not delete workspace files.

UI

Images render as a constrained preview with a View original lightbox and Download original action. Files render as a filename, media type, size, and Download action. Markdown files (.md, .markdown, .mdx) additionally render an inline rendered preview below the file row, with the download action preserved. The card is replayable because its path and session identity are persisted with the tool/result event; old cards without the identity use the Host's metadata recovery route.

The image preview uses the current file bytes and CSS constraints rather than creating a second thumbnail object. Preview reads are capped at 16 MiB; markdown text previews are capped at 1 MiB.

The markdown renderer is markdown-it's standalone ESM build (the ./browser export) served verbatim by the Host under /_dsh/file-message/vendor/markdown-it.mjs — no CDN, no bundler step. The browser loads it with dynamic import(). The ESM build is deliberate: the UMD build's AMD branch would be taken whenever a global define exists (the monaco loader in the same page), registering the module anonymously instead of exposing the constructor. Rendering happens in the browser with html: false (raw HTML inside the file is escaped) and markdown-it's built-in validateLink rejects javascript:/vbscript:/file:/data: hrefs, so workspace files never inject markup or scripts into the page.

Downloads are native streaming: the Download action is a plain link to the Host content route, which pipes the resolved workspace file straight into the HTTP response (Content-Disposition: attachment). The browser downloads natively — no fetch + blob buffering in page memory, no base64, and no 64 MiB transfer ceiling for downloads. Sending a file into the conversation still requires the file to fit in a 64 MiB read (the model-facing send_file bound), but downloading a sent file is unbounded.

Persistence

For the stock JSONL session backend, one successful send appends an item to:

<session-directory>/send-attachments-metas.json

The file has this shape:

{
  "version": 1,
  "sessionId": "session-...",
  "items": {
    "call-id": {
      "callId": "call-id",
      "sessionId": "session-...",
      "toolName": "send_image",
      "kind": "image",
      "path": "/workspace/output/result.png",
      "cwd": "/workspace",
      "displayName": "result.png",
      "mediaType": "image/png",
      "size": 183420,
      "version": "...",
      "createdAt": "2026-01-01T00:00:00.000Z"
    }
  }
}

Writes are serialized per session and published through a temporary file plus rename. The Host resolves the session's persistence location instead of reconstructing the encoded session-directory name. A legacy callId lookup builds an in-memory index once per process and skips unrelated unreadable sidecars.

Security and limits

  • Paths are resolved through DSH's fs service against the current session cwd.
  • The resolved target must remain inside the session workspace.
  • Symlink escapes are rejected by canonical containment.
  • Only regular files are accepted.
  • The Host re-resolves and re-stats the recorded path for every preview or download, and streams it through ctx.fs.processPath after the workspace-containment check.
  • The content route serves four modes: meta (replay metadata; legacy calls without a session ID return only the recovered identity, while detail=full returns the full record), preview (images, ≤ 16 MiB), text (text/* files, ≤ 1 MiB, used by the markdown card), and download (native streaming, unbounded).
  • preview, text, and download require the recorded sessionId; only the legacy identity lookup may omit it.
  • The browser never receives a file:// URL or reads a local path directly.

Install

The published package is @yiln-dsh/[email protected].

dsh plugin --profile web add file:/path/to/dsh-plugin-file-message

Restart dsh web after installing the profile Bundle. The plugin is plain JavaScript and has no build step.