Open-source project
ysr666/dsh-vision-router avatar
ysr666/dsh-vision-router

dsh-vision-router's free path is a remote endpoint, and an empty local OCR result is the trigger to upload

Eyes for text-only DeepSeek Harness agents: built-in free vision chain (no key) + pixel-level vision tools (Q&A, grounding, crop, pixel diff, colors, OCR, SVG trace, cutout, screenshots). One-command install, no Python, image turns work like ordinary tool-calling turns.

1,127 stars51 forksJavaScriptMIT

At a glance

What is it?
This plugin gives a text only coding agent a way to see: fourteen tools covering cropping, pixel diffing, tracing, cutouts, OCR, and screenshots, with a small classifier style vision model called on demand while the reasoning model stays put. The project is unusually upfront about its own data flow. A table at the top of the page states exactly which operations stay on your machine and which do not, the package description repeats the warning, and the one detail worth reading twice is that a locally empty OCR result is treated as a reason to send the image somewhere.
Who is it for?
Adopt this if you want pixel level tools without writing them, and start by turning on the local only switch, because the default configuration is a remote endpoint with a friendly name. Then check two things.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 2, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The default free path is a named remote host, and the page says so twice

The first warning on the page is a caution, and its subject is the word free. A fresh install has an anonymous vision fallback enabled, so free and no key do not mean offline. When a cloud vision model is used, the plugin sends the image or a derived crop, the vision prompt, and related request metadata to that provider, and the page says not to use that chain for confidential, regulated, or classified material. The data flow table makes it concrete by naming the endpoint host the fallback talks to and adding that the service still receives the request payload and network metadata such as the source IP. The package description in the project metadata then repeats the same point in a sentence of its own, which is unusual and worth noting: the disclosure is not confined to the readme, it is also in the thing a package index shows you.

An empty local OCR result is a reason to send the image

The table has one row that deserves reading on its own. Optical character recognition with the local engine is processed on your machine, but with the default engine setting, an unavailable or empty local result may fall back to a vision model. So a document that yields nothing locally, a blank page, a scan that does not parse, an image with no text at all, will be sent to a provider. That is a different rule from failing open on error, because empty is not an error; it is a legitimate answer for most images. If the plugin is running with the local only switch off and no key configured, the fallback is the only thing that can answer, so the empty case is exactly the case that reaches the network. Worth knowing before you point it at a folder of screenshots and assume nothing leaves the box.

Local only is a switch that disables execution, not a rewrite of your config

The escape hatch is in settings, under the plugin's own general section, labelled local only vision. The page is precise about what it does and does not do, and the distinction matters. It is a runtime policy rather than a destructive rewrite: your saved cloud rows and the fallback entry stay configured, they simply cannot execute while the switch is on. Eligibility is restricted to loopback addresses, named explicitly as localhost, the 127 range, and the IPv6 loopback, which covers a local model server, another local runtime, and custom local endpoints. Two caveats follow. The text a vision model returns still goes back to your chat model, which may itself be remote, so a local image pipeline plus a remote chat model is still a remote data path. And the page says to test the final boundary in your own environment, because the plugin cannot make a remote chat model, a proxy, or a host integration local.

Seven tools stay on the machine and the rest are network calls

The split is drawn explicitly, which makes the tool list easier to reason about than a flat count. Local pixel operations, and they never call a vision model, are crop, pixel diff, palette, SVG trace, cutout, a materialise operation, and an HTML screenshot. Everything that asks a model to look is a network call: describe, detect, ground, and the OCR path when it falls back, plus the routing of an image turn itself. Two further rows cover the rest. A user configured cloud provider receives the image under its own retention and privacy terms, which is the row to read before pointing this at a company endpoint. And a local model server is described precisely: the pixels go to your own machine, but the resulting text still returns to the chat model. None of this needs Python. The pipeline is built on a native image library, a vector tracer, an OCR engine, and a system Chrome.

The free tier is five models and two requests a minute, with the buckets described as theoretical

Here is the whole free story in two sentences. Vision tools end with a five model anonymous fallback: no account, no key, two requests per minute per address per model, and roughly ten a minute in theory across independent buckets. Anything you supply yourself runs first, so the fallback is the last resort rather than the default provider, which is the right ordering and also means the fallback is what absorbs your burst. Two things to notice in the wording. The rate is per address, so several agents or a shared network share the budget. And the ten a minute figure is qualified with in theory, by the author's own hand, which suggests the bucket accounting has not been verified in production. At two requests a minute, an agent doing a crop and describe loop is a handful of calls per step, so the ceiling binds quickly on a long task.

The only executable is a diagnostic command; the plugin installs itself through a patch

The package declares one binary and it is not the installer. The name maps to a file called doctor, so the executable is a diagnostic tool, and the actual installation happens through the harness's own plugin command. The one command claim is real, and the mechanism is unusual: the package ships its own composition patch, and the plugin add command uses it to wire the row, the admission wrapper, and the attachment limits with no manual file editing. That means the install mutates harness configuration on your behalf, which is worth understanding before you run it rather than after. Two smaller details. Taking over the official model route is an optional setting described as stealth mode, and it is off by default. And the package exports subpaths for its own manifest and its patch file, so other tooling can read the configuration this plugin installs.

Three required peers share one range that straddles two release candidates

The peer dependency block is where this plugin couples itself to its host. Three separate packages, an anonymous user id library, the model integration, and a storage domain package, all carry the same compound version range, and the range is not a normal one: it accepts a window starting at a release candidate in the 0.1 line up to a pre-release of 0.2, or a verified release candidate in the 0.2 line up to 0.3. In other words the plugin installs against two parallel pre-release trains simultaneously, which is what lets it run on hosts that have not settled on either. The image library is a fourth peer rather than a dependency, so you supply it. The release announcement explains what the 3.0 work bought: vision authority moved into a scoped policy store backed by host storage, which hydrates before child sessions publish and binds delegation to the host agent lifecycle. That is the same durability the local only switch depends on.

Five build configs, a quality directory, and an audit link pinned to the last major

The repository root is bigger than a plugin's root has any reason to be, and the shape of it explains some of the choices. There are five separate TypeScript configurations, split by base, build, client, declaration, and host, which is a plugin that compiles into several distinct surfaces rather than one. There is a workspace file, so the presets directory is a set of sibling packages rather than plain data. There is a directory named quality, a security policy, a sponsor file, a changelog, and two readmes, one English and one Chinese. The one detail that belongs in any evaluation is in the header rather than the body: the third party audit report linked at the top is pinned to a specific version and a specific commit, and that version is two majors behind the package you would install today. Nobody has re-run the audit, or has not published it.

Editorial conclusion

Adopt this if you want pixel level tools without writing them, and start by turning on the local only switch, because the default configuration is a remote endpoint with a friendly name. Then check two things. Whether any of your images are the kind the page tells you not to send to a cloud chain, since an empty OCR result is enough to trigger a send even when you thought you were local. And whether your chat model is also local, because the page is clear that keeping the pixels local does nothing if the resulting text goes to a remote model, and it tells you to test the network boundary yourself rather than trusting the switch.

Frequently asked questions

Does dsh-vision-router send my images to a server?

Yes, by default. A fresh install has an anonymous cloud fallback enabled that sends the image or a derived crop plus the prompt and request metadata to a named provider endpoint, and the page states that free and no key do not mean offline. A local only setting blocks cloud rows from executing while leaving them configured.

What does dsh-vision-router need installed?

No Python. The pipeline runs on a native image library, a vector tracer, an OCR engine, and a system Chrome, with the browser automation package expecting a Chrome you already have. Node 22.19 or newer, or 24, is required, with the package manager version pinned in the project metadata.

Which dsh-vision-router tools stay on my machine?

Crop, pixel diff, palette, SVG trace, cutout, materialise, and HTML screenshot are processed locally and never call a vision model. Image turn routing and the describe, detect, ground, and OCR paths send the image or a derived crop to the selected provider.

How do I install dsh-vision-router?

Through the harness plugin command in one step, which applies the composition patch the package ships and wires the row, the admission wrapper, and the attachment limits without manual file edits. Taking over the official model route is an optional setting, off by default.

What does the dsh-vision-router free fallback allow?

Five models with no account and no key, two requests per minute per address per model, which the page describes as roughly ten a minute in theory across independent buckets. Vision models you supply yourself are tried first, so the fallback only absorbs what the others did not answer.

Official sources

  1. License: MIT
  2. Project website
  3. README
  4. Releases
  5. ysr666/dsh-vision-router on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ysr666-dsh-vision-router.svg)](https://hysenlabs.com/projects/ysr666-dsh-vision-router)