inmny/dsh-sandbox-escalation-fix 预览 preview

inmny/dsh-sandbox-escalation-fix

Plugin插件 Native原生 ⭐ 18 MIT Approval & Security审批与安全

让 DeepSeek Harness 忽略不高于 Session 当前权限的无效 sandbox_permissions 请求,避免模型在已经拥有更高或相同权限时反复触发 not strictly wider 错误,同时保留 DSH 原有的提权审批和非法参数校验。

catalog descriptioncatalog 简介 / catalog description:DeepSeek Harness 插件:处理DSH沟槽的权限管理(full acess下传入同级或者降级的请求会报错,导致ai大战权限管理)

Project Overview项目介绍

This plugin is built exclusively for DeepSeek Harness (DSH), designed to resolve sandbox permission escalation bugs found in DSH version 0.1.0-rc.6. It filters out invalid permission requests that do not grant a wider permission scope than the current active session, which stops repeated, annoying error messages that pop up when the model requests equal or lower permissions than it already holds. It preserves DSH’s original escalation approval flow and validation for illegal parameters, and works with all default and custom DSH presets out of the box without any extra configuration required after installation.

The plugin addresses multiple common error scenarios that DSH users regularly encounter when working with sandbox permissions. It fixes the "sandbox escalation is not strictly wider than current mode" error that occurs when the model requests the same permission level it already has active in the current session. It also resolves the invalid parameter error that triggers when a justification is provided without a corresponding sandbox_permissions entry, and adds a default non-empty justification when the model omits this required field for legitimate escalation requests.

To install or update this plugin, you can use the official DSH CLI command dsh plugin --profile web add with the plugin name to add it to your active web profile, and you must restart dsh web after installation to load the plugin correctly. It requires Node.js version 24 or newer to run properly, and is licensed under the permissive MIT open source license. The plugin is only needed for DSH 0.1.0-rc.6; once the DSH core project fixes the underlying permission issue upstream, you can safely remove this plugin from your profile.

这是一款专为 DeepSeek Harness(DSH)开发的原生插件,用于修复 DSH 0.1.0-rc.6 版本中沙箱权限提权的错误问题。它会忽略权限不高于当前会话的无效 sandbox_permissions 请求,避免模型在已有相同或更高权限时反复触发错误,同时保留 DSH 原有的提权审批流程和非法参数校验功能。它对 standard、code、cordis、minimal 等官方预设和自定义预设都生效,安装后不需要额外配置。

它可修复多种 DSH 常见错误,包括请求同级权限时出现的「权限不严格宽于当前模式」错误、仅存在提权说明却未附带 sandbox_permissions 导致的参数配对错误,还会在模型遗漏合法提权所需的非空说明时,自动填入默认说明「Empty justification」。用户可通过 DSH CLI 命令将它安装到目标 profile,作为 bundle layer 插件,它不会修改 DSH 的安装目录。

该插件运行要求 Node.js 24 或更高版本,适配 DSH 0.1.0-rc.6 版本,支持所有 DSH 兼容的宿主平台。它以 MIT 许可证开源,支持通过 CLI 命令完成安装、更新、卸载,也支持本地开发版本的安装。官方提供了完整的测试覆盖所有功能场景,如果 DSH 上游官方修复了该问题,用户可移除该插件。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 18 stars - an early-stage project星标 18,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix@0.1.2

把 inmny/dsh-sandbox-escalation-fix 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-sandbox-escalation-fix

让 DeepSeek Harness 忽略不高于 Session 当前权限的无效 sandbox_permissions 请求,避免模型在已经拥有更高或相同权限时反复触发 not strictly wider 错误,同时保留 DSH 原有的提权审批和非法参数校验。

DSH 重复请求同级沙箱权限

使用方法

插件安装到 profile 后,会在 Host 侧修复 bash、pwsh、write 和 edit 中多余或过时的提权参数。standard、code、cordis、minimal 以及自定义 preset 中可见的对应工具共用这一修复,不需要额外配置。

插件针对以下错误:

Error: sandbox escalation to "danger-full-access" is not strictly wider than
this call's current "danger-full-access" mode

同样覆盖当前已经是 danger-full-access,但模型仍附加 sandbox_permissions: "workspace-write" 的过时请求:

DSH 在 danger-full-access 下重复请求 workspace-write

对于确实需要升级的请求,如果模型遗漏 justification,或只提供空字符串和空白字符,插件会自动填入 "Empty justification":

DSH 缺少非空 justification

反过来,如果模型只提供 justification,却没有提供 sandbox_permissions,插件会忽略这个没有实际作用的理由,避免触发下面的参数配对错误:

Error: invalid escalation: justification is only valid together with sandbox_permissions

安装后,如果模型请求的权限不比 Session 当前权限更高,插件就忽略这个无效的提权请求,并使用当前 Session 权限正常执行工具。真正更宽的请求仍进入 DSH 审批流程;缺失或空白的理由会使用上述 fallback,合法的非空理由保持不变。read-only、未知 target 或非字符串 justification 等非法值仍由 DSH 拒绝。

插件只作为 bundle layer 安装到目标 profile,不修改 DSH 安装目录。

安装或更新

从 npm 安装固定版本到 Web profile:

dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix@0.1.2

更新现有安装时使用同一条命令。安装完成后重启 dsh web,让 Host 加载新插件,然后新建会话。

安装最新版时可以省略版本号:

dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix

开发本地版本时传入 checkout 路径:

dsh plugin --profile web add C:\path\to\dsh-sandbox-escalation-fix

移除插件:

dsh plugin --profile web remove dsh-plugin-sandbox-escalation-fix

权限语义

当前 mode 请求的 sandbox_permissions 处理结果
read-only workspace-write 保持参数,继续走原有审批
read-only danger-full-access 保持参数,继续走原有审批
workspace-write workspace-write 删除冗余参数,按普通调用执行
workspace-write danger-full-access 保持参数,继续走原有审批
danger-full-access danger-full-access 删除冗余参数,按普通调用执行
danger-full-access workspace-write 删除过时参数,按普通调用执行
任意 mode 未提供,只有 justification 删除无效理由,按普通调用执行

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev stent 下一个 Next quantum-practices →