DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Strip Sandbox Permissions — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
S

dsh-strip-sandbox-permissions

Strip Sandbox Permissions

从模型工具调用参数中移除 sandbox_permissions / justification,确保会话已有足够权限时不会触发沙箱权限升级。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:Sharl210/dsh-strip-sandbox-permissions#091d62c3dca0fcaa0cc7f26e6e470e19ef355f35
README兼容性版本

兼容性与来源证明

Strip Sandbox Permissions 以 dsh-strip-sandbox-permissions 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/21

版本

0.1.0stable
2026/8/21

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 1
周下载
0
最近提交
2026/8/21
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Mobiledsh-mobileDeepSeek Harness 移动端适配与安全访问插件,支持局域网、远程连接、Android App 和手机浏览器。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-strip-sandbox-permissions

A zero-dependency DeepSeek Harness (DSH) plugin that ignores sandbox_permissions / justification fields carried in model tool-call arguments, preventing false sandbox escalation rejections.

Problem

Some models (a post-training tendency) automatically attach sandbox_permissions (and its companion justification) to tool calls. When the session already runs with sufficient permission (for example full access), carrying a non-strictly-wider value triggers a false rejection from the DSH sandbox:

Error: sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode

How it works

Every model tool call flows through the llm/stream waterfall, so this is the single interception point that covers every adapter. Adapters emit a block-end chunk carrying the fully assembled tool-call block at the end of the stream. This plugin rewrites that block: it parses the arguments object, deletes the top-level sandbox_permissions / justification keys, and re-serializes. Session logs and replay both see the cleaned arguments, so nothing downstream disagrees.

Only those two escalation-specific keys are stripped; every other argument is preserved verbatim. A new block is produced only when one of the keys actually exists — otherwise the original block is passed through unchanged (zero cost). Invalid JSON, non-object arguments, and non-tool-call blocks are left untouched.

Install

Published on npm. Install with:

dsh plugin --profile <your-profile> add dsh-strip-sandbox-permissions

Restart DSH after installing. Verify:

dsh plugin --profile <your-profile> list

Package / publish

npm pack          # produce dsh-strip-sandbox-permissions-<version>.tgz
npm publish       # publish a new version to the npm registry

A granular access token with Bypass 2FA enabled and Read and write package access is required to publish; a token without bypass 2FA is rejected with a 403 even when otherwise valid.

中文说明

一个零依赖的 DeepSeek Harness(DSH)插件:忽略模型工具调用参数里携带的 sandbox_permissions / justification 字段,避免沙箱权限误拒绝。

部分模型(后训练倾向)会在工具调用参数里自动带上 sandbox_permissions(及其配套 justification)。当会话已处于足够权限(例如完整访问权限)时,携带一个非严格加宽的 值会触发 DSH 沙箱的误拒绝。本插件在 llm/stream 瀑布流(所有模型工具调用的必经点) 拦截 block-end 块,从工具参数对象顶层删除这两个字段后再交给装配器。只剥离这两个 升级专属字段,其余参数原样保留;未命中时零开销透传。

安装:

dsh plugin --profile <你的profile名> add dsh-strip-sandbox-permissions

安装完成后重启 DSH 即生效。

License

MIT