inmny/dsh-sandbox-escalation-fix
让 DeepSeek Harness 忽略不高于 Session 当前权限的无效 sandbox_permissions 请求,避免模型在已经拥有更高或相同权限时反复触发 not strictly wider 错误,同时保留 DSH 原有的提权审批和非法参数校验。
catalog descriptioncatalog 简介 / catalog description:DeepSeek Harness 插件:处理DSH沟槽的权限管理(full acess下传入同级或者降级的请求会报错,导致ai大战权限管理)
Project Overview项目介绍
This plugin is built exclusively for DeepSeek Harness (DSH), designed to resolve sandbox permission escalation bugs found in DSH version 0.1.0-rc.6. It filters out invalid permission requests that do not grant a wider permission scope than the current active session, which stops repeated, annoying error messages that pop up when the model requests equal or lower permissions than it already holds. It preserves DSH’s original escalation approval flow and validation for illegal parameters, and works with all default and custom DSH presets out of the box without any extra configuration required after installation.
The plugin addresses multiple common error scenarios that DSH users regularly encounter when working with sandbox permissions. It fixes the "sandbox escalation is not strictly wider than current mode" error that occurs when the model requests the same permission level it already has active in the current session. It also resolves the invalid parameter error that triggers when a justification is provided without a corresponding sandbox_permissions entry, and adds a default non-empty justification when the model omits this required field for legitimate escalation requests.
To install or update this plugin, you can use the official DSH CLI command dsh plugin --profile web add with the plugin name to add it to your active web profile, and you must restart dsh web after installation to load the plugin correctly. It requires Node.js version 24 or newer to run properly, and is licensed under the permissive MIT open source license. The plugin is only needed for DSH 0.1.0-rc.6; once the DSH core project fixes the underlying permission issue upstream, you can safely remove this plugin from your profile.
这是一款专为 DeepSeek Harness(DSH)开发的原生插件,用于修复 DSH 0.1.0-rc.6 版本中沙箱权限提权的错误问题。它会忽略权限不高于当前会话的无效 sandbox_permissions 请求,避免模型在已有相同或更高权限时反复触发错误,同时保留 DSH 原有的提权审批流程和非法参数校验功能。它对 standard、code、cordis、minimal 等官方预设和自定义预设都生效,安装后不需要额外配置。
它可修复多种 DSH 常见错误,包括请求同级权限时出现的「权限不严格宽于当前模式」错误、仅存在提权说明却未附带 sandbox_permissions 导致的参数配对错误,还会在模型遗漏合法提权所需的非空说明时,自动填入默认说明「Empty justification」。用户可通过 DSH CLI 命令将它安装到目标 profile,作为 bundle layer 插件,它不会修改 DSH 的安装目录。
该插件运行要求 Node.js 24 或更高版本,适配 DSH 0.1.0-rc.6 版本,支持所有 DSH 兼容的宿主平台。它以 MIT 许可证开源,支持通过 CLI 命令完成安装、更新、卸载,也支持本地开发版本的安装。官方提供了完整的测试覆盖所有功能场景,如果 DSH 上游官方修复了该问题,用户可移除该插件。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-sandbox-escalation-fix(inmny/dsh-sandbox-escalation-fix)
仓库:https://github.com/inmny/dsh-sandbox-escalation-fix
本站详情页:https://www.yhbd.top/plugins/inmny-dsh-sandbox-escalation-fix/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 18 · 最近提交 2026-08-21 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 18 stars - an early-stage project星标 18,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix@0.1.2
把 inmny/dsh-sandbox-escalation-fix 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugin-sandbox-escalation-fix
让 DeepSeek Harness 忽略不高于 Session 当前权限的无效 sandbox_permissions 请求,避免模型在已经拥有更高或相同权限时反复触发 not strictly wider 错误,同时保留 DSH 原有的提权审批和非法参数校验。

使用方法
插件安装到 profile 后,会在 Host 侧修复 bash、pwsh、write 和 edit 中多余或过时的提权参数。standard、code、cordis、minimal 以及自定义 preset 中可见的对应工具共用这一修复,不需要额外配置。
插件针对以下错误:
Error: sandbox escalation to "danger-full-access" is not strictly wider than
this call's current "danger-full-access" mode
同样覆盖当前已经是 danger-full-access,但模型仍附加 sandbox_permissions: "workspace-write" 的过时请求:

对于确实需要升级的请求,如果模型遗漏 justification,或只提供空字符串和空白字符,插件会自动填入 "Empty justification":

反过来,如果模型只提供 justification,却没有提供 sandbox_permissions,插件会忽略这个没有实际作用的理由,避免触发下面的参数配对错误:
Error: invalid escalation: justification is only valid together with sandbox_permissions
安装后,如果模型请求的权限不比 Session 当前权限更高,插件就忽略这个无效的提权请求,并使用当前 Session 权限正常执行工具。真正更宽的请求仍进入 DSH 审批流程;缺失或空白的理由会使用上述 fallback,合法的非空理由保持不变。read-only、未知 target 或非字符串 justification 等非法值仍由 DSH 拒绝。
插件只作为 bundle layer 安装到目标 profile,不修改 DSH 安装目录。
安装或更新
从 npm 安装固定版本到 Web profile:
dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix@0.1.2
更新现有安装时使用同一条命令。安装完成后重启 dsh web,让 Host 加载新插件,然后新建会话。
安装最新版时可以省略版本号:
dsh plugin --profile web add dsh-plugin-sandbox-escalation-fix
开发本地版本时传入 checkout 路径:
dsh plugin --profile web add C:\path\to\dsh-sandbox-escalation-fix
移除插件:
dsh plugin --profile web remove dsh-plugin-sandbox-escalation-fix
权限语义
| 当前 mode | 请求的 sandbox_permissions |
处理结果 |
|---|---|---|
read-only |
workspace-write |
保持参数,继续走原有审批 |
read-only |
danger-full-access |
保持参数,继续走原有审批 |
workspace-write |
workspace-write |
删除冗余参数,按普通调用执行 |
workspace-write |
danger-full-access |
保持参数,继续走原有审批 |
danger-full-access |
danger-full-access |
删除冗余参数,按普通调用执行 |
danger-full-access |
workspace-write |
删除过时参数,按普通调用执行 |
| 任意 mode | 未提供,只有 justification |
删除无效理由,按普通调用执行 |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest
saya-ch/dsh-mobile