xinghaix/deepseek-harness-desktop--plugins-dsh-sandbox-escalation-fix ↗★ 0

dsh-plugin-sandbox-escalation-fix

Normalize redundant sandbox requests and malformed justifications in DeepSeek Harness tools, including PTC run_code 适合遇到PTC或Shell工具提权报错、需要修复提权逻辑的用户。

パッケージ
dsh-plugin-sandbox-escalation-fix
互換性
未検証
Harness ピア範囲
0.1.6-alpha.1
Cordis ピア範囲
4.0.2
バージョン
0.2.1
最終更新
2026/09/20

同名パッケージの別リポジトリ

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:xinghaix/deepseek-harness-desktop#1442884593e57d217cd9ddd8de5f2f2e250f81cc&path:plugins/dsh-sandbox-escalation-fix

ドキュメント

README 全文を読む ↗

使用方法

插件安装到 profile 后,会在 Host 侧修复可见工具里多余或过时的提权参数。

PTC 从 DSH 早期版本就存在:0.1.0-rc.6 时内部叫 Code Mode,preset id 为 code,中文名已经是「PTC 模式」;0.1.5 起 preset 改名为 ptc。那时外层 run_code 没有 sandbox_permissions,提权只出现在程序内部的 bash / pwsh / write / edit 上,所以 0.1.x 包装这四个工具即可。0.1.6 把提权字段加到了外层 run_code:模型给整个 program 带上相同或更低的权限时,程序还没启动就会收到 not strictly wider。0.2.0 补上这个入口。

当前 DSH 0.1.6 自带工具里带这对字段的是:

  • PTC 外层 run_code(ptc preset 下模型直接调用的唯一入口;这是 0.1.6 新出现的提权面,不是新出现的 PTC)
  • bash / pwsh(standard、ptc、cordis 的一次性 shell;minimal 的持久 shell 没有提权字段,无需处理)
  • write / edit

其它带 sandbox_permissions + justification 的可见工具也会通过 tools.schemas() 被发现并一并修复,不需要额外配置。装的若仍是 0.1.2,PTC 会话里内部 shell / 写文件仍会被修复,但外层 run_code 的无效提权不会。

插件针对以下错误:

Error: sandbox escalation to "danger-full-access" is not strictly wider than
this call's current "danger-full-access" mode

同样覆盖当前已经是 danger-full-access,但模型仍附加 sandbox_permissions: "workspace-write" 的过时请求:

DSH 在 danger-full-access 下重复请求 workspace-write

对于确实需要升级的请求,如果模型遗漏 justification,或只提供空字符串和空白字符,插件会自动填入 "Empty justification":

DSH 缺少非空 justification

反过来,如果模型只提供 justification,却没有提供 sandbox_permissions,插件会忽略这个没有实际作用的理由,避免触发下面的参数配对错误:

Error: invalid escalation: justification is only valid together with sandbox_permissions

安装后,如果模型请求的权限不比 Session 当前权限更高(相同或更小),插件就忽略这个无效的提权请求,并使用当前 Session 权限正常执行工具。真正更宽的请求仍进入 DSH 审批流程;缺失或空白的理由会使用上述 fallback,合法的非空理由保持不变。read-only、未知 target 或非字符串 justification 等非法值仍由 DSH 拒绝。

插件只作为 bundle layer 安装到目标 profile,不修改 DSH 安装目录。