FengLingYaaa/dsh-gpt-perm-strip

DSH插件:移除当前会话权限并非严格更宽的残留GPT沙箱权限。

Project Overview项目介绍

This is a DeepSeek Harness plugin exclusively for GPT-family models. Before sandbox escalation check, it removes sandbox_permissions and justification fields that are not strictly wider than current session permissions. Use it to fix call failures caused by GPT sending redundant permissions. It leaves non-GPT model permissions unchanged.

这是DeepSeek Harness一款仅适用于GPT系列模型的插件。在工具调用进入沙箱权限检查前,它会移除不宽于当前会话权限的多余sandbox_permissionsjustification字段,解决GPT习惯重复发送相同权限导致调用失败的问题,仅对匹配规则的GPT模型生效。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

FengLingYaaa/dsh-gpt-perm-strip 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-gpt-perm-strip

A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.

Why

DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:

sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode

GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-writedanger-full-access) untouched.

tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.

GPT-only

Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):

  • gpt-4o, gpt-5.6-sol, chatgpt-4o-latest, openai/gpt-4.1, ft:gpt-4o:…
  • optional: o1 / o3 / o4 (includeOpenAiReasoning, default on)

Grok and DeepSeek are ignored unless you add extraModelPatterns.

Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip

Install

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

Or from a local checkout:

git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .

Config

Field Default Meaning
includeOpenAiReasoning true Treat o1/o3/o4 as GPT-family
extraModelPatterns [] Extra regexes against provider, model, or provider/model
injectPrompt true GPT-only runtime-context reminder
logStrips true Log each strip as [gpt-perm-strip] stripped …

Behavior

Session GPT argument Result
danger-full-access sandbox_permissions: danger-full-access stripped, call runs
workspace-write sandbox_permissions: workspace-write stripped
workspace-write sandbox_permissions: danger-full-access kept (real escalation)
read-only sandbox_permissions: workspace-write kept
non-GPT model any permission unchanged

permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.

上一个 Prev dsh-minimal-mode-compaction 下一个 Next dsh-maestro-sync