iimaguest/dsh-sandbox-escalation-guard ↗★ 0

dsh-sandbox-escalation-guard

Stops the DSH sandbox-escalation fields being offered to a model when the calling session cannot grant them, fixing the GPT-family retry loop at danger-full-access where every advertised enum value is rejected before the command runs. 适合需要修复 GPT 系列模型在提权时陷入重试死循环的用户。

Package
dsh-sandbox-escalation-guard
Compatibility
Unverified
Version
1.0.0
License
Apache-2.0
Last updated
Sep 19, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:iimaguest/dsh-sandbox-escalation-guard

Configuration

- id: dsh-sandbox-escalation-guard
  name: dsh-sandbox-escalation-guard
  config:
    warn: true             # log each intervention to the host console
    resolveMode: ...       # testing seam only; omit in production
    escalationPossible: ... # testing seam only; omit in production
fielddefaultmeaning
warntrueLog when the schema is narrowed or a call is corrected.
resolveMode(unset)Overrides effective-mode resolution for the per-call correction. Testing seam; production reads the session's own sandbox/mode fold through sandboxPolicy.
escalationPossible(unset)Overrides whether the published surface keeps the escalation fields. Testing seam; production reads the approval policy.