FengLingYaaa/dsh-gpt-perm-strip
DSH插件:移除当前会话权限并非严格更宽的残留GPT沙箱权限。
Project Overview项目介绍
This is a DeepSeek Harness plugin exclusively for GPT-family models. Before sandbox escalation check, it removes sandbox_permissions and justification fields that are not strictly wider than current session permissions. Use it to fix call failures caused by GPT sending redundant permissions. It leaves non-GPT model permissions unchanged.
这是DeepSeek Harness一款仅适用于GPT系列模型的插件。在工具调用进入沙箱权限检查前,它会移除不宽于当前会话权限的多余sandbox_permissions和justification字段,解决GPT习惯重复发送相同权限导致调用失败的问题,仅对匹配规则的GPT模型生效。
请帮我了解并安装插件:【dsh-gpt-perm-strip】【https://github.com/FengLingYaaa/dsh-gpt-perm-strip】
Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip
把 FengLingYaaa/dsh-gpt-perm-strip 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-gpt-perm-strip
A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.
Why
DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:
sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode
GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-write → danger-full-access) untouched.
tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.
GPT-only
Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):
gpt-4o,gpt-5.6-sol,chatgpt-4o-latest,openai/gpt-4.1,ft:gpt-4o:…- optional:
o1/o3/o4(includeOpenAiReasoning, default on)
Grok and DeepSeek are ignored unless you add extraModelPatterns.
Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip
Install
dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip
Or from a local checkout:
git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .
Config
| Field | Default | Meaning |
|---|---|---|
includeOpenAiReasoning |
true |
Treat o1/o3/o4 as GPT-family |
extraModelPatterns |
[] |
Extra regexes against provider, model, or provider/model |
injectPrompt |
true |
GPT-only runtime-context reminder |
logStrips |
true |
Log each strip as [gpt-perm-strip] stripped … |
Behavior
| Session | GPT argument | Result |
|---|---|---|
danger-full-access |
sandbox_permissions: danger-full-access |
stripped, call runs |
workspace-write |
sandbox_permissions: workspace-write |
stripped |
workspace-write |
sandbox_permissions: danger-full-access |
kept (real escalation) |
read-only |
sandbox_permissions: workspace-write |
kept |
| non-GPT model | any permission | unchanged |
permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.
wenbin-wb/dsh-bridge
PerryLink/dsh-permission-rules
eri64/dsh-claude-ux
MichengAI/dsh-archive-manager
lsz-asd/dsh-plugin-session-delete
10086ggqq/dsh_theme_terraria
king-bcolor/dsh-multi-tenant-projects
ZK-Andy/dsh-continual-evolve