trentswd/dsh-escalation-review ↗★ 0
dsh-escalation-review
仅针对沙箱逃逸的安全审查工具 适合需要对所有沙箱提权审批进行严格安全审查与闭环控制的用户。
安装
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:trentswd/dsh-escalation-review说明文档
阅读完整 README ↗Configuration
enabled is the gate, and it ships off: while it is off the plugin runs no review and makes no model
calls. With it on, it answers every sandbox-escalation approval. The gate belongs to the plugin rather
than to your permission table, so installing it leaves your presets as they are, independent of whichever
preset a session happens to use. Set it from the config page — the two-position control on the first row
of the card, Off / On — or with "enabled": true in a config file (the GUI writes the textual form
"enabledText": "true").
Lowest to highest priority: the package's config.json → ~/.dsh/escalation-review.config.json →
configPath if you pass one → the host config block of the plugin entry → the settings layer the config
page writes (with its own *.ui.json companion). File layers are re-read on every escalation and the
settings layer is polled about every two seconds, so edits take effect without a restart; changing the
plugin's code needs one.
config.json accepts // and /* */ comments. cordis.patch.yml is YAML: comments there need #, and a
parse failure makes the loader skip the whole bundle silently.
| Key | Default | Meaning |
|---|---|---|
enabled | false | The intervention switch. |
enabledText | "" | Text form of the switch ("true" / "false") written by the config page; non-empty overrides enabled. |
provider / model | "" | Which provider and model review; empty follows the session. |
reasoningEffort | "" | Reviewer thinking effort: off, minimal, low, medium, high, xhigh, max, or empty to follow the session. |
failMode | deny | What a failed or timed-out review means: deny or ask. |
denyMode | deny | What a deny verdict means: deny outright, or ask the user. |
probeRunner | inproc | Read-only probes: inproc (no process spawned) or shell (a read-only command inside the sandbox). |
policyExtra | "" | Free-form rules appended to the reviewer policy. |
allowedHosts | [] | Hosts whose ordinary network access counts as low risk. An empty array in a user file overrides the package list, so write the full list if you write the key at all. |
timeoutMs | 100000 | Total budget for one review, retries included. |
attemptTimeoutMs | 30000 | Cap for a single request; a timeout is retried. |
retryDelayMs | 5000 | Wait between attempts. |
minAttemptMs | 2000 | Skip a retry when the remaining budget after the delay is below this. |