trentswd/dsh-escalation-review ↗★ 0

dsh-escalation-review

仅针对沙箱逃逸的安全审查工具 适合需要对所有沙箱提权审批进行严格安全审查与闭环控制的用户。

套件
dsh-escalation-review
相容性
待驗證
Harness 依賴範圍
>=0.1.7-rc.2 <0.3.0
Cordis 依賴範圍
~4.0.4
版本
0.2.2
授權
MIT
最近更新
2026年9月28日

安裝

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:trentswd/dsh-escalation-review

Configuration

enabled is the gate, and it ships off: while it is off the plugin runs no review and makes no model calls. With it on, it answers every sandbox-escalation approval. The gate belongs to the plugin rather than to your permission table, so installing it leaves your presets as they are, independent of whichever preset a session happens to use. Set it from the config page — the two-position control on the first row of the card, Off / On — or with "enabled": true in a config file (the GUI writes the textual form "enabledText": "true").

Lowest to highest priority: the package's config.json → ~/.dsh/escalation-review.config.json → configPath if you pass one → the host config block of the plugin entry → the settings layer the config page writes (with its own *.ui.json companion). File layers are re-read on every escalation and the settings layer is polled about every two seconds, so edits take effect without a restart; changing the plugin's code needs one.

config.json accepts // and /* */ comments. cordis.patch.yml is YAML: comments there need #, and a parse failure makes the loader skip the whole bundle silently.

KeyDefaultMeaning
enabledfalseThe intervention switch.
enabledText""Text form of the switch ("true" / "false") written by the config page; non-empty overrides enabled.
provider / model""Which provider and model review; empty follows the session.
reasoningEffort""Reviewer thinking effort: off, minimal, low, medium, high, xhigh, max, or empty to follow the session.
failModedenyWhat a failed or timed-out review means: deny or ask.
denyModedenyWhat a deny verdict means: deny outright, or ask the user.
probeRunnerinprocRead-only probes: inproc (no process spawned) or shell (a read-only command inside the sandbox).
policyExtra""Free-form rules appended to the reviewer policy.
allowedHosts[]Hosts whose ordinary network access counts as low risk. An empty array in a user file overrides the package list, so write the full list if you write the key at all.
timeoutMs100000Total budget for one review, retries included.
attemptTimeoutMs30000Cap for a single request; a timeout is retried.
retryDelayMs5000Wait between attempts.
minAttemptMs2000Skip a retry when the remaining budget after the delay is below this.